๐ง๐พ
lns.bz
2026-09-30 05:00:55
(18 hours ago)
Too many 404 requests [BY]
Web App Attack
๐ฌ๐ง
consul.to
2026-09-29 05:23:56
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 06:31:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.40.35.42 (42.35.40.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.35.42 (42.35.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 02:31:34.417029 2026] [security2:error] [pid 31855:tid 31855] [client 34.40.35.42:49162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "getitenglish.casademunt.com"] [uri "/.git/config"] [unique_id "aroJxpvTXveBrAwfdqiRywAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-28 05:08:49
(2 days ago)
[livebd] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apach ...
show more
[livebd] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.40.35.42 - - [28/Sep/2026:07:08:46 +0200] "GET /.git/config HTTP/1.1" 404 2142 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.40.35.42 - - [28/Sep/2026:07:08:46 +0200] "GET /.env HTTP/1.1" 404 2142 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.40.35.42 - - [28/Sep/2026:07:08:46 +0200] "GET /.env.local HTTP/1.1" 404 2142 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.40.35.42 - - [28/Sep/2026:07:08:46 +0200] "GET /.env.production HTTP/1.1" 404 2142 "-" "Mozilla/5.0 (
...
show less
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
mcabanas
2026-09-27 07:06:52
(3 days ago)
[ARKAND Sentinel Security Engine] Hostile activity detected & blocked at Linux kernel (iptables). Ta ...
show more
[ARKAND Sentinel Security Engine] Hostile activity detected & blocked at Linux kernel (iptables). Target: geco.org.mx. Reason: RBL Blacklist (Spamhaus XBL): XBL: Botnet / Malware / Servidor Comprometido / Exploit (Crรญtico) en intento de escaneo '/.git/config'. User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36. TLS JA3: 07ff1e545ef8ab3fcf8a4dc9272221c2. Path: GET /.git/config HTTP/1.1.
show less
Port Scan
Hacking
Bad Web Bot
Exploited Host
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-09-27 06:53:20
(3 days ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/42.35.40.34.bc.googleusercontent. ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/42.35.40.34.bc.googleusercontent.com
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-27 05:46:44
(3 days ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
big-cloud.nl
2026-09-27 03:45:01
(3 days ago)
Try to access /.git/config
Web App Attack
๐บ๐ธ
BSG Webmaster
2026-09-26 21:41:45
(4 days ago)
Hacking Attempt using path /old/phpinfo.php
Brute-Force
Web App Attack
๐ฆ๐บ
gregoo23
2026-09-26 21:41:41
(4 days ago)
34.40.35.42 - - [27/Sep/2026:07:41:37 +1000] "GET /pinfo.php HTTP/1.1" 404 70297 "-" "Mozilla/5.0 (X ...
show more
34.40.35.42 - - [27/Sep/2026:07:41:37 +1000] "GET /pinfo.php HTTP/1.1" 404 70297 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.40.35.42 - - [27/Sep/2026:07:41:38 +1000] "GET /test.php HTTP/1.1" 404 70289 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.40.35.42 - - [27/Sep/2026:07:41:39 +1000] "GET /phpinfo HTTP/1.1" 404 70281 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 15:55:53
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.40.35.42 (42.35.40.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.35.42 (42.35.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:55:46.775161 2026] [security2:error] [pid 11284:tid 11284] [client 34.40.35.42:46790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "balay.pamplonaserviciotecnico.com"] [uri "/.git/config"] [unique_id "arfrAqL3jLHH4KUojLRq0wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-26 10:15:02
(4 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 19:47:37
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.40.35.42 (42.35.40.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.35.42 (42.35.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 15:47:29.518990 2026] [security2:error] [pid 19709:tid 19709] [client 34.40.35.42:52920] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "greenlight.us"] [uri "/.git/config"] [unique_id "arbP0VLX0lNNCoG2IzAPFAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-25 06:23:02
(5 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-25 06:07:30
(5 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack