🇺🇸
NeverBehave
2026-09-12 04:59:55
(5 hours ago)
[fail2ban] service ocserv jail
Brute-Force
Web App Attack
🇧🇷
dermatovirtual
2026-09-12 04:57:04
(5 hours ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 206 unauthorized requests recorded between 2026-09-11 04:52:07 UTC and 2026-09-11 04:53:15 UTC (rate: ~181,8 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-11 04:53:14 UTC] IP: 34.88.16.197 - W3C IIS (Port 443): GET /development/.env -> HTTP 404 [CLIENT: 34.88.16.197]
[2026-09-11 04:53:14 UTC] IP: 34.88.16.197 - W3C IIS (Port 443): GET /production/.env -> HTTP 404 [CLIENT: 34.88.16.197]
[2026-09-11 04:53:14 UTC] IP: 34.88.16.197 - W3C IIS (Port 443): GET /uat/.env -> HTTP 404 [CLIENT: 34.88.16.197]
show less
Bad Web Bot
Web App Attack
🇨🇦
Vianpyro
2026-09-12 03:58:18
(6 hours ago)
Honeypot: 12 request(s) in 0 min. Paths: /, /.env, /.env.local, /.env.production, /.git/config. Meth ...
show more
Honeypot: 12 request(s) in 0 min. Paths: /, /.env, /.env.local, /.env.production, /.git/config. Method(s): GET, POST. UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/13. ASN: 396982 (Google LLC).
show less
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 02:19:38
(7 hours ago)
Web Attack Gitscanner Traffic Detected
Web App Attack
🇦🇺
rubixstudios
2026-09-11 18:52:03
(15 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 14:14:14
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.16.197 (197.16.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.16.197 (197.16.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 10:14:07.377302 2026] [security2:error] [pid 27503:tid 27503] [client 34.88.16.197:37460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.advantstudio.com"] [uri "/.git/config"] [unique_id "aqQMrzxWOXwMYDa_jUkE-QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 13:01:21
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.16.197 (197.16.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.16.197 (197.16.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 09:01:13.953421 2026] [security2:error] [pid 3715:tid 3715] [client 34.88.16.197:53452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.adamsclothiers.com"] [uri "/.git/config"] [unique_id "aqP7mWXs-YhSQ_NR7OzhbgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 12:16:13
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.16.197 (197.16.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.16.197 (197.16.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 08:16:09.019080 2026] [security2:error] [pid 26839:tid 26839] [client 34.88.16.197:49016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.acmax.com"] [uri "/.git/config"] [unique_id "aqPxCQll-JOYcNlnQn-9NgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 11:17:01
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.16.197 (197.16.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.16.197 (197.16.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 07:16:54.999813 2026] [security2:error] [pid 5440:tid 5498] [client 34.88.16.197:60514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.absurdotron.com"] [uri "/.git/config"] [unique_id "aqPjJkC-Fw2ZfhrYVtPwlwAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 10:38:02
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.16.197 (197.16.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.16.197 (197.16.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 06:37:57.520958 2026] [security2:error] [pid 5910:tid 5910] [client 34.88.16.197:57670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.abdulhameeds.art"] [uri "/.git/config"] [unique_id "aqPaBVGQe-mbkAAiy1ieqwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 07:46:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.16.197 (197.16.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.16.197 (197.16.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 03:46:35.541951 2026] [security2:error] [pid 5660:tid 5660] [client 34.88.16.197:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.365soft.top"] [uri "/.git/config"] [unique_id "aqOx2yQi9kWNxJRpMpAlHwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 06:20:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.16.197 (197.16.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.16.197 (197.16.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 02:20:56.267187 2026] [security2:error] [pid 21648:tid 21648] [client 34.88.16.197:44018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.179vfs.com"] [uri "/.git/config"] [unique_id "aqOdyAcm1fdnA3hOMRrH2gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇷
dermatovirtual
2026-09-11 04:55:38
(1 day ago)
Dermato Virtual CSIRT: Malicious web application probes detected against app.dermatovirtual.com.br ( ...
show more
Dermato Virtual CSIRT: Malicious web application probes detected against app.dermatovirtual.com.br (Web Server Ports 80/443) from 34.88.16.197. Edge perimeter drop active pursuant to RFC 2142 / RFC 3013 compliance.
show less
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-11 03:59:06
(1 day ago)
42.173 requests in 1 hour (3mos1w6d)
Brute-Force
Bad Web Bot
🇩🇪
dbmwebdesign
2026-09-11 03:45:25
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack