๐บ๐ธ
TPI-Abuse
2026-09-23 09:11:20
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.74.140.48 (48.140.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.140.48 (48.140.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 05:11:15.648035 2026] [security2:error] [pid 14898:tid 14898] [client 34.74.140.48:38816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "b9k9.com"] [uri "/src/.git/config"] [unique_id "arOXs8zxfxKJzTSyL86VjwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-23 08:22:27
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
๐จ๐ญ
4server
2026-09-23 08:21:55
(1 hour ago)
[WedSep2310:21:49.5123142026][security2:error][pid437909:tid438036][client34.74.140.48:0]ModSecurity ...
show more
[WedSep2310:21:49.5123142026][security2:error][pid437909:tid438036][client34.74.140.48:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"avvocato.urbani.ch\"][uri\"/site/.git/config\"][unique_id\"arOMHTmlfSbjvfPVkTAI3wAAAJc\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 06:10:29
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.140.48 (48.140.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.140.48 (48.140.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 02:10:24.445680 2026] [security2:error] [pid 368:tid 368] [client 34.74.140.48:34786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.asfmglobal.com"] [uri "/htdocs/.git/config"] [unique_id "arNtUNamytGT8k3OsZYOdAAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-23 05:05:20
(5 hours ago)
[ti-02ov] Web exploit scanning: 8 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02ov] Web exploit scanning: 8 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.74.140.48 - - [23/Sep/2026:07:05:13 +0200] "GET /www/.git/config HTTP/1.1" 301 6299 "-" "crusader-worker/1.0"
34.74.140.48 - - [23/Sep/2026:07:05:13 +0200] "GET /wordpress/.git/config HTTP/1.1" 301 6299 "-" "crusader-worker/1.0"
34.74.140.48 - - [23/Sep/2026:07:05:13 +0200] "GET /var/www/.git/config HTTP/1.1" 301 6299 "-" "crusader-worker/1.0"
34.74.140.48 - - [23/Sep/2026:07:05:13 +0200] "GET /api/.git/config HTTP/1.1" 301 6299 "-" "crusader-worker/1.0"
34.74.140.48 - - [23/Sep/2026:07:05:13 +0200] "GET /site/.git/config HTTP/1.1" 301 6299 "-" "crusader-worker/1.0"
34.74.140.48 - - [23/Sep/2026:07:05:13 +0200] "GET /src/.git/config HTTP/1.1" 301 6299 "-" "crusader-worker/1.0"
34.74.140.48 - - [23/Sep/20
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-23 04:15:34
(5 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 04:01:30
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.140.48 (48.140.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.140.48 (48.140.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 00:01:22.868069 2026] [security2:error] [pid 8196:tid 8196] [client 34.74.140.48:35404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aridscapes.com"] [uri "/app/.git/config"] [unique_id "arNPEowgMqNWgdNphU80ogAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-23 02:05:01
(8 hours ago)
Scanning/Probing (14)
Brute-Force
Web App Attack
Anonymous
2026-09-23 01:15:03
(8 hours ago)
suspicious request in access.log
Web App Attack
Anonymous
2026-09-23 00:07:32
(10 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 23:40:13
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.140.48 (48.140.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.140.48 (48.140.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 19:40:07.373161 2026] [security2:error] [pid 18514:tid 18514] [client 34.74.140.48:51364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "angove.biz"] [uri "/api/.git/config"] [unique_id "arMR1zRc94hBFv3c_6Su-gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-22 22:15:07
(11 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-22 22:00:42
(12 hours ago)
[da.kdns.gr] httpd-config-scan: sites=www.akraion.com; logs=/var/log/httpd/domains/akraion.com.log; ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.akraion.com; logs=/var/log/httpd/domains/akraion.com.log; samples=/public/.git/config | /.git/config | /var/www/.git/config
show less
Hacking
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-09-22 21:16:30
(12 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.74.140.48 (US/United States/48.140.7 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.74.140.48 (US/United States/48.140.74.34.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-09-22 20:06:07
(14 hours ago)
Trying to access config files
Web App Attack