๐จ๐ญ
TheCoon
2026-06-10 12:30:02
(23 hours ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐ง๐ท
Peregrine
2026-06-10 03:13:29
(1 day ago)
Fail2Ban S3 Jail: tomcat-honeypot | Evidence: - 34.50.105.96 - - [08/Jun/2026:08:36:57 -0300] "GET / ...
show more
Fail2Ban S3 Jail: tomcat-honeypot | Evidence: - 34.50.105.96 - - [08/Jun/2026:08:36:57 -0300] "GET /.git/config HTTP/1.1" 404 414
show less
Bad Web Bot
๐ซ๐ท
masterguru
2026-06-09 15:44:05
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.50.105.96 (ID/Indonesia/96.105.50. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.50.105.96 (ID/Indonesia/96.105.50.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ฉ๐ช
Progetto1
2026-06-09 14:28:02
(1 day ago)
Detected via HAProxyScanner at 2026-06-09 14:28:01 UTC on destination port WEB (80/443). Repeated sc ...
show more
Detected via HAProxyScanner at 2026-06-09 14:28:01 UTC on destination port WEB (80/443). Repeated scan / connection.
show less
Port Scan
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-09 14:21:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.50.105.96 (96.105.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.105.96 (96.105.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 10:21:37.984091 2026] [security2:error] [pid 26128:tid 26135] [client 34.50.105.96:48634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "forestancestry.com"] [uri "/.git/config"] [unique_id "aighcVIK1jRyHLWrY6mTcQAAAUU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 13:36:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.50.105.96 (96.105.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.105.96 (96.105.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 09:36:28.732460 2026] [security2:error] [pid 13888:tid 13888] [client 34.50.105.96:44320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "doreenkimura.com"] [uri "/.git/config"] [unique_id "aigW3N-tBEOBCJTF48Au8QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 12:41:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.50.105.96 (96.105.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.105.96 (96.105.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 08:41:00.235818 2026] [security2:error] [pid 21804:tid 21804] [client 34.50.105.96:50764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nesetsv.com"] [uri "/.git/config"] [unique_id "aigJ3I4QLoOwHYkqgVGH9AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 12:17:01
(1 day ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 10:29:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.105.96 (96.105.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.105.96 (96.105.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 06:29:50.960655 2026] [security2:error] [pid 23526:tid 23526] [client 34.50.105.96:38546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kaleidoscope-glass.com"] [uri "/.git/config"] [unique_id "aifrHmABMIuiYjE-r4Oi-QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 07:45:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.105.96 (96.105.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.105.96 (96.105.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 03:45:47.937810 2026] [security2:error] [pid 13207:tid 13207] [client 34.50.105.96:37302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.prueba.victotex.com"] [uri "/.git/config"] [unique_id "aifEq14lFBqC-eIm-BskKAAAAHs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 06:46:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.105.96 (96.105.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.105.96 (96.105.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 02:46:19.692020 2026] [security2:error] [pid 31937:tid 31937] [client 34.50.105.96:47888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "archief.org"] [uri "/.git/config"] [unique_id "aie2u_2GgcRlToPCktCfkwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-09 05:59:55
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
4server
2026-06-09 04:25:42
(2 days ago)
[TueJun0906:25:40.1229292026][security2:error][pid2328470:tid2328637][client34.50.105.96:0]ModSecuri ...
show more
[TueJun0906:25:40.1229292026][security2:error][pid2328470:tid2328637][client34.50.105.96:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.vivereiltrentino.it\"][uri\"/.git/config\"][unique_id\"aieVxCBLUU_-lA1pRhrGAwAAANY\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 03:14:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.105.96 (96.105.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.105.96 (96.105.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 23:14:37.275259 2026] [security2:error] [pid 15434:tid 15434] [client 34.50.105.96:50580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bankcardtexas.soviaenterprises.com"] [uri "/.git/config"] [unique_id "aieFHfQNCXO-S1lQ_QDQoAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
ludarkstar99
2026-06-09 02:25:12
(2 days ago)
Blocked by os-abuseipdb; 10 hits, proto=tcp, ports=443,80
Port Scan
Hacking