๐ฌ๐ง
consul.to
2026-08-30 00:04:58
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 22:55:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.57.190.139 (139.190.57.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.57.190.139 (139.190.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 18:55:43.313073 2026] [security2:error] [pid 8534:tid 8543] [client 34.57.190.139:57230] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "emmaryan.yrcs.net"] [uri "/htdocs/.git/config"] [unique_id "apNjbw6FIqHbJlroR3NtEwAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-28 22:03:36
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-27.
show less
Web App Attack
SSH
Hacking
๐ฟ๐ฆ
conure.sh
2026-08-28 12:14:39
(2 days ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
๐ซ๐ท
dynamix
2026-08-27 22:53:06
(3 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
mnsf
2026-08-27 20:05:23
(3 days ago)
Too many Status 50X (24)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:24:59
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.57.190.139 (139.190.57.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.57.190.139 (139.190.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:24:54.175025 2026] [security2:error] [pid 3238812:tid 3239205] [client 34.57.190.139:45968] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.the-aquifer.com.giere.us"] [uri "/.git/config"] [unique_id "apBy5hRRnOZfqEvuY1nHMwAAAQU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 16:43:26
(3 days ago)
34.57.190.139 - - [27/Aug/2026:18:43:26 +0200] "GET /app/.git/config HTTP/1.1" 301 169 "-" "crusader ...
show more
34.57.190.139 - - [27/Aug/2026:18:43:26 +0200] "GET /app/.git/config HTTP/1.1" 301 169 "-" "crusader-worker/1.0"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 16:24:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.57.190.139 (139.190.57.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.57.190.139 (139.190.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 12:24:45.689126 2026] [security2:error] [pid 12411:tid 12411] [client 34.57.190.139:41496] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "qcyprus.com"] [uri "/htdocs/.git/config"] [unique_id "apBkzTHedRC5u3Kiqtx9YwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 16:15:01
(3 days ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
4server
2026-08-27 15:48:42
(3 days ago)
[ThuAug2717:48:37.4104292026][security2:error][pid1389175:tid1389224][client34.57.190.139:0]ModSecur ...
show more
[ThuAug2717:48:37.4104292026][security2:error][pid1389175:tid1389224][client34.57.190.139:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"mgevents.ch.136-243-54-122.cpanel.site\"][uri\"/wordpress/.git/config\"][unique_id\"apBcVdbxaFUg5f5FJbMJNQAAAYs\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
Sรฉfora Srl
2026-08-27 13:37:04
(3 days ago)
crowdsecurity/http-probing detected by CrowdSec
Web App Attack
๐ฎ๐น
mediarama.com
2026-08-27 13:12:56
(3 days ago)
Banned by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 12:39:29
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.57.190.139 (139.190.57.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.57.190.139 (139.190.57.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 08:39:23.642187 2026] [security2:error] [pid 25522:tid 25522] [client 34.57.190.139:50172] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.title36.itaxcenter.com"] [uri "/html/.git/config"] [unique_id "apAv-519gsNP0FAHA8tbmwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
masterguru
2026-08-27 12:28:59
(3 days ago)
. Matched phrase "/.git/" at REQUEST_URI. (210492-145)
Web App Attack