๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-26 23:29:06
(20 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-24 20:10:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.9.54.69 (69.54.9.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.54.69 (69.54.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 16:10:04.861120 2026] [security2:error] [pid 31174:tid 31174] [client 34.9.54.69:54646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.schoolrx.org"] [uri "/.git/config"] [unique_id "arWDnAPxOZzoKEP1K7qt5gAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 19:28:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.9.54.69 (69.54.9.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.54.69 (69.54.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 15:28:06.406019 2026] [security2:error] [pid 14456:tid 14456] [client 34.9.54.69:53840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.scarletveil.org"] [uri "/.git/config"] [unique_id "arV5xvGFuWC9Fkez8DqzfwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 19:08:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.9.54.69 (69.54.9.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.54.69 (69.54.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 15:08:14.731006 2026] [security2:error] [pid 11628:tid 11628] [client 34.9.54.69:54120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sbiusa.org"] [uri "/.git/config"] [unique_id "arV1HtIuWRSHMfNSY8SKRgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-24 14:33:25
(2 days ago)
[ti-26al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-26al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.9.54.69 - - [24/Sep/2026:16:33:14 +0200] "GET /.git/config HTTP/1.1" 301 640 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 06:31:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.9.54.69 (69.54.9.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.54.69 (69.54.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 02:31:41.335968 2026] [security2:error] [pid 9026:tid 9081] [client 34.9.54.69:40482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.stephanietobola.com"] [uri "/.git/config"] [unique_id "arTDzbuaD_19v1-eLj6QxQAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 10:17:27
(4 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-09-22 02:55:03
(4 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-21 19:32:18
(5 days ago)
[ti-02ra] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02ra] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.9.54.69 - - [21/Sep/2026:21:32:16 +0200] "GET /.git/config HTTP/1.1" 404 53635 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-09-21 19:20:08
(5 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: staging.definitelynotahoneypot.online | URI: /.git/config | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack