🇫🇷
masterguru
2026-09-09 07:51:19
(1 hour ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇺🇸
mibbsdevs
2026-09-09 05:47:43
(3 hours ago)
CoffeePot Web: Automated bad bot directory fuzzing and high-rate 404 probing.
Port Scan
Bad Web Bot
🇬🇧
consul.to
2026-09-09 04:33:14
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:17:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.174.213 (213.174.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.174.213 (213.174.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:17:01.287857 2026] [security2:error] [pid 25444:tid 25444] [client 34.88.174.213:59994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "treadbox.net"] [uri "/.git/config"] [unique_id "ap-MPcXOGgznnPZ-aZS7mQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-08 04:12:36
(1 day ago)
Excessive multi-domain requests
Brute-Force
🇬🇧
andypiper
2026-09-08 01:02:31
(1 day ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇳🇿
Antinson
2026-09-08 00:57:28
(1 day ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇧🇪
cmbplf
2026-09-08 00:11:31
(1 day ago)
12.917 4xx requests in 1 hour (1w3d12h)
Brute-Force
Bad Web Bot
🇳🇱
homeshowdomain.nl
2026-09-07 22:02:39
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-06.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-07 21:09:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.174.213 (213.174.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.174.213 (213.174.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 17:08:55.170339 2026] [security2:error] [pid 22528:tid 22528] [client 34.88.174.213:39036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "travelwithjenniferb.com"] [uri "/.git/config"] [unique_id "ap8n5y9O7jLBfHN_yD3-GwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:24:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.174.213 (213.174.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.174.213 (213.174.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:24:26.158920 2026] [security2:error] [pid 872275:tid 872299] [client 34.88.174.213:49590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "travelusa.us"] [uri "/.git/config"] [unique_id "ap8derZBiXUuFNMTNeFPmQAAANI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:45:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.174.213 (213.174.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.174.213 (213.174.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:45:27.446155 2026] [security2:error] [pid 31890:tid 31890] [client 34.88.174.213:37786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "travelto.info"] [uri "/.git/config"] [unique_id "ap8UVwQFmzvB5BOKPjVr1QAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:13:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.174.213 (213.174.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.174.213 (213.174.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:13:10.043277 2026] [security2:error] [pid 20896:tid 20896] [client 34.88.174.213:34474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "travelsupersonic.com"] [uri "/.git/config"] [unique_id "ap8Mxtpnn404jt2qpIzXyAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
pipeline.es
2026-09-07 17:15:39
(1 day ago)
Web scanning / probing for vulnerable paths | URL: /notifications/.env | Evidence: travelplanet.pt 3 ...
show more
Web scanning / probing for vulnerable paths | URL: /notifications/.env | Evidence: travelplanet.pt 34.88.174.213 - - [07/Sep/2026:19:14:50 +0200] \"GET /notifications/.env HTTP/1.1\" 404 20268 \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=FI | ASN: GOOGLE-CLOUD-PLATFORM | Country: FI
show less
Port Scan
Web App Attack
🇩🇪
NewWavesApp
2026-09-07 15:22:41
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.88.174.213 (FI/Finland/213.174.88.34 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.88.174.213 (FI/Finland/213.174.88.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection