🇿🇦
conure.sh
2026-09-12 12:01:33
(1 hour ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 1s
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 10:24:01
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.65.250 (250.65.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.65.250 (250.65.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 06:23:53.939594 2026] [security2:error] [pid 1081:tid 1081] [client 34.50.65.250:46608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rosarymaker.com"] [uri "/.git/config"] [unique_id "aqUoObMHd0EF2q90RHCUngAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Alt255
2026-09-12 10:09:24
(3 hours ago)
34.50.65.250 - - [12/Sep/2026:12:09:24 +0200] "GET /.git/config HTTP/1.1" 404 2126 "-" "Mozilla/5.0 ...
show more
34.50.65.250 - - [12/Sep/2026:12:09:24 +0200] "GET /.git/config HTTP/1.1" 404 2126 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 09:02:28
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.65.250 (250.65.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.65.250 (250.65.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 05:02:22.788508 2026] [security2:error] [pid 9244:tid 9244] [client 34.50.65.250:39944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rosalbaespinosa.com"] [uri "/.git/config"] [unique_id "aqUVHg4jY3MSFPy2iL69nAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
sdos.es
2026-09-12 08:28:27
(5 hours ago)
"Remote Command Execution: Unix Shell Expression Found - Matched Data: $((41*271)) found within ARGS ...
show more
"Remote Command Execution: Unix Shell Expression Found - Matched Data: $((41*271)) found within ARGS:0: {then: $1:__proto__:then status: resolved_model reason: -1 value: {then:$b1337} _response: {_prefix: var res=process.mainmodule.require(child_process).execsync(echo $((41*271)) | base64 -w 0).tostring().trim() throw object.assign(new error(next_redirect) {digest: `next_redirect push/login?a=${res} 307 `}) _chunks: $q2 _formdata: {get: $1:constructor:constructor}}}"
show less
Web App Attack
🇷🇴
iulianh
2026-09-12 07:59:14
(5 hours ago)
80,443
Brute-Force
SSH
🇸🇪
vaia.cloud
2026-09-12 07:35:02
(6 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-12 07:00:21
(6 hours ago)
Excessive multi-domain requests
Brute-Force
🇮🇹
VHosting
2026-09-12 06:40:03
(6 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 06:31:58
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.65.250 (250.65.50.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.65.250 (250.65.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 02:31:54.088838 2026] [security2:error] [pid 30454:tid 30454] [client 34.50.65.250:42454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ropesandsneakers.com.flatchestedmama.com"] [uri "/.git/config"] [unique_id "aqTx2qH01-s29tL-z-fDqAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Roper123
2026-09-12 06:28:07
(7 hours ago)
Web exploits
Web App Attack
🇳🇱
Alt255
2026-09-12 06:22:02
(7 hours ago)
34.50.65.250 - - [12/Sep/2026:08:22:01 +0200] "GET /.git/config HTTP/1.1" 301 617 "-" "Mozilla/5.0 ( ...
show more
34.50.65.250 - - [12/Sep/2026:08:22:01 +0200] "GET /.git/config HTTP/1.1" 301 617 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇩🇪
Gwyneth Llewelyn
2026-09-11 21:53:44
(15 hours ago)
2026/09/11 22:53:36 [error] 1267648#1267648: *217923 access forbidden by rule, client: 34.50.65.250, ...
show more
2026/09/11 22:53:36 [error] 1267648#1267648: *217923 access forbidden by rule, client: 34.50.65.250, server: regapi.betatechnologies.info, request: "GET /.env HTTP/1.1", host: "regapi.betatechnologies.info"
34.50.65.250 - - [11/Sep/2026:22:53:36 +0100] "GET /.env HTTP/1.1" 403 1178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026/09/11 22:53:42 [error] 1267648#1267648: *217923 access forbidden by rule, client: 34.50.65.250, server: regapi.betatechnologies.info, request: "GET /app/.env HTTP/1.1", host: "regapi.betatechnologies.info"
show less
Brute-Force
Web App Attack
🇩🇪
netclix.gr
2026-09-11 17:48:02
(19 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.50.65.250 (ID/Indonesia/250.65.50.34 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.50.65.250 (ID/Indonesia/250.65.50.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
🇺🇸
Rip
2026-09-11 17:31:36
(20 hours ago)
403 Errors: Access Forbidden
Brute-Force