πΊπΈ
infra-monitor
2026-09-01 12:00:06
(13 hours ago)
Automated ban via infra-monitor: crowdsecurity/http-sensitive-files, suspicious-probe
Port Scan
Web App Attack
π©πͺ
Roper123
2026-09-01 08:52:01
(16 hours ago)
Web exploits
Web App Attack
π³π±
Savvii
2026-09-01 07:10:26
(17 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
πΈπ¬
naveeddaros
2026-09-01 06:52:02
(18 hours ago)
HTTP Flood DDoS attack detected
Brute-Force
Bad Web Bot
πΈπͺ
nekopavel
2026-09-01 06:19:52
(18 hours ago)
34.50.3.16 - - [01/Sep/2026:08:19:49 +0200]"GET /.git/config HTTP/1.1" 200 1494"-" pavel.gg "Mozilla ...
show more
34.50.3.16 - - [01/Sep/2026:08:19:49 +0200]"GET /.git/config HTTP/1.1" 200 1494"-" pavel.gg "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36""0.000" "-""Seoul" "KR"
34.50.3.16 - - [01/Sep/2026:08:19:50 +0200]"GET /.env HTTP/1.1" 200 1494"-" pavel.gg "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36""0.000" "-""Seoul" "KR"
34.50.3.16 - - [01/Sep/2026:08:19:50 +0200]"GET /.env.local HTTP/1.1" 200 1494"-" pavel.gg "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36""0.000" "-""Seoul" "KR"
...
show less
Hacking
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-09-01 05:55:02
(19 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 04:58:09
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.3.16 (16.3.50.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.3.16 (16.3.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:58:05.128470 2026] [security2:error] [pid 14087:tid 14105] [client 34.50.3.16:37192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paulvester.com"] [uri "/.git/config"] [unique_id "apZbXfaFODPEoRpIu-RpFQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
todix
2026-09-01 04:31:53
(20 hours ago)
Web App Attack Exploid from 34.50.3.16
Web App Attack
π³πΏ
Antinson
2026-09-01 03:52:32
(21 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-01 03:25:45
(21 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.50.3.16 (16.3.50.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:949110) triggered by 34.50.3.16 (16.3.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:25:40.561298 2026] [security2:error] [pid 4849:tid 4849] [client 34.50.3.16:36998] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulnlp.com"] [uri "/.git/config"] [unique_id "apZFtJmIXfs-igIOalRQTgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§π·
Halux
2026-09-01 02:46:57
(22 hours ago)
34.50.3.16 Probing protected path or service
Web App Attack
π¬π§
Apache
2026-09-01 01:30:59
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.3.16 (KR/South Korea/16.3.50.34.bc.google ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.3.16 (KR/South Korea/16.3.50.34.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 00:48:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.50.3.16 (16.3.50.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.3.16 (16.3.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:48:50.506745 2026] [security2:error] [pid 8824:tid 8824] [client 34.50.3.16:53240] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paulbihn.com"] [uri "/.git/config"] [unique_id "apYg8p-1e3YDCWd2dvONvwAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-09-01 00:17:42
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
Anonymous
2026-09-01 00:14:47
(1 day ago)
Malicious Probing
Bad Web Bot