๐บ๐ธ
factor1
2026-09-02 16:26:08
(3 minutes ago)
CrowdSec at saturn Reports Abuse
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 12:37:32
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.51.129.249 (249.129.51.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.51.129.249 (249.129.51.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 08:37:28.034540 2026] [security2:error] [pid 18135:tid 18135] [client 34.51.129.249:43102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "proinser.imerka.com.mx"] [uri "/.git/config"] [unique_id "apgYiAYqcXwHMrSrUE40gQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 11:40:45
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.51.129.249 (249.129.51.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.51.129.249 (249.129.51.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 07:40:38.667025 2026] [security2:error] [pid 17030:tid 17030] [client 34.51.129.249:51032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "progresstraining.info"] [uri "/.git/config"] [unique_id "apgLNrAE0YyQyUcKjdJIqwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 11:19:02
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.51.129.249 (249.129.51.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.51.129.249 (249.129.51.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 07:18:55.643479 2026] [security2:error] [pid 17909:tid 17909] [client 34.51.129.249:39526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "progressivefileshare.org"] [uri "/.git/config"] [unique_id "apgGH3ju5SpUxwaIft5wxQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Dunham Support
2026-09-02 11:17:15
(5 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.51.129.249 (SE/Sweden/249.129.51.34. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.51.129.249 (SE/Sweden/249.129.51.34.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-09-02 11:05:16
(5 hours ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-02 09:34:58
(6 hours ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
enpepet
2026-09-02 09:10:53
(7 hours ago)
GENERAL: parametres: [url:git=] UA:Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like G ...
show more
GENERAL: parametres: [url:git=] UA:Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 URL:/.git/config
show less
Port Scan
Hacking
Brute-Force
Bad Web Bot
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-02 09:05:15
(7 hours ago)
2026/09/02 10:05:08 [error] 380594#380594: *2251268 access forbidden by rule, client: 34.51.129.249, ...
show more
2026/09/02 10:05:08 [error] 380594#380594: *2251268 access forbidden by rule, client: 34.51.129.249, server: centroestudostibetanos.org, request: "GET /.env HTTP/1.1", host: "programanalanda.centroestudostibetanos.org"
34.51.129.249 - - [02/Sep/2026:10:05:08 +0100] "GET /.env HTTP/1.1" 403 1057 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026/09/02 10:05:14 [error] 380594#380594: *2251262 access forbidden by rule, client: 34.51.129.249, server: centroestudostibetanos.org, request: "GET /app/.env HTTP/1.1", host: "programanalanda.centroestudostibetanos.org"
show less
Brute-Force
Web App Attack
Anonymous
2026-09-02 08:55:01
(7 hours ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
TheDjRider
2026-09-02 08:15:30
(8 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-02T08:15:26.826493505Z. Context: http_status=404
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-09-02 08:04:13
(8 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-02 07:06:10
(9 hours ago)
34.51.129.249 - - [02/Sep/2026:09:06:10 +0200] "GET /.git/config HTTP/1.1" 301 169 "-" "Mozilla/5.0 ...
show more
34.51.129.249 - - [02/Sep/2026:09:06:10 +0200] "GET /.git/config HTTP/1.1" 301 169 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Web App Attack
๐ซ๐ท
Octopuce
2026-09-02 07:04:57
(9 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐ฌ๐ง
gws-hostmaster
2026-09-02 06:26:00
(10 hours ago)
ModSecurity OWASP CRS (Anomaly Score: 50): JavaScript Prototype Pollution;JSON-Based SQL Injection;N ...
show more
ModSecurity OWASP CRS (Anomaly Score: 50): JavaScript Prototype Pollution;JSON-Based SQL Injection;Node.js Injection Attack 1/2;PHP Injection Attack: Variable Access Found;Remote Command Execution: Direct Unix Command Execution;Remote Command Execution: Unix Shell Expression Found;Restricted File Access Attempt;SQL Injection Attack: SQL function name detected;URL file extension is restricted by policy;
show less
Web App Attack