๐ฆ๐น
Pingger Shikkoken
2026-10-08 21:15:47
(1 day ago)
2026-10-08T21:15:47+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT=ServerBridge MAC ...
show more
2026-10-08T21:15:47+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT=ServerBridge MAC=b6:ab:74:e6:2e:14:2c:dd:e9:13:03:d9:08:00 SRC=34.4.41.43 DST=10.1.1.2 LEN=60 TOS=0x00 PREC=0x60 TTL=55 ID=55218 DF PROTO=TCP SPT=54060 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0 2026-10-08T21:15:48+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT=ServerBridge MAC=b6:ab:74:e6:2e:14:2c:dd:e9:13:03:d9:08:00 SRC=34.4.41.43 DST=10.1.1.2 LEN=60 TOS=0x00 PREC=0x60 TTL=55 ID=55219 DF PROTO=TCP SPT=54060 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0 2026-10-08T21:15:49+00:00 iskariot kernel: AbuseIPDB-Blacklist-Dropped: IN=ens3 OUT=ServerBridge MAC=b6:ab:74:e6:2e:14:2c:dd:e9:13:03:d9:08:00 SRC=34.4.41.43 DST=10.1.1.2 LEN=60 TOS=0x00 PREC=0x60 TTL=55 ID=55220 DF PROTO=TCP SPT=54060 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
show less
Hacking
Bad Web Bot
๐ฉ๐ช
tsZero
2026-10-08 20:07:57
(1 day ago)
Scan example: path=/.git/config status=404
Hacking
๐ณ๐ฑ
Site.eu
2026-10-08 18:24:14
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-08 15:08:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.4.41.43 (43.41.4.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.4.41.43 (43.41.4.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 11:08:44.913887 2026] [security2:error] [pid 7115:tid 7115] [client 34.4.41.43:54106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bennoyes.com"] [uri "/.git/config"] [unique_id "asex_C4fjz-KBzLyK1GpegAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 13:52:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.4.41.43 (43.41.4.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.4.41.43 (43.41.4.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 09:52:36.231592 2026] [security2:error] [pid 18734:tid 18734] [client 34.4.41.43:37938] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bennefeld.k0cgy.net"] [uri "/.git/config"] [unique_id "asegJHAyCMUO9qqWDzj60gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 13:19:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.4.41.43 (43.41.4.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.4.41.43 (43.41.4.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 09:19:28.937558 2026] [security2:error] [pid 14670:tid 14670] [client 34.4.41.43:45612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "benlbrown.com"] [uri "/.git/config"] [unique_id "aseYYPF07hf6HTjpb-t3EAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 13:11:14
(1 day ago)
[ns1.skdns.gr] httpd-suspicious-path: iis-w3c
Hacking
Web App Attack
Anonymous
2026-10-08 09:44:24
(1 day ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.4.41.43 (US/United States/43.41.4.34.bc.g ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 34.4.41.43 (US/United States/43.41.4.34.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 34.4.41.43 - - [08/Oct/2026:11:44:21 +0200] "GET /.env HTTP/1.1" 406 518 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.4.41.43 - - [08/Oct/2026:11:44:22 +0200] "GET /.env.local HTTP/1.1" 406 4888 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.4.41.43 - - [08/Oct/2026:11:44:22 +0200] "GET /.env HTTP/1.1" 406 518 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Port Scan
Anonymous
2026-10-08 09:08:28
(1 day ago)
"GET /.env HTTP/1.1"
Hacking
Web App Attack
๐ธ๐ช
vaia.cloud
2026-10-08 06:35:02
(1 day ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 06:01:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.4.41.43 (43.41.4.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.4.41.43 (43.41.4.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 02:01:19.177966 2026] [security2:error] [pid 9267:tid 9267] [client 34.4.41.43:51056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "benefit-design.com"] [uri "/.git/config"] [unique_id "ascxry-HbGpH0J0M2xqnPwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-08 05:54:41
(2 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-10-08 04:22:18
(2 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ซ๐ท
baphomet
2026-10-08 03:55:16
(2 days ago)
Probed planted web canary URI (not a real app path).
HTTP request completed against planted URIs (.e ...
show more
Probed planted web canary URI (not a real app path).
HTTP request completed against planted URIs (.env/wp-login/xmlrpc/phpmyadmin/.git).
jail=nginx-canary proto=tcp port=80,443 failures>=2 class=web-app-probe
these paths are not real apps on this host; hit is hostile recon
when=2026-10-08T03:55:16Z sensor=fail2ban role=web-canary
src=34.4.41.43
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 03:24:15
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.4.41.43 (43.41.4.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.4.41.43 (43.41.4.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 23:24:10.447736 2026] [security2:error] [pid 13621:tid 13621] [client 34.4.41.43:57518] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bencramerinc.com"] [uri "/.git/config"] [unique_id "ascM2lMrBZjjxVWY8pMLwwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack