🇳🇱
middelkoopcc
2026-09-10 07:38:01
(2 hours ago)
2026-09-10 09:34:31 GET /.git/config [301] && 2026-09-10 09:34:33 GET /.env [301] && 2026-09-10 09:3 ...
show more
2026-09-10 09:34:31 GET /.git/config [301] && 2026-09-10 09:34:33 GET /.env [301] && 2026-09-10 09:34:42 GET /.env.bak [301] && 142 more within 20 minutes
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 06:50:06
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.49.4 (4.49.50.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.49.4 (4.49.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 02:49:57.512279 2026] [security2:error] [pid 25711:tid 25711] [client 34.50.49.4:37684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tourissue.com"] [uri "/.git/config"] [unique_id "aqJTFQpaMBEOKxeILN_DogAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 05:28:46
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.49.4 (4.49.50.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.49.4 (4.49.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 01:28:41.593766 2026] [security2:error] [pid 8668:tid 8668] [client 34.50.49.4:33876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "veenstras.com"] [uri "/.git/config"] [unique_id "aqJACaCBU9XYty_CYKRyngAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-10 04:58:47
(4 hours ago)
Try to access /.git/config
Web App Attack
🇩🇪
Séfora Srl
2026-09-10 00:34:18
(9 hours ago)
crowdsecurity/http-probing detected by CrowdSec
Web App Attack
Anonymous
2026-09-09 21:56:55
(11 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇪🇸
pipeline.es
2026-09-09 19:37:12
(14 hours ago)
Web scanning / probing for vulnerable paths | URL: /.env.old | Evidence: b2b.fitofly.md 34.50.49.4 - ...
show more
Web scanning / probing for vulnerable paths | URL: /.env.old | Evidence: b2b.fitofly.md 34.50.49.4 - - [09/Sep/2026:21:36:02 +0200] \"GET /.env.old HTTP/1.1\" 404 34884 \"-\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=KR | ASN: GOOGLE-CLOUD-PLATFORM | Country: KR
show less
Port Scan
Web App Attack
🇮🇹
VHosting
2026-09-09 19:30:03
(14 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇬🇧
sc user
2026-09-09 19:06:37
(14 hours ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
🇺🇸
TPI-Abuse
2026-09-09 18:55:10
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.49.4 (4.49.50.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.49.4 (4.49.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 14:55:04.561886 2026] [security2:error] [pid 16333:tid 16333] [client 34.50.49.4:52122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "praemiumtech.com"] [uri "/.git/config"] [unique_id "aqGriHf2hcMHbEbktyK5wwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Mangelot Hosting
2026-09-09 18:27:52
(15 hours ago)
(modsecurity) srv104 ModSecurity 34.50.49.4 (KR/South Korea/4.49.50.34.bc.googleusercontent.com): 30 ...
show more
(modsecurity) srv104 ModSecurity 34.50.49.4 (KR/South Korea/4.49.50.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 17:58:40
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.49.4 (4.49.50.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.49.4 (4.49.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 13:58:36.854956 2026] [security2:error] [pid 13268:tid 13268] [client 34.50.49.4:39626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "praedari.com"] [uri "/.git/config"] [unique_id "aqGeTMi9TA86glzMDFJhsAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 16:18:24
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.49.4 (4.49.50.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.49.4 (4.49.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 12:18:19.152155 2026] [security2:error] [pid 17378:tid 17378] [client 34.50.49.4:34582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "markrudin.com"] [uri "/.git/config"] [unique_id "aqGGy-LOJbSUBOcLx7GugQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-09 16:07:03
(17 hours ago)
16.448 4xx requests in 1 hour (5d12h6m)
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-09 15:45:25
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.49.4 (4.49.50.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.49.4 (4.49.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 11:45:21.111104 2026] [security2:error] [pid 17145:tid 17145] [client 34.50.49.4:41956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "markrikey.com"] [uri "/.git/config"] [unique_id "aqF_EUC7WyowGqa0ZwnTNwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack