๐บ๐ธ
dot.mg
2026-09-17 04:04:10
(1 day ago)
Scan of vulnerable files
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-17 02:16:57
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 14:34:32
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.97.191.71 (71.191.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.191.71 (71.191.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 10:34:24.844987 2026] [security2:error] [pid 4260:tid 4260] [client 34.97.191.71:35772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wisdomworkforceoptimization.com"] [uri "/.git/config"] [unique_id "aqqo8L2M_jRAE-wPJwG_cwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:47:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.97.191.71 (71.191.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.191.71 (71.191.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:47:07.751552 2026] [security2:error] [pid 7872:tid 7872] [client 34.97.191.71:46650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wiro.am"] [uri "/.git/config"] [unique_id "aqqd28IztuUDbRRwuD_nWgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-09-16 13:23:01
(2 days ago)
2026-09-16 15:21:14 GET /.git/config [301] && 2026-09-16 15:21:15 GET /.env [301] && 2026-09-16 15:2 ...
show more
2026-09-16 15:21:14 GET /.git/config [301] && 2026-09-16 15:21:15 GET /.env [301] && 2026-09-16 15:21:17 GET /.env.bak [301] && 141 more within 20 minutes
show less
Web App Attack
๐จ๐ญ
Origon
2026-09-16 13:22:36
(2 days ago)
http-sensitive-files - IP: 34.97.191.71 - time="2026-09-16T15:22:36+02:00" level=info msg="(555f66b ...
show more
http-sensitive-files - IP: 34.97.191.71 - time="2026-09-16T15:22:36+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 34.97.191.71 (JP/396982) : 4h ban on Ip 34.97.191.71" module=db
show less
Web App Attack
๐ฆ๐บ
Klaverstyn
2026-09-16 13:01:42
(2 days ago)
Cross-vhost secrets/RCE probing campaign
Web App Attack
Hacking
๐ณ๐ด
jad-abuse
2026-09-16 12:59:01
(2 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, env_probe, source_backup, server_status, wp_admin. Observed by 1 sensor(s); 521 hits.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 06:13:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.97.191.71 (71.191.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.191.71 (71.191.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 02:13:38.405008 2026] [security2:error] [pid 402:tid 402] [client 34.97.191.71:48292] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ww-bbs.com"] [uri "/.git/config"] [unique_id "aqozkpAJuPUlhv8bekikVAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack