๐ฟ๐ฆ
conure.sh
2026-09-16 12:07:38
(3 days ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 2s
Web App Attack
Anonymous
2026-09-16 08:43:14
(3 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 08:41:50
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.96.202.78 (78.202.96.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.202.78 (78.202.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 04:41:43.756171 2026] [security2:error] [pid 31598:tid 31598] [client 34.96.202.78:45342] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.weismanovens.daveweisman.com"] [uri "/.git/config"] [unique_id "aqpWR75gY8WkwMfzQBOAfQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-09-16 08:09:17
(3 days ago)
URL Probing: /server/.env
Web App Attack
๐ฆ๐น
penguin-solutions.at
2026-09-16 06:37:01
(3 days ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 06:26:03
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.96.202.78 (78.202.96.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.202.78 (78.202.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 02:25:55.752749 2026] [security2:error] [pid 19728:tid 19728] [client 34.96.202.78:51256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.weightlossover50.customdesignsbybjp.com"] [uri "/.git/config"] [unique_id "aqo2c9fHg0e4jnI8lbNArgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-16 05:50:11
(3 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-16 05:39:23
(3 days ago)
34.96.202.78 - - [16/Sep/2026:07:39:18 +0200] "GET /.env.staging HTTP/1.1" 404 520 "-" "Mozilla/5.0 ...
show more
34.96.202.78 - - [16/Sep/2026:07:39:18 +0200] "GET /.env.staging HTTP/1.1" 404 520 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.96.202.78 - - [16/Sep/2026:07:39:18 +0200] "GET /.env.development HTTP/1.1" 404 520 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.96.202.78 - - [16/Sep/2026:07:39:19 +0200] "GET /.env.test HTTP/1.1" 404 520 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.96.202.78 - - [16/Sep/2026:07:39:19 +0200] "GET /.env.remote HTTP/1.1" 404 520 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.96.202.78 - - [16/Sep/2026:07:39:19 +0200] "GET /.env.bak HTTP/1.1" 404 520 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.96.202.78 - - [16/Sep/2026:07:39:19 +0200] "GE
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-16 04:36:50
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.96.202.78 (78.202.96.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.202.78 (78.202.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 00:36:43.594208 2026] [security2:error] [pid 26640:tid 26648] [client 34.96.202.78:37078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wegelin.kylight.com"] [uri "/.git/config"] [unique_id "aqoc2wov_FmABo9ZnDJCUwAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-16 03:56:14
(3 days ago)
(modsecurity) srv102 ModSecurity 34.96.202.78 (HK/Hong Kong/78.202.96.34.bc.googleusercontent.com): ...
show more
(modsecurity) srv102 ModSecurity 34.96.202.78 (HK/Hong Kong/78.202.96.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 02:25:17
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.96.202.78 (78.202.96.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.202.78 (78.202.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 22:25:12.206305 2026] [security2:error] [pid 28292:tid 28292] [client 34.96.202.78:54440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.weebly.martinka.org"] [uri "/.git/config"] [unique_id "aqn-CFY2xDH3YWRgVsBVCgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:19:51
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.96.202.78 (78.202.96.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.202.78 (78.202.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:19:44.696029 2026] [security2:error] [pid 27296:tid 27296] [client 34.96.202.78:39796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wedemandavote.empoweruohio.org"] [uri "/.git/config"] [unique_id "aqnusHkyX5S6V2M4YoWCqAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 23:59:17
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.96.202.78 (78.202.96.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.202.78 (78.202.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 19:59:12.104675 2026] [security2:error] [pid 29833:tid 29833] [client 34.96.202.78:49626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.weddingcapitalpartners.vittariadesign.com"] [uri "/.git/config"] [unique_id "aqnb0HWdcpPI6FM4YkL-ZwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-15 23:11:14
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-15 20:46:12
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.96.202.78 (78.202.96.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.96.202.78 (78.202.96.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:46:08.992557 2026] [security2:error] [pid 15145:tid 15145] [client 34.96.202.78:42386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.webtree.grimone.com"] [uri "/.git/config"] [unique_id "aqmukCltB3mH9GgHzVjvTQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack