🇺🇸
TPI-Abuse
2026-09-04 21:50:42
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.139.225 (225.139.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.139.225 (225.139.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:50:36.950001 2026] [security2:error] [pid 7029:tid 7029] [client 34.92.139.225:58152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jfexpressfr8.com"] [uri "/htdocs/.git/config"] [unique_id "aps9LNHRPBAiwW7wAqhtSAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 21:33:53
(22 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 21:18:07
(22 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 21:00:39
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.139.225 (225.139.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.139.225 (225.139.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:00:33.737853 2026] [security2:error] [pid 21754:tid 21754] [client 34.92.139.225:43900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dick-schoonover.com"] [uri "/htdocs/.git/config"] [unique_id "apsxcTQaF_yCum1_y2V4pAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 18:52:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.92.139.225 (225.139.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.139.225 (225.139.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 14:52:30.944575 2026] [security2:error] [pid 1451031:tid 1451031] [client 34.92.139.225:50860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.eastbrooktech.com"] [uri "/app/.git/config"] [unique_id "apsTbtbmu3DnE_2fFE5oEwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 17:07:03
(1 day ago)
Automated web scanner. Requested suspicious paths: /htdocs/.git/config | /site/.git/config | /.git/c ...
show more
Automated web scanner. Requested suspicious paths: /htdocs/.git/config | /site/.git/config | /.git/config | /var/www/.git/config | /wordpress/.git/config | /html/.git/config | /public/.git/config. UTC: 2026-09-04 16:19:44.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:17:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.92.139.225 (225.139.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.139.225 (225.139.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:17:20.777494 2026] [security2:error] [pid 3074850:tid 3074898] [client 34.92.139.225:35290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "undergroundinternational.com.oplconnect.com"] [uri "/.git/config"] [unique_id "aprS8ADE4i4QbWxJxPwpCAAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-04 13:53:45
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
antlac1
2026-09-04 09:22:09
(1 day ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇮🇹
CoreTech srl
2026-09-04 05:08:56
(1 day ago)
cloudlinux2 fail2ban: 2026-09-04 07:04:16,522 fail2ban.filter [1594]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-04 07:04:16,522 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 180.153.236.60 - 2026-09-04 07:04:16cloudlinux2 fail2ban: 2026-09-04 07:04:26,322 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 35.201.135.19 - 2026-09-04 07:04:26cloudlinux2 fail2ban: 2026-09-04 07:04:37,859 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.92.139.225 - 2026-09-04 07:04:37cloudlinux2 fail2ban: 2026-09-04 07:04:38,239 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.92.139.225 - 2026-09-04 07:04:38cloudlinux2 fail2ban: 2026-09-04 07:04:37,766 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.92.139.225 - 2026-09-04 07:04:37cloudlinux2 fail2ban: 2026-09-04 07:04:37,866 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.92.139.225 - 2026-09-04 07:04:37cloudlinux2 fail2ban: 2026-09-04 07:04:38,259 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.92.139.225 - 2026-09-04 07
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 04:55:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.92.139.225 (225.139.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.139.225 (225.139.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:54:53.701383 2026] [security2:error] [pid 28821:tid 28821] [client 34.92.139.225:44248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.baystarpartners.com"] [uri "/www/.git/config"] [unique_id "appPHckTtgu8dDa44S39FwAAAC8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 01:54:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.92.139.225 (225.139.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.139.225 (225.139.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 21:54:21.351771 2026] [security2:error] [pid 26571:tid 26571] [client 34.92.139.225:41640] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agreyhawkcampaign.net.bandsolution.net"] [uri "/.git/config"] [unique_id "apokzdBBxrOiVeF3CkLBOgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 00:45:01
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-09-04 00:18:41
(1 day ago)
[ns27.kdns.gr] httpd-config-scan: sites=www.foraofakous.gr; logs=/var/log/httpd/domains/foraofakous. ...
show more
[ns27.kdns.gr] httpd-config-scan: sites=www.foraofakous.gr; logs=/var/log/httpd/domains/foraofakous.gr.log; samples=/www/.git/config | /public/.git/config | /wordpress/.git/config
show less
Hacking
Web App Attack
🇫🇷
masterguru
2026-09-04 00:14:11
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.92.139.225 (225.139.92.34.bc.googl ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.92.139.225 (225.139.92.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking