๐ฉ๐ช
filstal.org
2026-09-20 22:19:32
(14 minutes ago)
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels an ...
show more
Web reconnaissance detected: automated probing for sensitive files, backup archives, admin panels and known vulnerability paths.
show less
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:08:59
(25 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.91.86.27 (27.86.91.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.86.27 (27.86.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:08:53.803149 2026] [security2:error] [pid 29046:tid 29046] [client 34.91.86.27:33786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kingscruff.com"] [uri "/.git/config"] [unique_id "arBZdWTaQ6DTDUxyaTZKcAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 21:33:24
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.91.86.27 (27.86.91.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.86.27 (27.86.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:33:17.293777 2026] [security2:error] [pid 18298:tid 18298] [client 34.91.86.27:53324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kimbrothersduluth.com"] [uri "/.git/config"] [unique_id "arBRHYbnfdMxTWI0uu_p3gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-20 21:19:49
(1 hour ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-20 21:14:39
(1 hour ago)
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34. ...
show more
[ti-12al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 34.91.86.27 - - [20/Sep/2026:23:14:37 +0200] "GET /.git/config HTTP/1.1" 404 7942 "-" "-"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
KiekerJan
2026-09-20 21:14:19
(1 hour ago)
34.91.86.27 - - [20/Sep/2026:23:14:17 +0200] "GET /.git/config HTTP/1.1" 301 162 "-" "-"
34.91.86.27 ...
show more
34.91.86.27 - - [20/Sep/2026:23:14:17 +0200] "GET /.git/config HTTP/1.1" 301 162 "-" "-"
34.91.86.27 - - [20/Sep/2026:23:14:18 +0200] "GET /.git/config HTTP/1.1" 301 162 "-" "-"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 21:12:04
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.91.86.27 (27.86.91.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.86.27 (27.86.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:12:01.577294 2026] [security2:error] [pid 7075:tid 7075] [client 34.91.86.27:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kidswithcamerasmovie.com"] [uri "/.git/config"] [unique_id "arBMIQ8kBEYa-mgEkBTpngAAAD0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-20 21:10:05
(1 hour ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 3 hits.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 20:48:37
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.91.86.27 (27.86.91.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.86.27 (27.86.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 16:48:33.399127 2026] [security2:error] [pid 26246:tid 26246] [client 34.91.86.27:48980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.khovanov.com"] [uri "/.git/config"] [unique_id "arBGoS0rxIGL-oMCfXRJ5QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-09-20 20:30:31
(2 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 20:25:26
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.86.27 (27.86.91.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.86.27 (27.86.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 16:25:21.838120 2026] [security2:error] [pid 10044:tid 10044] [client 34.91.86.27:55016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kfraser.com"] [uri "/.git/config"] [unique_id "arBBMSYQfQvqgnuTtKevNAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 20:05:19
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.91.86.27 (27.86.91.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.91.86.27 (27.86.91.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 16:05:13.588338 2026] [security2:error] [pid 9212:tid 9212] [client 34.91.86.27:51134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kevinfranz.com"] [uri "/.git/config"] [unique_id "arA8eeakMJPO4nY5crJU_gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 20:05:03
(2 hours ago)
suspicious request in access.log
Web App Attack
๐ต๐ฑ
ketovoila.pl
2026-09-20 20:00:43
(2 hours ago)
ketovoila.pl web app secret/repository scan: hits=2; unique_paths=1; sample_paths=/.git/config; UA=" ...
show more
ketovoila.pl web app secret/repository scan: hits=2; unique_paths=1; sample_paths=/.git/config; UA=""; window=2026-09-20T20:00:43Z..2026-09-20T20:00:44Z HTTP methods: GET (2).
show less
Bad Web Bot
Web App Attack
๐จ๐ฆ
Anytech
2026-09-20 19:57:52
(2 hours ago)
Blocked by ConnMonitor
Web App Attack