๐บ๐ธ
TPI-Abuse
2026-08-31 19:09:49
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.64.136.2 (2.136.64.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.136.2 (2.136.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 15:09:41.017278 2026] [security2:error] [pid 8534:tid 8534] [client 34.64.136.2:46186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "riversidecabinswv.com"] [uri "/.git/config"] [unique_id "apXRdUO3wfNKIMwiVXnY_QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 17:34:35
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.64.136.2 (2.136.64.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.136.2 (2.136.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 13:34:28.425842 2026] [security2:error] [pid 27137:tid 27137] [client 34.64.136.2:53538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rivercityacct.com"] [uri "/.git/config"] [unique_id "apW7JCYlXc9GRx0gLWvOgwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
leo1305
2026-08-31 16:45:44
(2 weeks ago)
CrowdSec detection | scenario: http-sensitive-files
Web App Attack
Exploited Host
๐ซ๐ท
Octopuce
2026-08-31 16:41:06
(2 weeks ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 15:07:29
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.64.136.2 (2.136.64.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.136.2 (2.136.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 11:07:25.901927 2026] [security2:error] [pid 32665:tid 32665] [client 34.64.136.2:44918] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ritterlien.com"] [uri "/.git/config"] [unique_id "apWYrd0X7ekRqroF5wOsEwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-31 15:07:24
(2 weeks ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
Marc
2026-08-31 12:30:47
(2 weeks ago)
34.64.136.2 - - [31/Aug/2026:14:30:45 +0200] "GET /.git/config HTTP/1.1" 404 705 "-" "Mozilla/5.0 (W ...
show more
34.64.136.2 - - [31/Aug/2026:14:30:45 +0200] "GET /.git/config HTTP/1.1" 404 705 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 34.64.136.2 - - [31/Aug/2026:14:30:46 +0200] "GET /.env HTTP/1.1" 404 705 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 34.64.136.2 - - [31/Aug/2026:14:30:46 +0200] "GET /.env.local HTTP/1.1" 404 705 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Brute-Force
๐บ๐ธ
infra-monitor
2026-08-31 12:00:11
(2 weeks ago)
Automated ban via infra-monitor: suspicious-probe, crowdsecurity/http-sensitive-files
Port Scan
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-31 11:13:56
(2 weeks ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-08-31 08:24:40
(2 weeks ago)
[MonAug3110:24:34.9423142026][security2:error][pid2421798:tid2421826][client34.64.136.2:0]ModSecurit ...
show more
[MonAug3110:24:34.9423142026][security2:error][pid2421798:tid2421826][client34.64.136.2:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"risanamento-funghi-muffa.ch\"][uri\"/\"][unique_id\"apU6Qmkr6ZwbCVWxqvq7NQAAABE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
IloGus
2026-08-31 07:00:58
(2 weeks ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ซ๐ท
masterguru
2026-08-31 06:25:52
(2 weeks ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐ณ๐ฑ
Savvii
2026-08-31 04:58:03
(2 weeks ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-08-31 04:50:02
(2 weeks ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐จ๐ญ
ALPHANET
2026-08-31 04:36:31
(2 weeks ago)
web exploits
Hacking
Exploited Host
Web App Attack