🇫🇮
NoaQT
2026-09-06 08:48:06
(3 hours ago)
2026-09-06T08:48:05.757433+00:00 ingress-1 haproxy[16887]: 34.82.224.196:42950 [06/Sep/2026:08:48:05 ...
show more
2026-09-06T08:48:05.757433+00:00 ingress-1 haproxy[16887]: 34.82.224.196:42950 [06/Sep/2026:08:48:05.756] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 68/68/0/0/0 0/0 "GET /.mcp.json HTTP/1.1"
2026-09-06T08:48:05.764313+00:00 ingress-1 haproxy[16887]: 34.82.224.196:42952 [06/Sep/2026:08:48:05.763] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 69/69/0/0/0 0/0 "GET /mcp.json HTTP/1.1"
2026-09-06T08:48:05.774326+00:00 ingress-1 haproxy[16887]: 34.82.224.196:42968 [06/Sep/2026:08:48:05.773] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 70/70/0/0/0 0/0 "GET /mcp_config.json HTTP/1.1"
2026-09-06T08:48:05.792694+00:00 ingress-1 haproxy[16887]: 34.82.224.196:42978 [06/Sep/2026:08:48:05.792] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 71/71/0/0/0 0/0 "GET /.cursor/mcp.json HTTP/1.1"
2026-09-06T08:48:05.792762+00:00 ingress-1 haproxy[16887]: 34.82.224.196:42800 [06/Sep/2026:08:48:05.792] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 71/71
...
show less
DDoS Attack
🇧🇾
lns.bz
2026-09-06 07:34:07
(4 hours ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
factor1
2026-09-06 06:22:13
(5 hours ago)
CrowdSec at saturn Reports Abuse
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 04:40:19
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.82.224.196 (196.224.82.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.224.196 (196.224.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 00:40:13.975690 2026] [security2:error] [pid 9259:tid 9259] [client 34.82.224.196:43638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mylert.sguard.co"] [uri "/app/.git/config"] [unique_id "apzurRJ4dlXHiiwE7yG1GQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇱🇻
garmtech.com
2026-09-06 02:00:28
(10 hours ago)
Attempted access to sensitive endpoint (/wordpress/.git/config) detected. Automated scan or unauthor ...
show more
Attempted access to sensitive endpoint (/wordpress/.git/config) detected. Automated scan or unauthorized probing.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:56:36
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.82.224.196 (196.224.82.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.224.196 (196.224.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:56:27.966693 2026] [security2:error] [pid 18209:tid 18209] [client 34.82.224.196:43294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theknowledgemaster.com"] [uri "/backend/.git/config"] [unique_id "apzIS6YyPqsS_2MKtqE0tgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-06 00:28:57
(11 hours ago)
cloudlinux2 fail2ban: 2026-09-06 02:24:15,436 fail2ban.filter [1594]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-06 02:24:15,436 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.82.224.196 - 2026-09-06 02:24:15cloudlinux2 fail2ban: 2026-09-06 02:24:15,404 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.82.224.196 - 2026-09-06 02:24:15cloudlinux2 fail2ban: 2026-09-06 02:24:15,486 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.82.224.196 - 2026-09-06 02:24:15cloudlinux2 fail2ban: 2026-09-06 02:24:15,420 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.82.224.196 - 2026-09-06 02:24:15cloudlinux2 fail2ban: 2026-09-06 02:24:15,495 fail2ban.filter [1594]: INFO [recidive] Found 34.82.224.196 - 2026-09-06 02:24:15cloudlinux2 fail2ban: 2026-09-06 02:24:18,287 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 35.196.227.153 - 2026-09-06 02:24:18cloudlinux2 fail2ban: 2026-09-06 02:24:18,232 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 35.196.227.153 - 2026-09-06 02:24:17cl
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 00:27:51
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.82.224.196 (196.224.82.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.224.196 (196.224.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:27:44.895711 2026] [security2:error] [pid 8682:tid 8682] [client 34.82.224.196:54618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wickedworks.net"] [uri "/var/www/.git/config"] [unique_id "apyzgLQiwwSlJ82aYzAiUQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
john doe
2026-09-05 22:07:05
(13 hours ago)
SentinelBot: Secret-path hunting (9 distinct paths): Env File Hunting (score: 63)
Bad Web Bot
🇩🇪
raph
2026-09-05 22:05:44
(14 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
🇩🇪
Philister11
2026-09-05 02:07:01
(1 day ago)
CrowdSec: crowdsecurity/http-sensitive-files (US/AS396982)
Web App Attack
Hacking
🇦🇺
A.i.D.A.N.N
2026-09-05 02:04:39
(1 day ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web application attack detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 23:28:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.82.224.196 (196.224.82.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.224.196 (196.224.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 19:28:22.182630 2026] [security2:error] [pid 31780:tid 31780] [client 34.82.224.196:55100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "804web.net"] [uri "/app/.git/config"] [unique_id "aptUFsJlVYYngmVwecVMeAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 22:35:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.82.224.196 (196.224.82.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.82.224.196 (196.224.82.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 18:34:56.416241 2026] [security2:error] [pid 29497:tid 29517] [client 34.82.224.196:53572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "royalbusinesscollege.com"] [uri "/api/.git/config"] [unique_id "aptHkOUDlZXDjmKVmdp3ggAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 22:00:49
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-03.
show less
Web App Attack
SSH
Hacking