π©πͺ
FD-IX
2026-09-01 10:21:36
(5 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 10:06:06
(5 hours ago)
BIDSODE WEBEXPLOIT 34.97.54.102 (102.54.97.34.bc.googleusercontent.com)
Web App Attack
π³π±
ConsulHosting
2026-09-01 09:42:17
(6 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
π³π±
Site.eu
2026-09-01 06:36:47
(9 hours ago)
Excessive multi-domain requests
Brute-Force
π©πͺ
4server
2026-09-01 06:24:06
(9 hours ago)
[TueSep0108:24:03.5965432026][security2:error][pid3769845:tid3769940][client34.97.54.102:0]ModSecuri ...
show more
[TueSep0108:24:03.5965432026][security2:error][pid3769845:tid3769940][client34.97.54.102:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.bianchitecno.ch.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"apZvg33-xdf6c4faUdSjEwAAAJA\"]
show less
Port Scan
Brute-Force
Web App Attack
Anonymous
2026-09-01 06:00:01
(9 hours ago)
suspicious request in access.log
Web App Attack
π³π±
Savvii
2026-09-01 05:54:28
(9 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
π§π·
dominioz
2026-09-01 05:44:40
(9 hours ago)
2026-09-01 05:43:37 GET /.git/config - - 34.97.54.102 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+Apple ...
show more
2026-09-01 05:43:37 GET /.git/config - - 34.97.54.102 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 598
2026-09-01 05:43:37 GET /.env - - 34.97.54.102 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 584
2026-09-01 05:43:47 GET /app/.env - - 34.97.54.102 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 592
2026-09-01 05:43:47 GET /apps/.env - - 34.97.54.102 HTTP/1.1 Mozilla/5.0+(X11;+Linux+x86_64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 594
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 04:07:25
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.54.102 (102.54.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.54.102 (102.54.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:07:19.598518 2026] [security2:error] [pid 24717:tid 24717] [client 34.97.54.102:42202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bhs.michaelpmcgrath.com"] [uri "/.git/config"] [unique_id "apZPd5pN3F_PNCZQsV8wYAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-09-01 00:20:22
(15 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
π©πͺ
Balthasar Morpheus JΓΆrmundur (JKweb Service)
2026-09-01 00:00:50
(15 hours ago)
JKweb Security: Severe and dangerous web attack detected. Vulnerability Wordpress Scanning, Director ...
show more
JKweb Security: Severe and dangerous web attack detected. Vulnerability Wordpress Scanning, Directory Brute-Forcing / Content Discovery, Predictable Resource Location / Forced Browsing, Scan for administration and debugging interfaces of modern frameworks, Scan for Spring Boot Actuator Leaks, Scan for Cloud & Infrastructure Credentials, Scan for Database & Backup Dumps, Scan for IDE- und Editor-Configurations, Scan for CI/CD Pipelines & GitHub Workflows etc. The Attacker is permanently banned by Fail2Ban, configurate by JKweb Security a brand of JKweb Service.
show less
Port Scan
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 11:42:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.97.54.102 (102.54.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.54.102 (102.54.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 07:41:58.655948 2026] [security2:error] [pid 27083:tid 27083] [client 34.97.54.102:33574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bvi-boat-registration.com.boatregistrationdelaware.com"] [uri "/.git/config"] [unique_id "apVoho6zgkzCZzwyMjHKbgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 11:00:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.97.54.102 (102.54.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.54.102 (102.54.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 07:00:03.975506 2026] [security2:error] [pid 3348:tid 3361] [client 34.97.54.102:42498] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.buyused-jomega.jomega.org"] [uri "/.git/config"] [unique_id "apVesxxZMtl8EsPBoMiqcQAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 10:13:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.97.54.102 (102.54.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.54.102 (102.54.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 06:13:10.116720 2026] [security2:error] [pid 18212:tid 18212] [client 34.97.54.102:58690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.buygoldandsilveratspot.mroxygen.org"] [uri "/.git/config"] [unique_id "apVTtv7oyfMQ8hzCTGeOxgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 08:21:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.97.54.102 (102.54.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.54.102 (102.54.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 04:21:14.417191 2026] [security2:error] [pid 7729:tid 7729] [client 34.97.54.102:58356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.busybconstruction.ewingmissouri.com"] [uri "/.git/config"] [unique_id "apU5eu8hqEgLMF15V2E2rQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack