๐ฉ๐ช
arnisolutions
2026-09-02 07:27:15
(1 hour ago)
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production s ...
show more
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production server. Observed on 1 day(s) between 2026-09-02 and 2026-09-02 (UTC). Sample request: GET / HTTP/2.0
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-02 05:40:48
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.94.89.227 (227.89.94.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.89.227 (227.89.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 01:40:43.735768 2026] [security2:error] [pid 19488:tid 19488] [client 34.94.89.227:48162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whatireallydid.com"] [uri "/.git/config"] [unique_id "ape2221N-FkaPjz52iVQOgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 04:48:52
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.94.89.227 (227.89.94.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.89.227 (227.89.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 00:48:48.838605 2026] [security2:error] [pid 10957:tid 10957] [client 34.94.89.227:51728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whatcausesmentalillness.com"] [uri "/.git/config"] [unique_id "apeqsJIlNEg5nzWEriwldwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-02 04:05:37
(5 hours ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฟ
Antinson
2026-09-02 03:42:12
(5 hours ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-02 02:54:04
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.94.89.227 (227.89.94.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.89.227 (227.89.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 22:53:57.390152 2026] [security2:error] [pid 27727:tid 27727] [client 34.94.89.227:60788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whaletailbikini.com"] [uri "/.git/config"] [unique_id "apePxfrNsZZNFvUgRvkDwAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
nzhost.co.nz
2026-09-02 02:17:46
(6 hours ago)
$f2bV_matches
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-02 00:20:25
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.94.89.227 (227.89.94.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.89.227 (227.89.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 20:20:22.277564 2026] [security2:error] [pid 20656:tid 20656] [client 34.94.89.227:40478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wgs.cc"] [uri "/.git/config"] [unique_id "apdrxpbx06fhqMS3VkRrKAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 23:51:04
(9 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-01 23:00:08
(10 hours ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-01 22:54:17
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.94.89.227 (227.89.94.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.89.227 (227.89.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 18:54:12.093915 2026] [security2:error] [pid 15301:tid 15301] [client 34.94.89.227:44092] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wgalleria.com"] [uri "/.git/config"] [unique_id "apdXlL3BHoZ2nQ69ASHzIAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Kitki30.com
2026-09-01 22:29:22
(10 hours ago)
HTTP Probing (server 3). Log: 34.94.89.227 - - [01/Sep/2026:22:29:21 +0000] "GET /.git/config HTTP/1 ...
show more
HTTP Probing (server 3). Log: 34.94.89.227 - - [01/Sep/2026:22:29:21 +0000] "GET /.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.94.89.227 - - [01/Sep/2026:22:29:21 +0000] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
nayumi
2026-09-01 22:19:45
(10 hours ago)
CrowdSec detection: crowdsecurity/http-sensitive-files | Service: http, http, http, http, http
Web App Attack
๐ฉ๐ช
enjoyably
2026-09-01 22:10:47
(10 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-01 20:46:11
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.94.89.227 (227.89.94.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.89.227 (227.89.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 16:46:05.627389 2026] [security2:error] [pid 1899:tid 1899] [client 34.94.89.227:55198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wfowisdom.com"] [uri "/.git/config"] [unique_id "apc5jZT5R6N70n3ctKSc-QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack