🇬🇧
consul.to
2026-09-06 04:20:52
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
🇩🇪
gadix
2026-09-06 02:10:43
(2 days ago)
[06/Sep/2026:04:10:42.456940 +0200] apzLoimbBAe7kMfIqr0sSQAAAAA 34.73.228.217 59310 127.0.0.1 7081
[ ...
show more
[06/Sep/2026:04:10:42.456940 +0200] apzLoimbBAe7kMfIqr0sSQAAAAA 34.73.228.217 59310 127.0.0.1 7081
[06/Sep/2026:04:10:42.458663 +0200] apzLorPAp6LIr8tQV4WpnAAAAAk 34.73.228.217 59322 127.0.0.1 7081
[06/Sep/2026:04:10:42.464534 +0200] apzLogDgJHaX8tBendDYjAAAAAQ 34.73.228.217 59336 127.0.0.1 7081
...
show less
Web App Attack
🇩🇪
SwinT
2026-09-06 00:00:12
(3 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
Anonymous
2026-09-05 23:00:03
(3 days ago)
suspicious request in access.log
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-05 22:02:32
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-04.
show less
Web App Attack
SSH
Hacking
🇫🇷
dynamix
2026-09-05 21:39:00
(3 days ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:04:03
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.228.217 (217.228.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.228.217 (217.228.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:03:54.676256 2026] [security2:error] [pid 10209:tid 10209] [client 34.73.228.217:59040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cobbwebb.net"] [uri "/app/.git/config"] [unique_id "apyDurpT-jcHj4buqrsGAwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
Inartis
2026-09-05 11:43:29
(3 days ago)
34.73.228.217 - - [05/Sep/2026:13:43:28 +0200] "GET /.git/config HTTP/1.1" 302 403 "-" "crusader-wor ...
show more
34.73.228.217 - - [05/Sep/2026:13:43:28 +0200] "GET /.git/config HTTP/1.1" 302 403 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 02:09:22
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.228.217 (217.228.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.228.217 (217.228.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 22:09:17.330196 2026] [security2:error] [pid 8299:tid 8299] [client 34.73.228.217:49502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ltrinc.com"] [uri "/site/.git/config"] [unique_id "apt5zeelMev5U9AGXXt9nAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-05 02:07:38
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 34.73.228.217 (US/United States/217.228.73.34.b ...
show more
(mod_security) mod_security (id:949110) triggered by 34.73.228.217 (US/United States/217.228.73.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇩🇪
raph
2026-09-05 01:14:57
(4 days ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇳🇴
jad-abuse
2026-09-04 22:53:06
(4 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, scanner_ua. Observed by 1 sensor(s); 24 hits.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:52:41
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.228.217 (217.228.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.228.217 (217.228.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:52:33.806296 2026] [security2:error] [pid 3732:tid 3732] [client 34.73.228.217:44934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.proyectando.com"] [uri "/var/www/.git/config"] [unique_id "aps9ob6PRvyaZYC192RsQgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 21:11:29
(4 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 21:11:24
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.73.228.217 (217.228.73.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.73.228.217 (217.228.73.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:11:19.547544 2026] [security2:error] [pid 21963:tid 21963] [client 34.73.228.217:36438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.stananddana.com"] [uri "/api/.git/config"] [unique_id "apsz92epvkatIndlSC1_vgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack