๐ท๐ด
iulianh
2026-08-30 00:16:27
(3 weeks ago)
80,443
Brute-Force
SSH
๐ซ๐ท
dynamix
2026-08-30 00:08:27
(3 weeks ago)
Multiple WAF Violations
Web App Attack
๐จ๐ฆ
Anytech
2026-08-29 23:36:32
(3 weeks ago)
Blocked by ConnMonitor
Web App Attack
๐ฌ๐ง
OptimusGO
2026-08-29 22:42:58
(3 weeks ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-08-29 23:42:58 UTC
Log evidence:
08/29/2026-23:42:57.829511 [wDrop] [**] [1:7000910:1] FINSERV CRITICAL: Git Repository Access [**] [Classification: Web Application Attack] [Priority: 1] {TCP} 34.92.128.193:59516 -> 185.127.18.66:80
08/29/2026-23:42:57.832745 [wDrop] [**] [1:7000910:1] FINSERV CRITICAL: Git Repository Access [**] [Classification: Web Application Attack] [Priority: 1] {TCP} 34.92.128.193:59528 -> 185.127.18.66:80
show less
Port Scan
Brute-Force
Anonymous
2026-08-28 22:08:34
(3 weeks ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 19:02:40
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 34.92.128.193 (193.128.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 34.92.128.193 (193.128.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 15:02:32.441042 2026] [security2:error] [pid 21524:tid 21524] [client 34.92.128.193:34192] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||uhfcfoundation.org|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "uhfcfoundation.org"] [uri "/access.log"] [unique_id "apHbSK2GnYiJ96lUXe4BhQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 18:25:06
(3 weeks ago)
suspicious request in access.log
Web App Attack
Anonymous
2026-08-27 16:06:15
(3 weeks ago)
Trying to access config files
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-08-27 14:22:32
(3 weeks ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 13:17:09
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.92.128.193 (193.128.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.128.193 (193.128.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 09:17:00.963068 2026] [security2:error] [pid 7360:tid 7360] [client 34.92.128.193:43832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.movers.ink2wear.com"] [uri "/app/.git/config"] [unique_id "apA4zNiCyupm_qfXt7cVtgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Lunix
2026-08-27 12:49:35
(3 weeks ago)
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-08-27 10:40:55
(3 weeks ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ซ๐ท
ELYAZ
2026-08-27 09:36:28
(3 weeks ago)
(y3) Failed access -byebye- from 34.92.128.193 (HK/Hong Kong/193.128.92.34.bc.googleusercontent.com) ...
show more
(y3) Failed access -byebye- from 34.92.128.193 (HK/Hong Kong/193.128.92.34.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 07:44:07
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.92.128.193 (193.128.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.128.193 (193.128.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 03:44:02.986404 2026] [security2:error] [pid 31579:tid 31579] [client 34.92.128.193:42040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yevid.com"] [uri "/app/.git/config"] [unique_id "ao_qwm17fbaDZsjhrhywzQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 05:51:14
(4 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.92.128.193 (193.128.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.128.193 (193.128.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 01:51:09.977688 2026] [security2:error] [pid 1043:tid 1043] [client 34.92.128.193:48770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mortuarymessageservices.com"] [uri "/wordpress/.git/config"] [unique_id "ao_QTQoWTGwktnjS-sCl6gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack