๐ฟ๐ฆ
conure.sh
2026-09-02 15:26:54
(1 hour ago)
csagent: score 20.7: 404 noise floor x3, secrets grab x2; 1 domain(s) in 2s
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-02 13:27:04
(3 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 10:39:58
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.55.89 (89.55.97.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.55.89 (89.55.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 06:39:53.128431 2026] [security2:error] [pid 16356:tid 16356] [client 34.97.55.89:54962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amybeam.info.amybeam.com"] [uri "/.git/config"] [unique_id "apf8-YA4WeLPiS0ibc6HTwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
zynex
2026-09-02 08:40:59
(7 hours ago)
URL Probing: /.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 08:29:27
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 34.97.55.89 (89.55.97.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 34.97.55.89 (89.55.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 04:29:21.485447 2026] [security2:error] [pid 24598:tid 24598] [client 34.97.55.89:37988] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.amsterdamlayovers.thinkingepic.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.amsterdamlayovers.thinkingepic.com"] [uri "/phpinfo.php.bak"] [unique_id "apfeYYjH2A-AwornQ5nnYwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-02 08:26:26
(8 hours ago)
(modsecurity) srv103 ModSecurity 34.97.55.89 (JP/Japan/89.55.97.34.bc.googleusercontent.com): 30 in ...
show more
(modsecurity) srv103 ModSecurity 34.97.55.89 (JP/Japan/89.55.97.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ซ๐ท
dynamix
2026-09-02 08:23:28
(8 hours ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-02 08:17:58
(8 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-02 08:14:04
(8 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.test HTTP/1.1, GET /.env.staging HTTP/1.1, GET /.e ...
show more
Bot / scanning and/or hacking attempts: GET /.env.test HTTP/1.1, GET /.env.staging HTTP/1.1, GET /.env.local HTTP/1.1, GET /.env HTTP/1.1, POST / HTTP/1.1, GET /.env.production HTTP/1.1, GET / HTTP/1.1, GET /.env.development HTTP/1.1, GET /.git/config HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 06:26:33
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.55.89 (89.55.97.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.55.89 (89.55.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 02:26:26.673541 2026] [security2:error] [pid 11036:tid 11036] [client 34.97.55.89:47320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ampstudio.infinite-e.com"] [uri "/.git/config"] [unique_id "apfBkpT43IcRXwhBveeRMQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
XICTRON
2026-09-02 05:05:06
(11 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
Anonymous
2026-09-02 04:56:51
(11 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.97.55.89 (JP/Japan/89.55.97.34.bc.go ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.97.55.89 (JP/Japan/89.55.97.34.bc.googleusercontent.com)
show less
SQL Injection
๐ซ๐ท
masterguru
2026-09-02 04:29:45
(12 hours ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-02 01:08:58
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.55.89 (89.55.97.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.55.89 (89.55.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 21:08:53.331498 2026] [security2:error] [pid 1042456:tid 1042464] [client 34.97.55.89:48344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ammisr.com.oplconnect.com"] [uri "/.git/config"] [unique_id "apd3JZHZ0DOpF4nuszEKiwAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-02 00:56:10
(15 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+1 more) | 2026-09-02 00:56 UTC
show less
Hacking
Web App Attack