๐บ๐ธ
TPI-Abuse
2026-09-03 09:55:49
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.67.93.218 (218.93.67.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.67.93.218 (218.93.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 05:55:44.015475 2026] [security2:error] [pid 7827:tid 7827] [client 34.67.93.218:52564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "understory.us"] [uri "/.git/config"] [unique_id "aplEIGQCBLJbdZaTYn0YMQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-03 09:24:06
(3 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-03 09:18:56
(3 hours ago)
cloudlinux2 fail2ban: 2026-09-03 11:13:46,713 fail2ban.filter [1472]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-03 11:13:46,713 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 35.229.65.180 - 2026-09-03 11:13:46cloudlinux2 fail2ban: 2026-09-03 11:13:55,979 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 34.67.93.218 - 2026-09-03 11:13:55cloudlinux2 fail2ban: 2026-09-03 11:13:55,305 fail2ban.filter [1472]: INFO [plesk-wordpress] Found 193.36.225.183 - 2026-09-03 11:13:55cloudlinux2 fail2ban: 2026-09-03 11:13:46,852 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 35.229.65.180 - 2026-09-03 11:13:46cloudlinux2 fail2ban: 2026-09-03 11:14:04,619 fail2ban.filter [1472]: INFO [plesk-wordpress] Found 172.245.102.40 - 2026-09-03 11:14:04cloudlinux2 fail2ban: 2026-09-03 11:14:05,140 fail2ban.filter [1472]: INFO [recidive] Found 172.245.102.40 - 2026-09-03 11:14:04cloudlinux2 fail2ban: 2026-09-03 11:14:04,866 fail2ban.actions [1472]: NOTICE [plesk-wordpress] Ban 172.245.102.40cloudlinux2 fail2ban: 2026-09-0
show less
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-03 09:04:49
(3 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 1 hits.
show less
Web App Attack
Anonymous
2026-09-02 04:08:46
(1 day ago)
Trying to access config files
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-01 21:59:04
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-31.
show less
Web App Attack
SSH
Hacking
๐จ๐ญ
4server
2026-09-01 20:40:12
(1 day ago)
[TueSep0122:40:06.5814322026][security2:error][pid639041:tid639776][client34.67.93.218:0]ModSecurity ...
show more
[TueSep0122:40:06.5814322026][security2:error][pid639041:tid639776][client34.67.93.218:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"sesael.ch\"][uri\"/.git/config\"][unique_id\"apc4JoYdHnefdaUGXKPI9AAAAAA\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 19:52:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.67.93.218 (218.93.67.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.67.93.218 (218.93.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 15:51:59.935515 2026] [security2:error] [pid 23677:tid 23677] [client 34.67.93.218:3424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rohn.com"] [uri "/.git/config"] [unique_id "apcs31LOGwYBqZaGSvnDLQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-01 18:49:46
(1 day ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:46:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.67.93.218 (218.93.67.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.67.93.218 (218.93.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:46:16.337233 2026] [security2:error] [pid 18775:tid 18775] [client 34.67.93.218:4880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "comicpreservation.com"] [uri "/.git/config"] [unique_id "apae6BHphTH2zaz0Fzqw1AAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:01:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.67.93.218 (218.93.67.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.67.93.218 (218.93.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:01:23.723214 2026] [security2:error] [pid 21892:tid 21892] [client 34.67.93.218:23658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "healingworksmassage.studio"] [uri "/.git/config"] [unique_id "apZ4Qw_Rl-qIctZ5iw3LYAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 06:28:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.67.93.218 (218.93.67.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.67.93.218 (218.93.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 02:28:53.098059 2026] [security2:error] [pid 21905:tid 21905] [client 34.67.93.218:57704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "guitarsouth.com"] [uri "/.git/config"] [unique_id "apZwpW5LaLHXMTho7c7ydwAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 05:10:02
(2 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 04:13:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.67.93.218 (218.93.67.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.67.93.218 (218.93.67.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:13:13.931530 2026] [security2:error] [pid 17287:tid 17287] [client 34.67.93.218:15150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "caferutadelaseda.com"] [uri "/.git/config"] [unique_id "apZQ2eJbUWmHf-sSdWjUYAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-01 04:05:33
(2 days ago)
Abuse Detected (19)
Brute-Force
Web App Attack