๐บ๐ธ
TPI-Abuse
2026-09-01 22:23:03
(4 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.92.227.23 (23.227.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.227.23 (23.227.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 18:22:58.428098 2026] [security2:error] [pid 15532:tid 15532] [client 34.92.227.23:53614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brunerdevelopment.littlehorndesign.com"] [uri "/api/.git/config"] [unique_id "apdQQvtmFHbJxypuLHB-SwAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 21:16:15
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 20:17:47
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.227.23 (23.227.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.227.23 (23.227.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 16:17:43.619574 2026] [security2:error] [pid 26729:tid 26787] [client 34.92.227.23:40958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cynosurelandscapers.com"] [uri "/.git/config"] [unique_id "apcy56267NSCeOswjFqbYwAAAcs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-01 18:40:10
(3 hours ago)
Multiple WAF Violations
Web App Attack
๐ง๐ท
dominioz
2026-09-01 14:04:42
(8 hours ago)
2026-09-01 14:04:18 GET /html/.git/config - - 34.92.227.23 HTTP/1.1 crusader-worker/1.0 - 301 592
20 ...
show more
2026-09-01 14:04:18 GET /html/.git/config - - 34.92.227.23 HTTP/1.1 crusader-worker/1.0 - 301 592
2026-09-01 14:04:18 GET /www/.git/config - - 34.92.227.23 HTTP/1.1 crusader-worker/1.0 - 301 590
2026-09-01 14:04:18 GET /htdocs/.git/config - - 34.92.227.23 HTTP/1.1 crusader-worker/1.0 - 301 596
2026-09-01 14:04:18 GET /src/.git/config - - 34.92.227.23 HTTP/1.1 crusader-worker/1.0 - 301 590
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 13:43:43
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.227.23 (23.227.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.227.23 (23.227.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 09:43:37.171594 2026] [security2:error] [pid 20099:tid 20099] [client 34.92.227.23:60886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "barnquiltsofnorthernvermont.org"] [uri "/public/.git/config"] [unique_id "apbWidhwTwMneCjy1fbsUAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-01 13:32:50
(8 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Ribeye375
2026-09-01 13:14:52
(9 hours ago)
HIPS web-exfiltration - Block tcp/0:65535
Web App Attack
๐ช๐ธ
masterguru
2026-09-01 10:22:37
(12 hours ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 09:52:18
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.227.23 (23.227.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.227.23 (23.227.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:52:13.852455 2026] [security2:error] [pid 236589:tid 236634] [client 34.92.227.23:58532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theinfinitenow.com"] [uri "/wordpress/.git/config"] [unique_id "apagTcfpSwUk1Zhun1mE0QAAAVI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
wteiken
2026-09-01 06:23:26
(16 hours ago)
2026-09-01T02:23:25.064556-04:00 rocinante.teiken.net kernel: [136453.612626] syn_limit:IN=ens5 OUT= ...
show more
2026-09-01T02:23:25.064556-04:00 rocinante.teiken.net kernel: [136453.612626] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=34.92.227.23 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x60 TTL=58 ID=48483 DF PROTO=TCP SPT=53596 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-09-01T02:23:25.064731-04:00 rocinante.teiken.net kernel: [136453.613625] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=34.92.227.23 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x60 TTL=58 ID=19477 DF PROTO=TCP SPT=53642 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-09-01T02:23:25.064758-04:00 rocinante.teiken.net kernel: [136453.615293] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=34.92.227.23 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x60 TTL=58 ID=39926 DF PROTO=TCP SPT=53626 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-09-01T02:23:25.067267-04:00 rocinante.teiken.net kernel: [136453.620691] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:a
...
show less
Port Scan
๐บ๐ธ
jfz-abuse
2026-08-31 17:36:23
(1 day ago)
fail2ban: apache-filepath-recon
...
Web App Attack