πΊπΈ
TPI-Abuse
2026-08-29 00:23:40
(27 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.86.19.40 (40.19.86.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.19.40 (40.19.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 20:23:35.036645 2026] [security2:error] [pid 31657:tid 31657] [client 34.86.19.40:50396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.modernsalesforce.wholesalelivelobsters.com"] [uri "/backend/.git/config"] [unique_id "apImhygzHzLf5wWkur-tQgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
MBombeck
2026-08-29 00:06:40
(44 minutes ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
π©πͺ
TheDjRider
2026-08-28 22:43:24
(2 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-08-28T22:43:23.370908848Z. Context: http_status=404
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 19:36:34
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.86.19.40 (40.19.86.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.19.40 (40.19.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:36:29.760956 2026] [security2:error] [pid 12863:tid 12863] [client 34.86.19.40:49190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asermaq.cl.tecnoconce.com"] [uri "/.git/config"] [unique_id "apHjPSuOP6vsNTqqNyhYQwAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 19:10:38
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.86.19.40 (40.19.86.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.19.40 (40.19.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:10:33.921420 2026] [security2:error] [pid 16278:tid 16278] [client 34.86.19.40:33964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ai.evai.is"] [uri "/app/.git/config"] [unique_id "apHdKTyIviDPBNuZ3qpSlgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
e.fierstra
2026-08-28 18:50:26
(6 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-28 16:30:47
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.86.19.40 (40.19.86.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.86.19.40 (40.19.86.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 12:30:43.343111 2026] [security2:error] [pid 397:tid 397] [client 34.86.19.40:55180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "izloto.com"] [uri "/app/.git/config"] [unique_id "apG3s3q5fks3VGj-JOVHrwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-28 16:00:04
(8 hours ago)
suspicious request in access.log
Web App Attack
π«π·
dynamix
2026-08-28 15:39:39
(9 hours ago)
Multiple WAF Violations
Web App Attack
π©πͺ
big-cloud.nl
2026-08-28 11:49:04
(13 hours ago)
Try to access /site/.git/config
Web App Attack
πΊπΈ
mnsf
2026-08-28 00:05:58
(1 day ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
π©πͺ
ghostwarriors
2026-08-27 19:50:04
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
π©πͺ
yitzhaq
2026-08-27 19:20:32
(1 day ago)
34.86.19.40 - - [27/Aug/2026:21:20:28 +0200] "GET /.git/config HTTP/1.1" 403 4429 "-" "crusader-work ...
show more
34.86.19.40 - - [27/Aug/2026:21:20:28 +0200] "GET /.git/config HTTP/1.1" 403 4429 "-" "crusader-worker/1.0"
34.86.19.40 - - [27/Aug/2026:21:20:28 +0200] "GET /app/.git/config HTTP/1.1" 404 4427 "-" "crusader-worker/1.0"
34.86.19.40 - - [27/Aug/2026:21:20:28 +0200] "GET /src/.git/config HTTP/1.1" 404 4426 "-" "crusader-worker/1.0"
34.86.19.40 - - [27/Aug/2026:21:20:28 +0200] "GET /backend/.git/config HTTP/1.1" 404 4426 "-" "crusader-worker/1.0"
34.86.19.40 - - [27/Aug/2026:21:20:28 +0200] "GET /www/.git/config HTTP/1.1" 404 4425 "-" "crusader-worker/1.0"
34.86.19.40 - - [27/Aug/2026:21:20:28 +0200] "GET /api/.git/config HTTP/1.1" 404 4426 "-" "crusader-worker/1.0"
34.86.19.40 - - [27/Aug/2026:21:20:28 +0200] "GET /html/.git/config HTTP/1.1" 404 4426 "-" "crusader-worker/1.0"
34.86.19.40 - - [27/Aug/2026:21:20:28 +0200] "GET /site/.git/config HTTP/1.1" 404 4427 "-" "crusader-worker/1.0"
34.86.19.40 - - [27/Aug/2026:21:20:28 +0200] "GET /public/.git/config HTTP/1.1" 404 4426 "-" "crusader
show less
Web App Attack
Hacking
πΊπ¦
URAN Publishing Service
2026-08-27 19:13:36
(1 day ago)
[27/Aug/2026:22:13:35 +0300] -- 34.86.19.40 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/c ...
show more
[27/Aug/2026:22:13:35 +0300] -- 34.86.19.40 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 16:42:46
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.86.19.40 (US/United States/40.19.86. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.86.19.40 (US/United States/40.19.86.34.bc.googleusercontent.com)
show less
SQL Injection