๐ฆ๐บ
Starburst SysOp Team
2026-06-15 15:00:26
(1 day ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-syd2-4)
Hacking
Bad Web Bot
Anonymous
2026-06-15 13:06:17
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.64.227.223 (KR/South Korea/223.227.6 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.64.227.223 (KR/South Korea/223.227.64.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐ธ๐ช
EmK530
2026-06-15 12:38:52
(1 day ago)
URL flagged by RegEx: /v3/.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 08:53:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.64.227.223 (223.227.64.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.227.223 (223.227.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 04:53:36.197078 2026] [security2:error] [pid 20669:tid 20733] [client 34.64.227.223:43094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tristatepropertymgmt.com"] [uri "/htdocs/.git/config"] [unique_id "ai-9kPMvUdVBYVBVG9fefwAAAks"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 07:59:30
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.64.227.223 (223.227.64.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.227.223 (223.227.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 03:59:26.564962 2026] [security2:error] [pid 21268:tid 21268] [client 34.64.227.223:53484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.vintageamptubes.ink2wear.com"] [uri "/frontend/.git/config"] [unique_id "ai-w3veWjqFWTGThYeV2rgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 07:17:35
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.64.227.223 (223.227.64.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.227.223 (223.227.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 03:17:29.079501 2026] [security2:error] [pid 25489:tid 25489] [client 34.64.227.223:45136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "roguetechink.com"] [uri "/v2/.git/config"] [unique_id "ai-nCdgmwGHyWyHGDWpgzQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-15 05:57:24
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 05:57:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.64.227.223 (223.227.64.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.227.223 (223.227.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 01:56:58.598491 2026] [security2:error] [pid 26683:tid 26683] [client 34.64.227.223:39340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.asfmglobal.com"] [uri "/v3/.git/config"] [unique_id "ai-UKpSJVXU3UAB9F5lgyAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-06-15 04:55:51
(2 days ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-06-15 04:51:47
(2 days ago)
34.64.227.223 - - [15/Jun/2026:04:51:46 +0000] "GET /shop/.git/config HTTP/1.1" 404 2814 "-" "Mozill ...
show more
34.64.227.223 - - [15/Jun/2026:04:51:46 +0000] "GET /shop/.git/config HTTP/1.1" 404 2814 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.172 Safari/537.36 Vivaldi/2.5.1525.48"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-15 04:44:38
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฟ
Antinson
2026-06-15 04:22:07
(2 days ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
๐จ๐ญ
4server
2026-06-15 04:20:23
(2 days ago)
[MonJun1506:20:17.3401762026][security2:error][pid1420564:tid1420843][client34.64.227.223:0]ModSecur ...
show more
[MonJun1506:20:17.3401762026][security2:error][pid1420564:tid1420843][client34.64.227.223:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.shakary.com.81-17-25-250.cpanel.site\"][uri\"/html/.git/config\"][unique_id\"ai99gdcR_yLzP501-RgiygAAAQk\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 04:18:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.64.227.223 (223.227.64.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.64.227.223 (223.227.64.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 00:18:23.430448 2026] [security2:error] [pid 3287:tid 3287] [client 34.64.227.223:41082] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.copa.gabosoftware.com"] [uri "/.git/config"] [unique_id "ai99D4PuCLv5LTUuyQz0DAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-15 04:10:02
(2 days ago)
suspicious request in access.log
Web App Attack