🇧🇷
dominioz
2026-09-07 14:27:59
(2 hours ago)
2026-09-07 14:27:29 GET /.git/config - - 34.97.248.23 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+ ...
show more
2026-09-07 14:27:29 GET /.git/config - - 34.97.248.23 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 1987
2026-09-07 14:27:29 GET /.env - - 34.97.248.23 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 1987
2026-09-07 14:27:29 GET /.env.local - - 34.97.248.23 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 1987
2026-09-07 14:27:31 GET /.env.production - - 34.97.248.23 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 1987
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 12:40:24
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.248.23 (23.248.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.248.23 (23.248.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 08:40:19.806023 2026] [security2:error] [pid 7207:tid 7207] [client 34.97.248.23:47758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amaia.portalvasco.com"] [uri "/.git/config"] [unique_id "ap6ws0B3kQlGQmMGYzIAEgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
bazter.pro
2026-09-07 12:05:57
(4 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-07 10:50:01
(5 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 10:18:39
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.248.23 (23.248.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.248.23 (23.248.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:18:33.328889 2026] [security2:error] [pid 20165:tid 20185] [client 34.97.248.23:37740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.alzooma.maxelon.com"] [uri "/.git/config"] [unique_id "ap6PefD9INbBnN-nM3fAKAAAARE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-07 10:01:06
(6 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇳🇱
Site.eu
2026-09-07 08:21:58
(8 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 07:56:18
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.248.23 (23.248.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.248.23 (23.248.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:56:13.157714 2026] [security2:error] [pid 20802:tid 20802] [client 34.97.248.23:54076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.alwayswetandsexy.grayhost.net"] [uri "/.git/config"] [unique_id "ap5uHbKiVjtWmZBl9JdPtQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇺
DZBOT
2026-09-07 06:54:25
(9 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
Anonymous
2026-09-07 06:33:03
(10 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇩🇪
paissangroup
2026-09-06 23:31:49
(17 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 23:03:14
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.248.23 (23.248.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.248.23 (23.248.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 19:03:09.380947 2026] [security2:error] [pid 32528:tid 32528] [client 34.97.248.23:47160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.anewnurse.homehealth101.com"] [uri "/.git/config"] [unique_id "ap3xLe4f4WIS6r4wD4-msQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-06 22:50:04
(17 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-06 22:27:38
(18 hours ago)
34.97.248.23 - - [07/Sep/2026:00:27:33 +0200] "GET /.env.local HTTP/1.1" 404 515 "-" "Mozilla/5.0 (X ...
show more
34.97.248.23 - - [07/Sep/2026:00:27:33 +0200] "GET /.env.local HTTP/1.1" 404 515 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.97.248.23 - - [07/Sep/2026:00:27:33 +0200] "GET /.env.production HTTP/1.1" 404 515 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.97.248.23 - - [07/Sep/2026:00:27:33 +0200] "GET /.env.staging HTTP/1.1" 404 515 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.97.248.23 - - [07/Sep/2026:00:27:33 +0200] "GET /.env.development HTTP/1.1" 404 515 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.97.248.23 - - [07/Sep/2026:00:27:34 +0200] "GET /.env.test HTTP/1.1" 404 515 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.97.248.23 - - [07/Sep/2026:00:27:34 +020
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 21:49:37
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.248.23 (23.248.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.248.23 (23.248.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:49:30.359203 2026] [security2:error] [pid 21383:tid 21383] [client 34.97.248.23:46638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.anekawangi.kairoslogammakmur.com"] [uri "/.git/config"] [unique_id "ap3f6soKqlokP3Nn1eWrMwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack