๐บ๐ธ
TPI-Abuse
2026-10-05 00:36:01
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.74.66 (66.74.65.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.74.66 (66.74.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 20:35:55.200856 2026] [security2:error] [pid 23659:tid 23659] [client 34.65.74.66:46676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sifnosgreekcatering.com"] [uri "/.git/config"] [unique_id "asLw64TGGqXGUdUFB_YVyAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-10-05 00:28:34
(4 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 23:18:05
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.74.66 (66.74.65.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.74.66 (66.74.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 19:17:59.052532 2026] [security2:error] [pid 3403214:tid 3403288] [client 34.65.74.66:44926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "siestakeybch.com"] [uri "/.git/config"] [unique_id "asLep20VFKvOQ9AB_HPRoAAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-04 23:09:30
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 22:56:09
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.74.66 (66.74.65.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.74.66 (66.74.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 18:56:03.522142 2026] [security2:error] [pid 8606:tid 8606] [client 34.65.74.66:46844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sierrasatellite.com"] [uri "/.git/config"] [unique_id "asLZg5J5TrxV8f1T1nksDgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-04 22:46:53
(6 hours ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-04 22:11:37
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.74.66 (66.74.65.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.74.66 (66.74.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 18:11:30.305817 2026] [security2:error] [pid 14430:tid 14430] [client 34.65.74.66:42830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sierra-broadcasting.com"] [uri "/.git/config"] [unique_id "asLPEi0GxIMEhpHIVBIrmAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-04 22:03:32
(6 hours ago)
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[mx01aln] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.65.74.66 - - [05/Oct/2026:00:03:22 +0200] "GET /.git/config HTTP/1.1" 301 611 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-04 21:56:50
(6 hours ago)
Excessive multi-domain requests
Brute-Force
๐ง๐ช
cmbplf
2026-10-04 21:33:05
(7 hours ago)
7.976 requests with url.path *.env
1.484 requests with url.path *phpinfo.php
132 requests with ur ...
show more
7.976 requests with url.path *.env
1.484 requests with url.path *phpinfo.php
132 requests with url.path *.php.bak
show less
Brute-Force
Bad Web Bot
๐ฆ๐บ
2000cn.com.au
2026-10-04 20:47:34
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฉ๐ช
FeG Deutschland
2026-10-04 20:21:23
(8 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 20:05:44
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.74.66 (66.74.65.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.74.66 (66.74.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 16:05:38.976402 2026] [security2:error] [pid 16509:tid 16509] [client 34.65.74.66:58112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sieder.com.ar"] [uri "/.git/config"] [unique_id "asKxkhAbl_lcLLQvMYCxbAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-04 19:55:34
(8 hours ago)
Excessive 404/403 errors
Brute-Force
๐จ๐ญ
zynex
2026-10-04 19:48:27
(9 hours ago)
URL Probing: /frontend/.env
Web App Attack