๐ซ๐ท
Catalin Negru
2026-06-14 11:44:21
(1 hour ago)
2026-06-14 14:44:20,822 fail2ban.actions [2945670]: NOTICE [apache-404] Ban 34.47.189.241
20 ...
show more
2026-06-14 14:44:20,822 fail2ban.actions [2945670]: NOTICE [apache-404] Ban 34.47.189.241
2026-06-14 14:44:21,023 fail2ban.actions [2945670]: NOTICE [apache-dirscan] Ban 34.47.189.241
2026-06-14 14:44:21,110 fail2ban.actions [2945670]: NOTICE [apache-security] Ban 34.47.189.241
2026-06-14 14:44:21,160 fail2ban.actions [2945670]: NOTICE [apache-scan] Ban 34.47.189.241
2026-06-14 14:44:21,191 fail2ban.actions [2945670]: NOTICE [web-scanner] Ban 34.47.189.241
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
gadix
2026-06-14 10:06:23
(3 hours ago)
[14/Jun/2026:12:06:22.145997 +0200] ai59HpVrpyBnZqDJwzyaPgAAAMM 34.47.189.241 50390 127.0.0.1 7081
[ ...
show more
[14/Jun/2026:12:06:22.145997 +0200] ai59HpVrpyBnZqDJwzyaPgAAAMM 34.47.189.241 50390 127.0.0.1 7081
[14/Jun/2026:12:06:22.146563 +0200] ai59HnBHAN4dLqRC7mm88gAAARQ 34.47.189.241 50394 127.0.0.1 7081
[14/Jun/2026:12:06:22.196230 +0200] ai59HpVrpyBnZqDJwzyaPwAAANM 34.47.189.241 50398 127.0.0.1 7081
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 07:09:14
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.47.189.241 (241.189.47.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.189.241 (241.189.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 03:09:10.039649 2026] [security2:error] [pid 26225:tid 26225] [client 34.47.189.241:48620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "markthwaite.com"] [uri "/.git/config"] [unique_id "ai5Tlu0dplO5jLCocJsDQQAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sigurg
2026-06-14 05:28:22
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-14 05:10:56
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.47.189.241 (241.189.47.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.189.241 (241.189.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 01:10:51.956831 2026] [security2:error] [pid 14410:tid 14410] [client 34.47.189.241:45318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thesweeneys.ws"] [uri "/src/.git/config"] [unique_id "ai432xQnFfYya0EYhh5OlAAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
INTEQ
2026-06-14 05:02:02
(8 hours ago)
Web attack from 34.47.189.241
Web App Attack
๐บ๐ธ
mnsf
2026-06-14 04:09:51
(9 hours ago)
Too many Status 40X (12)
Scanning/Probing (15)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 02:40:37
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.47.189.241 (241.189.47.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.189.241 (241.189.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 22:40:32.208093 2026] [security2:error] [pid 5074:tid 5074] [client 34.47.189.241:37264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "es.laboquimia.es"] [uri "/static/.git/config"] [unique_id "ai4UoAguM2oWppeIv15vIQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 02:21:37
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.47.189.241 (241.189.47.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.189.241 (241.189.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 22:21:33.623406 2026] [security2:error] [pid 14741:tid 14741] [client 34.47.189.241:43810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.californiastarsfarm.com.herston.net"] [uri "/backend/.git/config"] [unique_id "ai4QLTYLwQ0bZzsKIjzDeQAAAGU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-14 02:00:01
(11 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 01:46:18
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.47.189.241 (241.189.47.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.189.241 (241.189.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 21:46:11.781171 2026] [security2:error] [pid 23466:tid 23466] [client 34.47.189.241:52362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.summercampregistration.wholesalelivelobsters.com"] [uri "/app/.git/config"] [unique_id "ai4H4ylyzbNjt-iWSJ3YVAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-06-14 01:43:54
(11 hours ago)
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:443 34.47.189.241 - - [14/Jun/2026:0 ...
show more
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:443 34.47.189.241 - - [14/Jun/2026:02:43:52 +0100] GET /assets/.git/config HTTP/1.1 403 3035 - Mozilla/5.0 (Linux; U; Android 1.6; en-us; SonyEricssonX10i Build/R1AA056) AppleWebKit/528.5 (KHTML, like Gecko) Version/3.1.2 Mobile Safari/525.20.1
show less
Web App Attack
Anonymous
2026-06-14 00:56:44
(12 hours ago)
[Sun Jun 14 02:56:43.975558 2026] [authz_core:error] [pid 248098] [client 34.47.189.241:57082] AH016 ...
show more
[Sun Jun 14 02:56:43.975558 2026] [authz_core:error] [pid 248098] [client 34.47.189.241:57082] AH01630: client denied by server configuration: /var/www/html/default/web
[Sun Jun 14 02:56:44.014655 2026] [authz_core:error] [pid 248101] [client 34.47.189.241:57088] AH01630: client denied by server configuration: /var/www/html/default/.git
[Sun Jun 14 02:56:44.047398 2026] [authz_core:error] [pid 248102] [client 34.47.189.241:57094] AH01630: client denied by server configuration: /var/www/html/default/app
[Sun Jun 14 02:56:44.099900 2026] [authz_core:error] [pid 248096] [client 34.47.189.241:57104] AH01630: client denied by server configuration: /var/www/html/default/dashboard
[Sun Jun 14 02:56:44.119029 2026] [authz_core:error] [pid 248095] [client 34.47.189.241:57106] AH01630: client denied by server configuration: /var/www/html/default/api
...
show less
Web App Attack