๐บ๐ธ
TPI-Abuse
2026-09-23 08:06:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.76.99.167 (167.99.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.99.167 (167.99.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 04:06:22.602059 2026] [security2:error] [pid 28015:tid 28015] [client 34.76.99.167:42078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "avalonestates.org"] [uri "/var/www/.git/config"] [unique_id "arOIfomu0SqCLj5Hh94a3QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
ca
2026-09-23 07:10:04
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-09-23 05:57:41
(2 days ago)
CrowdSec blocked IP for crowdsecurity/http-sensitive-files on vps_agent
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 04:02:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.76.99.167 (167.99.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.99.167 (167.99.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 00:02:24.865448 2026] [security2:error] [pid 563:tid 618] [client 34.76.99.167:50356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arizonasolutionsgroup.com"] [uri "/backend/.git/config"] [unique_id "arNPUHftFukqYwPNT3Ic2QAAAMg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
webanyone
2026-09-23 03:32:47
(2 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐จ๐ญ
4server
2026-09-22 23:13:50
(2 days ago)
[WedSep2301:13:43.8820452026][security2:error][pid4006101:tid4006207][client34.76.99.167:0]ModSecuri ...
show more
[WedSep2301:13:43.8820452026][security2:error][pid4006101:tid4006207][client34.76.99.167:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"amservice.ch.81-17-25-250.cpanel.site\"][uri\"/app/.git/config\"][unique_id\"arMLpxHL0hp3YYf-_-nw3wAAAAg\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 22:58:16
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.76.99.167 (167.99.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.99.167 (167.99.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:58:08.983839 2026] [security2:error] [pid 21784:tid 21784] [client 34.76.99.167:37428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amazinggraceministries.net"] [uri "/app/.git/config"] [unique_id "arMIAMvp0xZLl2q0bYXX4gAAAG8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-22 22:29:39
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐จ๐ฆ
john doe
2026-09-22 21:42:18
(2 days ago)
SentinelBot: Secret-path hunting (10 distinct paths): Env File Hunting (score: 58)
Bad Web Bot
๐ซ๐ท
dynamix
2026-09-22 21:28:00
(2 days ago)
Multiple WAF Violations
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-22 21:25:04
(2 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐จ๐ฟ
SystemAdmin
2026-09-22 21:23:56
(2 days ago)
Doing bad things...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 21:01:46
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.76.99.167 (167.99.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.99.167 (167.99.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:01:42.061217 2026] [security2:error] [pid 5510:tid 5510] [client 34.76.99.167:38930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agapeoffice.agapeaccountingllc.com"] [uri "/backend/.git/config"] [unique_id "arLstpXTMdX6UK7d0bjS2QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
stinpriza
2026-09-22 19:57:04
(2 days ago)
common Web Exploits being scanned
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 19:20:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.76.99.167 (167.99.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.99.167 (167.99.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:20:08.200567 2026] [security2:error] [pid 4402:tid 4402] [client 34.76.99.167:60386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adlc18.org"] [uri "/var/www/.git/config"] [unique_id "arLU6Mgg4jaOPXikA5JYYgAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack