๐ณ๐ฑ
Savvii
2026-09-02 14:41:57
(4 hours ago)
20 attempts against mh-misbehave-ban on acorn
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-02 14:09:44
(5 hours ago)
Excessive multi-domain requests
Brute-Force
๐ธ๐ช
vaia.cloud
2026-09-02 05:45:03
(13 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-02 03:39:16
(15 hours ago)
[02/Sep/2026:06:39:15 +0300] -- 34.89.191.47 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/ ...
show more
[02/Sep/2026:06:39:15 +0300] -- 34.89.191.47 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 02:42:06
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.191.47 (47.191.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.191.47 (47.191.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 22:41:57.894839 2026] [security2:error] [pid 18465:tid 18465] [client 34.89.191.47:41334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "utilis.net"] [uri "/.git/config"] [unique_id "apeM9eNklPOZjjbFB67FuwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-09-02 02:31:17
(16 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 01:23:53
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.191.47 (47.191.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.191.47 (47.191.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 21:23:47.232585 2026] [security2:error] [pid 6106:tid 6106] [client 34.89.191.47:48354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "utd.net"] [uri "/.git/config"] [unique_id "apd6o8Osinn4gfATgUrP0gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-02 01:10:04
(18 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-02 00:45:28
(18 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 00:15:55
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.191.47 (47.191.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.191.47 (47.191.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 20:15:50.775179 2026] [security2:error] [pid 20911:tid 20932] [client 34.89.191.47:36854] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "utahhoaservices.com"] [uri "/.git/config"] [unique_id "apdqtuVoniRRIgbE9kAIBgAAAVM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 00:00:31
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.191.47 (47.191.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.191.47 (47.191.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 20:00:22.344225 2026] [security2:error] [pid 26432:tid 26432] [client 34.89.191.47:51220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "utah17.com"] [uri "/.git/config"] [unique_id "apdnFvPYdYJngGhwLSggHwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ut-addicted.com
2026-09-01 23:27:04
(19 hours ago)
\[Wed Sep 02 01:27:02.857881 2026\] \[:error\] \[pid 17720:tid 140352409220864\] \[client 34.89.191. ...
show more
\[Wed Sep 02 01:27:02.857881 2026\] \[:error\] \[pid 17720:tid 140352409220864\] \[client 34.89.191.47:46196\] \[client 34.89.191.47\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 10\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "ut-addicted.com"\] \[uri "/"\] \[unique_id "apdfRq8Iu67eWZcfXTIviQAAANU"\]
show less
Brute-Force
Web App Attack
๐ซ๐ท
Stara
2026-09-01 22:52:51
(20 hours ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 22:13:40
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.191.47 (47.191.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.191.47 (47.191.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 18:13:35.407860 2026] [security2:error] [pid 27081:tid 27089] [client 34.89.191.47:53370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "usu.net"] [uri "/.git/config"] [unique_id "apdOD9hXESsNEkeLDZRgzwAAAEE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 21:55:01
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.89.191.47 (47.191.89.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.89.191.47 (47.191.89.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 17:54:57.361551 2026] [security2:error] [pid 3162:tid 3162] [client 34.89.191.47:56862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ustock.app.suffolksystems.com"] [uri "/.git/config"] [unique_id "apdJsSyFKu8zaOhZpWV7dQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack