Anonymous
2026-09-18 23:43:02
(16 hours ago)
Bot / scanning and/or hacking attempts: GET /admin/.env HTTP/1.1, GET /backend/.env HTTP/1.1, GET /f ...
show more
Bot / scanning and/or hacking attempts: GET /admin/.env HTTP/1.1, GET /backend/.env HTTP/1.1, GET /frontend/.env HTTP/1.1, GET /server/.env HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 19:52:23
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.40.103 (103.40.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.40.103 (103.40.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 15:52:19.764613 2026] [security2:error] [pid 9322:tid 9322] [client 34.88.40.103:36892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theoriginclinickc.com"] [uri "/.git/config"] [unique_id "aq2Wc03j4X2BwxMgJYP9NgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
rubixstudios
2026-09-18 17:07:03
(23 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
๐ฉ๐ช
dave
2026-09-18 15:51:55
(1 day ago)
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity ...
show more
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity/appsec-vpatch,crowdsecurity/vpatch-CVE-2025-55182,crowdsecurity/vpatch-env-access,crowdsecurity/vpatch-git-config,custom/traefik-sensitive-path-probe observed_by=3_hosts hit_count=203 first_seen=2026-09-18T15:35:00Z last_seen=2026-09-18T15:51:55Z
show less
Web App Attack
๐บ๐ธ
blizzard
2026-09-18 15:34:35
(1 day ago)
Unauthorized HTTP/1.1 POST / blocked by Managed rules: (ASN: 396982) (Network: Google LLC) (Method: ...
show more
Unauthorized HTTP/1.1 POST / blocked by Managed rules: (ASN: 396982) (Network: Google LLC) (Method: POST) (Path: /) (Query: ) (User Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36)
show less
Web App Attack
๐ซ๐ท
dynamix
2026-09-18 14:29:42
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
masterguru
2026-09-18 14:11:24
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
Anonymous
2026-09-18 14:10:01
(1 day ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-18 13:19:26
(1 day ago)
(php_susp_dir) srv102 PHP Suspicious Directory 34.88.40.103 (103.40.88.34.bc.googleusercontent.com): ...
show more
(php_susp_dir) srv102 PHP Suspicious Directory 34.88.40.103 (103.40.88.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 10:40:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.40.103 (103.40.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.40.103 (103.40.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 06:40:17.548573 2026] [security2:error] [pid 25680:tid 25680] [client 34.88.40.103:48708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thenowhere-men.com"] [uri "/.git/config"] [unique_id "aq0VEXy7EWfo3UVq4RJZQgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 09:13:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.40.103 (103.40.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.40.103 (103.40.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 05:13:51.704627 2026] [security2:error] [pid 30894:tid 30894] [client 34.88.40.103:36822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thenolangroup.llc"] [uri "/.git/config"] [unique_id "aq0AzynSuqs8ryLPlP6JkAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-18 07:22:47
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
wbsouza
2026-09-18 03:39:55
(1 day ago)
CrowdSec: crowdsecurity/http-sensitive-files โ automated firewall drops on self-hosted IDS sensor
Hacking
๐ณ๐ฑ
Site.eu
2026-09-18 03:30:59
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-18 03:10:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.40.103 (103.40.88.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.40.103 (103.40.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 23:10:16.713497 2026] [security2:error] [pid 29428:tid 29428] [client 34.88.40.103:38782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trademartghana.com"] [uri "/.git/config"] [unique_id "aqyrmPfXPbKRq4NEc3YzRgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack