๐ฉ๐ช
Hary74656
2026-09-21 00:06:37
(3 hours ago)
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3.
[earlier text truncated]
2). Oper ...
show more
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3.
[earlier text truncated]
2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/opt/owasp-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 55)"] [ver "OWASP_CRS/4.29.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "weavernet.at"] [uri "/"] [unique_id "arB1DZ5ED7Bbnia6ewHTsQAAABY"]
[Mon Sep 21 02:06:37.353347 2026] [vhost weavernet.at] [security2:error] [pid 393945:tid 140485049951936] [client 34.92.248.228:49092] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/opt/owasp-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 30)"] [ver "OWASP_CRS/4.29.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "weavernet.at"] [uri "/"] [unique_id "arB1DZ5ED7Bbnia6ewHTsgAAAAg"]
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:05:06
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.248.228 (228.248.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.248.228 (228.248.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:05:02.292562 2026] [security2:error] [pid 9922:tid 9922] [client 34.92.248.228:42216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "weavergroup.us"] [uri "/.git/config"] [unique_id "arB0roAJ2pueJhKTycJfbwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:17:00
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.248.228 (228.248.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.248.228 (228.248.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:16:56.466707 2026] [security2:error] [pid 18719:tid 18719] [client 34.92.248.228:47308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "weathercarib.com"] [uri "/.git/config"] [unique_id "arBpaEZXxg_Ma_9U06MqJwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ฌ
HighWay
2026-09-20 23:08:32
(4 hours ago)
34.92.248.228 - - [20/Sep/2026:23:08:27 +0000] "GET /phpinfo.php HTTP/1.1" 404 734 "-" "Mozilla/5.0 ...
show more
34.92.248.228 - - [20/Sep/2026:23:08:27 +0000] "GET /phpinfo.php HTTP/1.1" 404 734 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.92.248.228 - - [20/Sep/2026:23:08:27 +0000] "GET /info.php HTTP/1.1" 404 734 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.92.248.228 - - [20/Sep/2026:23:08:27 +0000] "GET /php.php HTTP/1.1" 404 734 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.92.248.228 - - [20/Sep/2026:23:08:27 +0000] "GET /i.php HTTP/1.1" 404 734 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.92.248.228 - - [20/Sep/2026:23:08:28 +0000] "GET /pi.php HTTP/1.1" 404 734 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.92.248.228
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
RamSet
2026-09-20 23:04:14
(4 hours ago)
[wx] HTTP-Probe on port 443 (via domain). 249 distinct paths probed in 51s. Sustained 253 req/min, 2 ...
show more
[wx] HTTP-Probe on port 443 (via domain). 249 distinct paths probed in 51s. Sustained 253 req/min, 248 nonexistent paths (404). Paths: /.git/config, /.env, /.env.local, /.env.production, /.env.staging, /.env.development, /.env.test, /.env.remote, /.env.bak, /.env.backup, /.env.save, /.env.old, /.env.sample, /.env.example, /.env.dev, /.env.prod, /.env.stage, /.env.ci, /.env.docker, /.env.live, /.env.preprod, /.env.uat, /.env.dist, /.env.swp, /.env.txt, /.env.json, /.env.yaml, /.env.yml, /app/.env, /apps/.env, /api/.env, /web/.env, /site/.env, /public/.env, /admin/.env, /backend/.env, /server/.env, /frontend/.env, /src/.env, /core/.env, /core/app/.env, /config/.env, /private/.env, /application/.env, /bootstrap/.env, /database/.env, /storage/.env, /var/www/.env, /var/www/html/.env, /current/.env, /release/.env, /releases/.env, /shared/.env, /deploy/.env, /build/.env, /dist/.env, /public_html/.env, /htdocs/.env, /www/.env, /html/.env
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
nyt
2026-09-20 20:04:13
(7 hours ago)
Sensitive File Probe
Web App Attack
๐ซ๐ท
pm33
2026-09-20 18:13:40
(9 hours ago)
Probing for resource vulnerabilities HTTP(S)
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-09-20 17:10:11
(10 hours ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
228.248.92.34.bc.googleusercontent.com
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 16:02:57
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.248.228 (228.248.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.248.228 (228.248.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 12:02:52.654745 2026] [security2:error] [pid 13232:tid 13232] [client 34.92.248.228:33812] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wea-inc.com"] [uri "/.git/config"] [unique_id "arADrBonSdMXPLCRj37lgQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 15:45:04
(11 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-09-20 15:10:23
(12 hours ago)
Malicious activity from IP detected: crowdsecurity/http-sensitive-files.
Web App Attack
Hacking
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-20 14:30:45
(13 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
Site.eu
2026-09-20 14:13:19
(13 hours ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-09-20 13:30:16
(14 hours ago)
| [Dangerous/Hong Kong] Aggressive IP 34.92.248.228 (~30 hits). Type: DoS Defender- Web server 400 e ...
show more
| [Dangerous/Hong Kong] Aggressive IP 34.92.248.228 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection