๐ฒ๐พ
Rizzy
2026-09-02 06:00:28
(1 hour ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 05:39:25
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.75.130.99 (99.130.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.130.99 (99.130.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 01:39:18.019010 2026] [security2:error] [pid 1879:tid 1879] [client 34.75.130.99:33820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.privateshoretours.com"] [uri "/html/.git/config"] [unique_id "ape2hlhEStF-F7mOOLZXQAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 04:50:35
(2 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐จ๐ญ
4server
2026-09-02 04:40:47
(2 hours ago)
[WedSep0206:40:44.6300292026][security2:error][pid2247025:tid2247469][client34.75.130.99:0]ModSecuri ...
show more
[WedSep0206:40:44.6300292026][security2:error][pid2247025:tid2247469][client34.75.130.99:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"mail.giardinonoleggioticino.ch\"][uri\"/htdocs/.git/config\"][unique_id\"apeozEJLiRs7yaq7hepHMwAAAVQ\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-02 04:15:59
(3 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.git (Match: /.git)
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-02 03:35:16
(4 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-09-02 01:44:36
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.130.99 (99.130.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.130.99 (99.130.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 21:44:28.023315 2026] [security2:error] [pid 25019:tid 25019] [client 34.75.130.99:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.ralphrichardson.com"] [uri "/html/.git/config"] [unique_id "apd_fI12D7w8aZ9yqMUIaAAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 00:44:19
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.75.130.99 (99.130.75.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.75.130.99 (99.130.75.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 20:44:12.344568 2026] [security2:error] [pid 27594:tid 27594] [client 34.75.130.99:56314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gnquivers.com"] [uri "/public/.git/config"] [unique_id "apdxXDwlrPbSU5ISrIFBqAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-02 00:13:27
(7 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.75.130.99 (US/United States/99.130 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.75.130.99 (US/United States/99.130.75.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
etu brutus
2026-09-02 00:02:11
(7 hours ago)
34.75.130.99 has been banned for [WebApp Attack]
...
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-02 00:01:02
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
mnsf
2026-09-01 20:05:24
(11 hours ago)
Scanning/Probing (17)
Brute-Force
Web App Attack
๐บ๐ธ
leasj
2026-09-01 17:58:55
(13 hours ago)
Observed Scanned 12 known-sensitive endpoint(s), e.g.: /app/.git/config, /public/.git/config, /var/w ...
show more
Observed Scanned 12 known-sensitive endpoint(s), e.g.: /app/.git/config, /public/.git/config, /var/www/.git/config, /www/.git/config, /src/.git/config.
show less
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ด
Bots.go.to.hell
2026-09-01 15:23:58
(16 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฌ๐ง
consul.to
2026-09-01 12:11:02
(19 hours ago)
Web attack/malicious scanning detected
Web App Attack