๐ท๐บ
Albram
2026-09-28 07:30:14
(11 hours ago)
Tries find Web server vulnerability
...
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 06:31:10
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.173.93 (93.173.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.173.93 (93.173.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 02:31:05.431708 2026] [security2:error] [pid 1079:tid 1079] [client 34.92.173.93:47550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vsecuritysolutions.com"] [uri "/.git/config"] [unique_id "aroJqd81juXSwmg6lU4ReAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-27 06:37:25
(1 day ago)
2026/09/27 07:37:17 [error] 2462#2462: *240158 access forbidden by rule, client: 34.92.173.93, serve ...
show more
2026/09/27 07:37:17 [error] 2462#2462: *240158 access forbidden by rule, client: 34.92.173.93, server: webapp.gwynethllewelyn.net, request: "GET /.env HTTP/1.1", host: "webapp.gwynethllewelyn.net"
34.92.173.93 - - [27/Sep/2026:07:37:17 +0100] "GET /.env HTTP/1.1" 403 1178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026/09/27 07:37:23 [error] 2462#2462: *240158 access forbidden by rule, client: 34.92.173.93, server: webapp.gwynethllewelyn.net, request: "GET /app/.env HTTP/1.1", host: "webapp.gwynethllewelyn.net"
show less
Brute-Force
Web App Attack
๐ท๐ด
iulianh
2026-09-27 04:06:23
(1 day ago)
80,443
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-26 20:32:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.92.173.93 (93.173.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.173.93 (93.173.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 16:32:47.830399 2026] [security2:error] [pid 14103:tid 14130] [client 34.92.173.93:43008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.attorneylouisiana.com"] [uri "/.git/config"] [unique_id "argr76PR_nkLCUqxeZDVDwAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 17:33:51
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.173.93 (93.173.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.173.93 (93.173.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 13:33:43.758658 2026] [security2:error] [pid 28806:tid 28926] [client 34.92.173.93:47338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.furball.co.uk"] [uri "/.git/config"] [unique_id "arawd7gI6ihdC6SzN4cWSAAAAI4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 14:11:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.173.93 (93.173.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.173.93 (93.173.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 10:11:37.966093 2026] [security2:error] [pid 9048:tid 9048] [client 34.92.173.93:40402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3ddatacenters.com"] [uri "/.git/config"] [unique_id "araBGQjCGRU56kYyKIXTRgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
gadix
2026-09-25 08:16:56
(3 days ago)
[25/Sep/2026:10:16:55.329611 +0200] arYt97iBRqvnZ9ADwmXdZQAAAAI 34.92.173.93 57638 127.0.0.1 7081
[2 ...
show more
[25/Sep/2026:10:16:55.329611 +0200] arYt97iBRqvnZ9ADwmXdZQAAAAI 34.92.173.93 57638 127.0.0.1 7081
[25/Sep/2026:10:16:55.744972 +0200] arYt96MTpkPde0wIvlVM0AAAAAQ 34.92.173.93 57648 127.0.0.1 7081
[25/Sep/2026:10:16:55.947965 +0200] arYt9xlK_AS8iPS3OIQLGwAAAAU 34.92.173.93 57664 127.0.0.1 7081
...
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-25 02:36:49
(3 days ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.92.173.93 - - [25/Sep/2026:04:36:28 +0200] "GET /roundcube//.git/config HTTP/1.1" 403 7438 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 18:47:56
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.173.93 (93.173.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.173.93 (93.173.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:47:49.923111 2026] [security2:error] [pid 4577:tid 4577] [client 34.92.173.93:59198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.danieljensen.org"] [uri "/.git/config"] [unique_id "arVwVdIWNz2gukypmVPNqwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 18:30:07
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.173.93 (93.173.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.173.93 (93.173.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:29:57.662200 2026] [security2:error] [pid 27470:tid 27470] [client 34.92.173.93:54790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.danielbrower.circleofsound.org"] [uri "/.git/config"] [unique_id "arVsJUck7Q05caDdcQSsmgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-24 09:40:35
(4 days ago)
[ThuSep2411:40:33.3486882026][security2:error][pid3494303:tid3494343][client34.92.173.93:0]ModSecuri ...
show more
[ThuSep2411:40:33.3486882026][security2:error][pid3494303:tid3494343][client34.92.173.93:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"webdisk.pytag.ch\"][uri\"/.env.bak\"][unique_id\"arTwETt2VzMixS0JmMgRzgAAAEQ\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-09-23 14:15:23
(5 days ago)
[WedSep2316:15:16.8847682026][security2:error][pid2304750:tid2304846][client34.92.173.93:0]ModSecuri ...
show more
[WedSep2316:15:16.8847682026][security2:error][pid2304750:tid2304846][client34.92.173.93:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"webdisk.jrtradeinnovation.ch\"][uri\"/.env.bak\"][unique_id\"arPe9Kku10M550gd4By1IwAAAMA\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
itsolon
2026-09-22 14:14:39
(6 days ago)
[22/Sep/2026:16:14:38 +0200] 179008647861.756859 34.92.173.93 35262 217.154.7.177 443
[22/Sep/2026:1 ...
show more
[22/Sep/2026:16:14:38 +0200] 179008647861.756859 34.92.173.93 35262 217.154.7.177 443
[22/Sep/2026:16:14:38 +0200] 179008647877.595665 34.92.173.93 35262 217.154.7.177 443
[22/Sep/2026:16:14:39 +0200] 179008647952.769661 34.92.173.93 35262 217.154.7.177 443
[22/Sep/2026:16:14:39 +0200] 179008647955.004000 34.92.173.93 35262 217.154.7.177 443
[22/Sep/2026:16:14:39 +0200] 179008647957.697307 34.92.173.93 35262 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 05:24:59
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.173.93 (93.173.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.173.93 (93.173.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 01:24:54.178000 2026] [security2:error] [pid 25420:tid 25420] [client 34.92.173.93:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.webuildbeaches.com"] [uri "/.git/config"] [unique_id "arIRJobXSSdmqlm9aTWHZgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack