๐จ๐ญ
zynex
2026-09-02 19:03:15
(8 hours ago)
URL Probing: /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 12:52:45
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.161.23 (23.161.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.161.23 (23.161.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 08:52:38.836426 2026] [security2:error] [pid 4203:tid 4203] [client 34.88.161.23:33678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trevthomas.com"] [uri "/.git/config"] [unique_id "apgcFk1iLRIBYZCZZEK0jgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
webanyone
2026-09-02 11:32:04
(16 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ซ๐ท
Octopuce
2026-09-02 10:29:19
(17 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-02 10:20:05
(17 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 09:52:15
(18 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.88.161.23 (23.161.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.88.161.23 (23.161.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 05:52:08.894901 2026] [security2:error] [pid 12989:tid 12989] [client 34.88.161.23:33202] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "trentong.com"] [uri "/.git/config"] [unique_id "apfxyFGVlazTjcAvwxQKYQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 09:36:13
(18 hours ago)
34.88.161.23 - - [02/Sep/2026:09:36:11 +0000] "GET /mailer/.env HTTP/1.1" 404 209 "-" "Mozilla/5.0 ( ...
show more
34.88.161.23 - - [02/Sep/2026:09:36:11 +0000] "GET /mailer/.env HTTP/1.1" 404 209 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.88.161.23 - - [02/Sep/2026:09:36:12 +0000] "GET /mail/.env HTTP/1.1" 404 209 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.88.161.23 - - [02/Sep/2026:09:36:12 +0000] "GET /mailing/.env HTTP/1.1" 404 209 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ซ๐ท
Baking333
2026-09-02 08:05:19
(19 hours ago)
[redacted] 34.88.161.23 - - [02/Sep/2026:09:05:17 +0100] "GET /.git/config HTTP/1.1" 302 1538 0/3996 ...
show more
[redacted] 34.88.161.23 - - [02/Sep/2026:09:05:17 +0100] "GET /.git/config HTTP/1.1" 302 1538 0/39960 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" [redacted] 34.88.161.23 - - [02/Sep/2026:09:05:17 +0100] "GET /.env HTTP/1.1" 302 1537 0/36726 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 06:03:43
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.161.23 (23.161.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.161.23 (23.161.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 02:03:39.619201 2026] [security2:error] [pid 15119:tid 15119] [client 34.88.161.23:35372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trendingnowsales.com.wholesalelivelobsters.com"] [uri "/.git/config"] [unique_id "ape8Oxm-AHzQMk4dnB3clwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
nzhost.co.nz
2026-09-02 05:50:51
(22 hours ago)
$f2bV_matches
Hacking
Brute-Force
Anonymous
2026-09-02 04:07:05
(23 hours ago)
Automated web scanner. Requested suspicious paths: /.git/config. UTC: 2026-09-02 03:59:42.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 04:04:37
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.161.23 (23.161.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.161.23 (23.161.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 00:04:29.980518 2026] [security2:error] [pid 16549:tid 16549] [client 34.88.161.23:53170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tremulant.com"] [uri "/.git/config"] [unique_id "apegTclhZ2Y5DTWwyHn84wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-02 04:02:21
(23 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+1 more) | 2026-09-02 04:02 UTC
show less
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-02 03:40:34
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
dynamix
2026-09-02 03:11:19
(1 day ago)
Multiple WAF Violations
Web App Attack