๐ฒ๐ฝ
octageeks.com
2026-09-01 04:13:04
(3 minutes ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ซ๐ท
dynamix
2026-09-01 03:31:49
(44 minutes ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-01 03:23:04
(53 minutes ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-09-01 02:22:17
(1 hour ago)
Suspicious URL access.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 01:40:48
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.22.40 (40.22.97.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.22.40 (40.22.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 21:40:41.583368 2026] [security2:error] [pid 12198:tid 12198] [client 34.97.22.40:43316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aws.corepest.com"] [uri "/.git/config"] [unique_id "apYtGeVYOyCvcyDV55uumwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 00:16:56
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฉ๐ช
todix
2026-08-31 17:36:07
(10 hours ago)
WebAttack or semilar from 34.97.22.40
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 17:28:55
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.22.40 (40.22.97.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.22.40 (40.22.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 13:28:51.747540 2026] [security2:error] [pid 19771:tid 19771] [client 34.97.22.40:38002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blogs.melton.space"] [uri "/.git/config"] [unique_id "apW509Yjzvj5Im76yN0N-QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-31 17:20:42
(10 hours ago)
34.97.22.40 - - [31/Aug/2026:14:20:40 -0300] "GET /.git/config HTTP/1.1" 403 829 "-" "Mozilla/5.0 (M ...
show more
34.97.22.40 - - [31/Aug/2026:14:20:40 -0300] "GET /.git/config HTTP/1.1" 403 829 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.97.22.40 - - [31/Aug/2026:14:20:41 -0300] "GET /.env HTTP/1.1" 403 829 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Port Scan
๐ต๐ฑ
TaKeN
2026-08-31 17:00:26
(11 hours ago)
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application pr ...
show more
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing from this source IP. Observed 1 matching blocked event(s) between 2026-08-31T19:00:26+02:00 and 2026-08-31T19:00:26+02:00. Sample requested paths: /.env.old.
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-31 16:39:37
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.22.40 (40.22.97.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.22.40 (40.22.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 12:39:29.998002 2026] [security2:error] [pid 13621:tid 13621] [client 34.97.22.40:60066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blog.tracybur.net"] [uri "/.git/config"] [unique_id "apWuQV1xybkjeuFnqBkmZwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-31 16:15:22
(12 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 15:57:39
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.22.40 (40.22.97.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.22.40 (40.22.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 11:57:30.072445 2026] [security2:error] [pid 24051:tid 24051] [client 34.97.22.40:40590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blog.ontrek.com"] [uri "/.git/config"] [unique_id "apWkaskoL1hgMREdkCCJYQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 15:18:47
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.22.40 (40.22.97.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.22.40 (40.22.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 11:18:39.643971 2026] [security2:error] [pid 13092:tid 13092] [client 34.97.22.40:43114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blog.istanbulartlist.com.pist.org.tr"] [uri "/.git/config"] [unique_id "apWbT6kz9uW8dyFtYe9tygAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-31 15:10:02
(13 hours ago)
suspicious request in access.log
Web App Attack