๐ฟ๐ฆ
conure.sh
2026-09-17 12:11:31
(14 hours ago)
csagent: score 20.4: secrets grab x2, 404 noise floor x2; 1 domain(s) in 5s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 09:30:03
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.133.254 (254.133.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.133.254 (254.133.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 05:29:56.995695 2026] [security2:error] [pid 4247:tid 4247] [client 34.97.133.254:51276] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "windisfun.com"] [uri "/.git/config"] [unique_id "aquzFIojFbIQWkXlfXqiFQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-17 04:55:41
(21 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-17 04:49:55
(21 hours ago)
csagent: score 20.3: secrets grab x2, 404 noise floor x2; 2 domain(s) in 3s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 02:41:53
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.133.254 (254.133.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.133.254 (254.133.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:41:46.979992 2026] [security2:error] [pid 31069:tid 31190] [client 34.97.133.254:52184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "workbykathryn.com"] [uri "/.git/config"] [unique_id "aqtTat-GhbskKmm_qiioOgAAAhY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 02:16:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.97.133.254 (254.133.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.133.254 (254.133.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:16:10.821053 2026] [security2:error] [pid 12930:tid 12930] [client 34.97.133.254:56452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "words.gmacguffin.com"] [uri "/.git/config"] [unique_id "aqtNalqAUjZ9BX9zVeXhiAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 15:51:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.97.133.254 (254.133.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.133.254 (254.133.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 11:51:02.872816 2026] [security2:error] [pid 14388:tid 14388] [client 34.97.133.254:58578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "willandtrustlaw.com"] [uri "/.git/config"] [unique_id "aqq65m8So2GUPZXBUUK7bwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-16 15:15:25
(1 day ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-16 14:26:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.97.133.254 (254.133.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.133.254 (254.133.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 10:26:45.381191 2026] [security2:error] [pid 15726:tid 15726] [client 34.97.133.254:59126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wilhelminas.biz"] [uri "/.git/config"] [unique_id "aqqnJQjAXvxqCwPjFPaiOgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 13:01:35
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ณ๐ฑ
i-turnradio.nl
2026-09-16 12:02:26
(1 day ago)
2026-09-16 @ 14:02:15 (CET) ~ Blocked for trying to access: /.env.local
Web App Attack
Anonymous
2026-09-16 12:02:14
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 11:55:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.97.133.254 (254.133.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.133.254 (254.133.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 07:55:22.144229 2026] [security2:error] [pid 1438:tid 1438] [client 34.97.133.254:42008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wildrosestudios.tv"] [uri "/.git/config"] [unique_id "aqqDqkiaZpz53-vvY4Z2CQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-16 11:23:39
(1 day ago)
[WedSep1613:23:32.7397912026][security2:error][pid498373:tid498477][client34.97.133.254:0]ModSecurit ...
show more
[WedSep1613:23:32.7397912026][security2:error][pid498373:tid498477][client34.97.133.254:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"wildpferde.ch\"][uri\"/\"][unique_id\"aqp8NPZUTpROptOs9lu0zwAAAJE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 11:23:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.97.133.254 (254.133.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.133.254 (254.133.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 07:23:16.189097 2026] [security2:error] [pid 27067:tid 27067] [client 34.97.133.254:43536] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wildpete.com"] [uri "/.git/config"] [unique_id "aqp8JFcXW1TCjUDgP-PSVAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack