Anonymous
2026-09-04 22:05:07
(5 hours ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:31:57
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.128.239 (239.128.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.128.239 (239.128.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:31:51.877132 2026] [security2:error] [pid 16936:tid 16936] [client 34.7.128.239:59130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.district7vote.com"] [uri "/html/.git/config"] [unique_id "aps4x3zzSo6x9VO5MyxObwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 21:07:13
(6 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 20:34:14
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.128.239 (239.128.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.128.239 (239.128.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 16:34:07.460144 2026] [security2:error] [pid 25703:tid 25703] [client 34.7.128.239:47580] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dmh-online.net"] [uri "/public/.git/config"] [unique_id "apsrP4KjUwWsrbiKofn_6AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 20:01:36
(7 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.7.128.239 (239.128.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.7.128.239 (239.128.7.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇮🇹
CoreTech srl
2026-09-04 16:18:56
(11 hours ago)
cloudlinux2 fail2ban: 2026-09-04 18:13:48,327 fail2ban.filter [1594]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-04 18:13:48,327 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 193.19.109.107 - 2026-09-04 18:13:47cloudlinux2 fail2ban: 2026-09-04 18:14:18,667 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 45.146.55.4 - 2026-09-04 18:14:18cloudlinux2 fail2ban: 2026-09-04 18:14:18,623 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 45.146.55.4 - 2026-09-04 18:14:18cloudlinux2 fail2ban: 2026-09-04 18:14:58,356 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Unban 34.14.19.11cloudlinux2 fail2ban: 2026-09-04 18:15:04,724 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 45.131.193.47 - 2026-09-04 18:15:03cloudlinux2 fail2ban: 2026-09-04 18:16:25,273 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 173.239.224.26 - 2026-09-04 18:16:24cloudlinux2 fail2ban: 2026-09-04 18:16:30,117 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 173.239.224.20 - 2026-09-04 18:16:29cloudlinux2 fail2ban: 2026-09-04
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 16:17:37
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.128.239 (239.128.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.128.239 (239.128.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 12:17:30.514201 2026] [security2:error] [pid 9567:tid 9567] [client 34.7.128.239:55336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cyber-matrix.org"] [uri "/htdocs/.git/config"] [unique_id "aprvGs-tMEurEcWvLhXkxwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
Ribeye375
2026-09-04 14:21:28
(13 hours ago)
HIPS recon-attempt - Block tcp/0:65535
Web App Attack
Anonymous
2026-09-04 13:39:19
(14 hours ago)
GET /app/.git/config HTTP/1.1
GET /backend/.git/config HTTP/1.1
GET /src/.git/config HTTP/1.1
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 11:05:39
(16 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇩🇪
raph
2026-09-04 07:22:56
(20 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:49:52
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.7.128.239 (239.128.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.128.239 (239.128.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:49:45.576285 2026] [security2:error] [pid 20197:tid 20197] [client 34.7.128.239:60416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stindustries.us"] [uri "/var/www/.git/config"] [unique_id "appN6Qlch6rySaAE-etURAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-03 23:13:07
(1 day ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 22:27:18
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.7.128.239 (239.128.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.128.239 (239.128.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:27:11.520949 2026] [security2:error] [pid 1591163:tid 1591245] [client 34.7.128.239:60406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "condomanagement360.com"] [uri "/htdocs/.git/config"] [unique_id "apn0P77tXB9Anvi7OzThTAAAAI0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
lolyay
2026-09-03 22:20:48
(1 day ago)
34.7.128.239 - - [03/Sep/2026:22:20:47 +0000] "GET /.git/config HTTP/1.1" 200 1200 "-" "crusader-wor ...
show more
34.7.128.239 - - [03/Sep/2026:22:20:47 +0000] "GET /.git/config HTTP/1.1" 200 1200 "-" "crusader-worker/1.0"
34.7.128.239 - - [03/Sep/2026:22:20:47 +0000] "GET /app/.git/config HTTP/1.1" 200 1200 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Bad Web Bot