Anonymous
2026-09-02 16:07:47
(3 hours ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 12:58:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.92.103.222 (222.103.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.103.222 (222.103.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:57:55.983279 2026] [security2:error] [pid 10758:tid 10758] [client 34.92.103.222:54250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "w1rq.com"] [uri "/.git/config"] [unique_id "apbL0_LtlVDDpXjBVE2mOwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-09-01 10:50:03
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 07:58:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.92.103.222 (222.103.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.103.222 (222.103.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 03:57:55.975212 2026] [security2:error] [pid 16503:tid 16503] [client 34.92.103.222:33944] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "w-c-p-m.com"] [uri "/.git/config"] [unique_id "apaFg4AQigQn8ndx8uE45wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
madeit
2026-09-01 07:42:04
(1 day ago)
Web App Attack
๐ซ๐ท
bazter.pro
2026-09-01 04:07:06
(1 day ago)
Auto-Ban [2026-09-01 07:07:06]: CRITICAL: .env attack; DC: Google LLC [Paths: 272] | Details: Exploi ...
show more
Auto-Ban [2026-09-01 07:07:06]: CRITICAL: .env attack; DC: Google LLC [Paths: 272] | Details: Exploit trap paths: /.git/config, /.env, /.env.local, /.env.production, /.env.staging | Sensitive files/paths: /.git/config, /.env, /.env.local, /.env.production, /.env.staging | 404 errors (40): /tmp/phpinfo.php, /site/phpinfo.php, /server-info.php, /public/phpinfo.php, /docs/phpinfo.php, /old/phpinfo.php, /test.php, /pinfo.php, /dev/phpinfo.php, /includes/phpinfo.php (and 30 more) | Other paths: /smtp/.env, /v1/.env, /cd/.env, /wp/.env, /firebase-adminsdk.json, /ci/.env, /beta/.env, /dev/.env, /.env1, /var/www/.env
show less
Web App Attack
Hacking
Anonymous
2026-09-01 03:40:08
(1 day ago)
| [Dangerous/Hong Kong] Aggressive IP 34.92.103.222 (~30 hits). Type: DoS Defender- Web server 400 e ...
show more
| [Dangerous/Hong Kong] Aggressive IP 34.92.103.222 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐ซ๐ท
masterguru
2026-09-01 01:31:29
(1 day ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
๐ณ๐ฑ
Site.eu
2026-09-01 01:10:06
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-31 16:17:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.103.222 (222.103.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.103.222 (222.103.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 12:17:25.243146 2026] [security2:error] [pid 18160:tid 18160] [client 34.92.103.222:44130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.feaverslane.com"] [uri "/.git/config"] [unique_id "apWpFV0uhHxMkdZ9UKEwrAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 15:44:50
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.103.222 (222.103.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.103.222 (222.103.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 11:44:45.106626 2026] [security2:error] [pid 117325:tid 117344] [client 34.92.103.222:58842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.fandgins.com"] [uri "/.git/config"] [unique_id "apWhbXVF_3S4Agqpj6G5RAAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-08-31 12:08:03
(2 days ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 2s
Web App Attack
๐ฎ๐น
VHosting
2026-08-31 10:45:04
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 08:20:55
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.103.222 (222.103.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.103.222 (222.103.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 04:20:50.174887 2026] [security2:error] [pid 6527:tid 6527] [client 34.92.103.222:52482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.drbolen.com"] [uri "/.git/config"] [unique_id "apU5YvMp0QDtS1bNhwSqtgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-08-30 18:42:32
(3 days ago)
URL Probing: /server/.env
Web App Attack