๐ฎ๐ณ
evicky2002
2026-09-24 06:00:03
(4 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-24 05:38:19
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.54.48 (48.54.50.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.54.48 (48.54.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:38:12.373879 2026] [security2:error] [pid 28684:tid 28684] [client 34.50.54.48:60924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "customwww.com"] [uri "/html/.git/config"] [unique_id "arS3RE0i2juJOx7e-wSS1QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-24 04:36:01
(4 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐จ๐ฆ
polycoda
2026-09-24 02:21:14
(4 days ago)
AutoBlock: โ๏ธ Configuration File Access (Non Decay-Based)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 01:50:17
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.54.48 (48.54.50.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.54.48 (48.54.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:50:12.895424 2026] [security2:error] [pid 4221:tid 4266] [client 34.50.54.48:42900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.colinkyffinmusic.com"] [uri "/api/.git/config"] [unique_id "arSB1Nvml7RpJh3mN4nG9wAAAM4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-24 01:15:06
(4 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 00:42:26
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.54.48 (48.54.50.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.54.48 (48.54.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:42:19.440952 2026] [security2:error] [pid 16942:tid 16942] [client 34.50.54.48:48986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.l3l4.com"] [uri "/site/.git/config"] [unique_id "arRx65pLo4zDcPbuDOuEeQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-23 22:50:22
(4 days ago)
[24/Sep/2026:01:50:22 +0300] -- 34.50.54.48 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/c ...
show more
[24/Sep/2026:01:50:22 +0300] -- 34.50.54.48 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
simon boshoff
2026-09-23 21:07:02
(4 days ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐บ๐ธ
Gabriel Camargo
2026-09-23 20:53:13
(4 days ago)
34.50.54.48 - - [23/Sep/2026:15:53:13 -0500] "GET /app/.git/config HTTP/1.1" 301 178 "-" "crusader-w ...
show more
34.50.54.48 - - [23/Sep/2026:15:53:13 -0500] "GET /app/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
34.50.54.48 - - [23/Sep/2026:15:53:13 -0500] "GET /src/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
34.50.54.48 - - [23/Sep/2026:15:53:13 -0500] "GET /www/.git/config HTTP/1.1" 301 178 "-" "crusader-worker/1.0"
...
show less
Brute-Force
SSH
๐ฉ๐ช
4server
2026-09-23 20:21:35
(4 days ago)
[WedSep2322:21:29.5670982026][security2:error][pid2661758:tid2661772][client34.50.54.48:0]ModSecurit ...
show more
[WedSep2322:21:29.5670982026][security2:error][pid2661758:tid2661772][client34.50.54.48:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"ci-ticino.ch.136-243-54-122.cpanel.site\"][uri\"/api/.git/config\"][unique_id\"arQ0ydDfv-I852Yyec6RlQAAAAM\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:00:32
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.50.54.48 (48.54.50.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.54.48 (48.54.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:00:24.115236 2026] [security2:error] [pid 1584:tid 1584] [client 34.50.54.48:58186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cbsproductionsinc.com"] [uri "/public/.git/config"] [unique_id "arQTuKwA49bsMd4BlZ06ywAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-23 17:48:57
(4 days ago)
cloudlinux2 fail2ban: 2026-09-23 19:45:07,479 fail2ban.actions [1603]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-23 19:45:07,479 fail2ban.actions [1603]: NOTICE [plesk-modsecurity] Unban 156.217.39.96cloudlinux2 fail2ban: 2026-09-23 19:45:16,961 fail2ban.filter [1603]: INFO [plesk-modsecurity] Found 34.50.54.48 - 2026-09-23 19:45:16cloudlinux2 fail2ban: 2026-09-23 19:45:16,918 fail2ban.filter [1603]: INFO [plesk-modsecurity] Found 34.50.54.48 - 2026-09-23 19:45:16cloudlinux2 fail2ban: 2026-09-23 19:45:16,969 fail2ban.filter [1603]: INFO [plesk-modsecurity] Found 34.50.54.48 - 2026-09-23 19:45:16cloudlinux2 fail2ban: 2026-09-23 19:45:17,008 fail2ban.filter [1603]: INFO [plesk-modsecurity] Found 34.50.54.48 - 2026-09-23 19:45:16cloudlinux2 fail2ban: 2026-09-23 19:45:16,951 fail2ban.filter [1603]: INFO [plesk-modsecurity] Found 34.50.54.48 - 2026-09-23 19:45:16cloudlinux2 fail2ban: 2026-09-23 19:45:16,928 fail2ban.filter [1603]: INFO [plesk-modsecurity] Found 34.50.54.48 - 2026-09-23 19:45:16cloudlinux2 fail2ban: 2026-09
show less
Brute-Force
Anonymous
2026-09-23 17:28:30
(4 days ago)
2026/09/23 17:28:28 [error] 4746#4746: *260893 [client 34.50.54.48] ModSecurity: Access denied with ...
show more
2026/09/23 17:28:28 [error] 4746#4746: *260893 [client 34.50.54.48] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "carportgh.com"] [uri "/www/.git/config"] [unique_id "179018450883.308848"] [ref ""], client: 34.50.54.48, server: www.carportgh.com, request: "GET /www/.git/config HTTP/1.1", host: "carportgh.com"
2026/09/23 17:28:28 [error] 4746#4746: *260894 [client 34.50.54.48] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecu
...
show less
Brute-Force
๐ณ๐ฑ
Alt255
2026-09-23 17:23:31
(4 days ago)
[ti-03tr] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-03tr] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.50.54.48 - - [23/Sep/2026:19:23:19 +0200] "GET /htdocs/.git/config HTTP/1.1" 403 6274 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack