๐ซ๐ท
cydit.eu
2026-09-16 08:38:22
(43 minutes ago)
phpMyAdmin attack detected by fail2ban on thor.cydit.eu
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 08:33:42
(48 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.88.41.27 (27.41.88.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.41.27 (27.41.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 04:33:36.105123 2026] [security2:error] [pid 23029:tid 23029] [client 34.88.41.27:39930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tracytappan.net"] [uri "/.git/config"] [unique_id "aqpUYFbxn29nUXHVlwEt4QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 08:15:49
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.88.41.27 (27.41.88.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.41.27 (27.41.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 04:15:42.680858 2026] [security2:error] [pid 27162:tid 27162] [client 34.88.41.27:54890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tracybur.net"] [uri "/.git/config"] [unique_id "aqpQLsDzWBbsuC49-1p9IgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 07:21:14
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.41.27 (27.41.88.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.41.27 (27.41.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 03:21:06.864595 2026] [security2:error] [pid 21110:tid 21110] [client 34.88.41.27:59314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tractiondrive.com"] [uri "/.git/config"] [unique_id "aqpDYr4f3q5q1uMKbRfh6AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-09-16 06:42:01
(2 hours ago)
2026-09-16 08:40:39 GET /.git/config [301] && 2026-09-16 08:40:39 GET /.env [301] && 2026-09-16 08:4 ...
show more
2026-09-16 08:40:39 GET /.git/config [301] && 2026-09-16 08:40:39 GET /.env [301] && 2026-09-16 08:40:39 GET /.env.bak [301] && 239 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 05:54:39
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.41.27 (27.41.88.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.41.27 (27.41.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 01:54:32.877043 2026] [security2:error] [pid 2121199:tid 2121199] [client 34.88.41.27:46810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tracklocross.com"] [uri "/.git/config"] [unique_id "aqovGL-vEaWv3UOG-zm-swAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pltcldvlpr
2026-09-16 03:53:51
(5 hours ago)
CMS/framework probe: 34.88.41.27 - - [16/Sep/2026:05:53:51 +0200] "GET /.git/config HTTP/1.1" 444 0 ...
show more
CMS/framework probe: 34.88.41.27 - - [16/Sep/2026:05:53:51 +0200] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" asn=396982 org="Google LLC" country=FI
...
show less
Web App Attack
๐จ๐ญ
dalslab ltd
2026-09-16 01:42:06
(7 hours ago)
[16/Sep/2026:03:41:56 +0200] - 404 404 - POST https tracking.dalslab.com "/" [Client 34.88.41.27] [L ...
show more
[16/Sep/2026:03:41:56 +0200] - 404 404 - POST https tracking.dalslab.com "/" [Client 34.88.41.27] [Length 24] [Gzip -] [Sent-to ] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[16/Sep/2026:03:41:56 +0200] - 404 404 - POST https tracking.dalslab.com "/" [Client 34.88.41.27] [Length 24] [Gzip -] [Sent-to ] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[16/Sep/2026:03:41:57 +0200] - 404 404 - POST https tracking.dalslab.com "/" [Client 34.88.41.27] [Length 24] [Gzip -] [Sent-to ] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-"
[16/Sep/2026:03:41:57 +0200] - 404 404 - GET https tracking.dalslab.com "/.git/config" [Client 34.88.41.27] [Length 27343] [Gzip -] [Sent-to ] "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SwinT
2026-09-16 01:00:05
(8 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ณ๐ฑ
Aitech DevOps
2026-09-16 00:48:41
(8 hours ago)
Fail2Ban nginx-botsearch banned 34.88.41.27 after 2 attempts
Brute-Force
SSH
๐ซ๐ท
โจ
2026-09-16 00:44:09
(8 hours ago)
Domain : trackhunter.co.uk
Rule : hack
2026-09-16 00:42:12 ***hidden-privacy*** GET /.env.bak - 443 ...
show more
Domain : trackhunter.co.uk
Rule : hack
2026-09-16 00:42:12 ***hidden-privacy*** GET /.env.bak - 443 - 34.88.41.27 HTTP/1.1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 - trackhunter.co.uk 404 0 0 333 499 55 - -
show less
Hacking
SQL Injection
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-16 00:01:45
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.88.41.27 (27.41.88.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.41.27 (27.41.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:01:36.829631 2026] [security2:error] [pid 13389:tid 13389] [client 34.88.41.27:55682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tracker.mindtekt.com"] [uri "/.git/config"] [unique_id "aqncYNFl15O4JVD3gk9cNgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
AetherFox
2026-09-15 23:45:20
(9 hours ago)
AetherFox VoidGuard detected: [Wed Sep 16 01:45:20.084103 2026] [authz_core:error] [pid 444686:tid 4 ...
show more
AetherFox VoidGuard detected: [Wed Sep 16 01:45:20.084103 2026] [authz_core:error] [pid 444686:tid 444720] [client 34.88.41.27:57696] AH01630: client denied by server configuration: proxy:https://[MASKED]/
[Wed Sep 16 01:45:20.084344 2026] [authz_core:error] [pid 444686:tid 444720] [client 34.88.41.27:57696] AH01630: client denied by server configuration: /var/www/ERRORpages/403.html
[Wed Sep 16 01:45:20.148688 2026] [authz_core:error] [pid 444686:tid 444722] [client 34.88.41.27:57696] AH01630: client denied by server configuration: proxy:https://[MASKED]/
[Wed Sep 16 01:45:20.148947 2026] [authz_core:error] [pid 444686:tid 444722] [client 34.88.41.27:57696] AH01630: client denied by server configuration: /var/www/ERRORpages/403.html
[Wed Sep 16 01:45:20.224739 2026] [authz_core:error] [pid 444686:tid 444723] [client 34.88.41.27:57696] AH01630: client denied by server configuration: proxy:https://[MASKED]/
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
Quarks Solutions
2026-09-15 15:59:17
(17 hours ago)
crowdsecurity/appsec-vpatch
Web App Attack