๐ฎ๐น
CoreTech srl
2026-09-21 20:52:35
(53 minutes ago)
cloudlinux2 fail2ban: 2026-09-21 22:03:48,381 fail2ban.actions [1598]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-21 22:03:48,381 fail2ban.actions [1598]: NOTICE [plesk-modsecurity] Ban 34.64.160.13cloudlinux2 fail2ban: 2026-09-21 22:03:47,583 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.64.160.13 - 2026-09-21 22:03:47cloudlinux2 fail2ban: 2026-09-21 22:03:47,828 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.64.160.13 - 2026-09-21 22:03:47cloudlinux2 fail2ban: 2026-09-21 22:03:55,002 fail2ban.actions [1598]: NOTICE [plesk-modsecurity] Unban 34.16.243.103cloudlinux2 fail2ban: 2026-09-21 22:03:48,073 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.64.160.13 - 2026-09-21 22:03:48cloudlinux2 fail2ban: 2026-09-21 22:03:47,082 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.64.160.13 - 2026-09-21 22:03:47cloudlinux2 fail2ban: 2026-09-21 22:03:48,318 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 34.64.160.13 - 2026-09-21 22:03:48cloudlinux2 fail2ban: 2026-09-21 22:03:48,388 f
show less
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-21 19:10:44
(2 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-21 18:38:55
(3 hours ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
sandra361
2026-09-21 18:05:04
(3 hours ago)
Cloudflare WAF: 27 requests / 25 unique paths from AS396982/KR | Action: block, link_maze_injected | ...
show more
Cloudflare WAF: 27 requests / 25 unique paths from AS396982/KR | Action: block, link_maze_injected | GET, POST HTTP/1.1 | Paths: /, /.env.development, /.env.json, /.env2, /application_default_credentials.json, /bin/.env, /firebase-key.json, /github/.env (+17 more) | Cloudflare Detected: React - RCE - CVE:CVE-2025-55182 | User Agent: 2 UAs (e.g. Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36)
show less
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-21 17:15:03
(4 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 17:08:00
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.64.160.13 (13.160.64.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.160.13 (13.160.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:07:54.459297 2026] [security2:error] [pid 16785:tid 16785] [client 34.64.160.13:47264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sandpointidaho.com"] [uri "/.git/config"] [unique_id "arFkapcAzsbCp7iPrWK1zwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 13:45:18
(4 days ago)
Observed scanned 12 known-sensitive endpoint(s), e.g.: /, /.env.old, /.git/config, /_phpinfo.php, /a ...
show more
Observed scanned 12 known-sensitive endpoint(s), e.g.: /, /.env.old, /.git/config, /_phpinfo.php, /api/staging/.env, /backups/.env
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
kumiko
2026-09-17 04:20:22
(4 days ago)
[2026-09-17 07:20:22] Probing for dotfiles
"GET /.git/config HTTP/1.1" 403
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-09-17 03:04:13
(4 days ago)
URL Probing: /server/.env
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-09-17 03:04:01
(4 days ago)
2026-09-17 05:00:18 GET /.git/config [404] && 2026-09-17 05:00:20 GET /.env [404] && 2026-09-17 05:0 ...
show more
2026-09-17 05:00:18 GET /.git/config [404] && 2026-09-17 05:00:20 GET /.env [404] && 2026-09-17 05:00:27 GET /.env.bak [404] && 153 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 02:53:36
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.64.160.13 (13.160.64.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.160.13 (13.160.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:53:29.691581 2026] [security2:error] [pid 24066:tid 24066] [client 34.64.160.13:38108] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "somewierdness.com"] [uri "/.git/config"] [unique_id "aqtWKfbNdP3YhVxStgdY8QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-17 02:30:14
(4 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 17:48:22
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.64.160.13 (13.160.64.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.160.13 (13.160.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 13:48:16.862011 2026] [security2:error] [pid 167113:tid 167113] [client 34.64.160.13:58880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saltyrootsyogaco.com"] [uri "/.git/config"] [unique_id "aqrWYDs8whS3RQSXjWX4BAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 17:18:29
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.64.160.13 (13.160.64.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.160.13 (13.160.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 13:18:25.077582 2026] [security2:error] [pid 21009:tid 21034] [client 34.64.160.13:36242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "saltflowlogistics.com"] [uri "/.git/config"] [unique_id "aqrPYYG4gW-vSRYOGmV7-gAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 16:54:55
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.64.160.13 (13.160.64.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.160.13 (13.160.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:54:52.599544 2026] [security2:error] [pid 24708:tid 24708] [client 34.64.160.13:42604] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "salsberggroup.com"] [uri "/.git/config"] [unique_id "aqrJ3ArtjboHZ0X3RC491wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack