π³π±
Savvii
2026-09-27 04:24:30
(4 hours ago)
20 attempts against mh-misbehave-ban on ficus
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-26 21:39:34
(11 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-26 15:59:39
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.78.47.31 (31.47.78.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.47.31 (31.47.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:59:36.237497 2026] [security2:error] [pid 6410:tid 6410] [client 34.78.47.31:33742] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.whaletailbikini.com"] [uri "/.git/config"] [unique_id "arfr6D8ZIR1P7-Wv6uZ5UwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-26 15:11:37
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.78.47.31 (31.47.78.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.47.31 (31.47.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:11:30.788775 2026] [security2:error] [pid 11154:tid 11154] [client 34.78.47.31:44190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.weyoungrenovations.com"] [uri "/.git/config"] [unique_id "arfgok0GRXpT4GeZqdFBzAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-25 19:18:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.78.47.31 (31.47.78.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.47.31 (31.47.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 15:18:44.032401 2026] [security2:error] [pid 7774:tid 7885] [client 34.78.47.31:51284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chriskovac.com"] [uri "/.git/config"] [unique_id "arbJFG6NAc_NRgZB3V_yOgAAAgA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-25 05:48:14
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-24 18:45:54
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.47.31 (31.47.78.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.47.31 (31.47.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:45:49.529078 2026] [security2:error] [pid 21003:tid 21003] [client 34.78.47.31:57758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.helpkccare.org"] [uri "/.git/config"] [unique_id "arVv3WuR3-QXutkUjJJbUAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-24 18:16:42
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.47.31 (31.47.78.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.47.31 (31.47.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:16:37.732084 2026] [security2:error] [pid 20003:tid 20003] [client 34.78.47.31:36066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.heckenbach.org"] [uri "/.git/config"] [unique_id "arVpBQ-Hi4QDDIWk5L3k9AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Thibault Millant
2026-09-23 10:28:56
(3 days ago)
2026/09/23 12:28:55 [error] 1010#1010: *165406 access forbidden by rule, client: 34.78.47.31, server ...
show more
2026/09/23 12:28:55 [error] 1010#1010: *165406 access forbidden by rule, client: 34.78.47.31, server: certifications.millant.ovh, request: "GET /.git/config HTTP/1.1", host: "certifications.millant.ovh"
2026/09/23 12:28:55 [error] 1010#1010: *165406 access forbidden by rule, client: 34.78.47.31, server: certifications.millant.ovh, request: "GET /.env HTTP/1.1", host: "certifications.millant.ovh"
2026/09/23 12:28:55 [error] 1010#1010: *165406 access forbidden by rule, client: 34.78.47.31, server: certifications.millant.ovh, request: "GET /.env.local HTTP/1.1", host: "certifications.millant.ovh"
2026/09/23 12:28:55 [error] 1010#1010: *165406 access forbidden by rule, client: 34.78.47.31, server: certifications.millant.ovh, request: "GET /.env.production HTTP/1.1", host: "certifications.millant.ovh"
2026/09/23 12:28:55 [error] 1010#1010: *165406 access forbidden by rule, client: 34.78.47.31, server: certifications.millant.ovh, request: "GET /.env.staging HTTP/1.1", host: "certifications.m
...
show less
Brute-Force
Exploited Host
Web App Attack
π³π±
homeshowdomain.nl
2026-09-21 22:01:54
(5 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-20.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-09-21 17:15:04
(5 days ago)
suspicious request in access.log
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 16:23:07
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.47.31 (31.47.78.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.47.31 (31.47.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:23:02.416357 2026] [security2:error] [pid 3459:tid 3459] [client 34.78.47.31:47932] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cbsproductionsinc.com"] [uri "/.git/config"] [unique_id "arFZ5lcGPAewjRbbi1KPGwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
big-cloud.nl
2026-09-21 15:41:20
(5 days ago)
Try to access /.git/config
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 17:00:50
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.78.47.31 (31.47.78.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.78.47.31 (31.47.78.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 13:00:44.150207 2026] [security2:error] [pid 5145:tid 5145] [client 34.78.47.31:54224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "enchantmenttours.com"] [uri "/.git/config"] [unique_id "arARPM9kGT_20CA2yVQjEwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 15:39:48
(6 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack