๐จ๐ญ
Peter-Johann Sarbach
2026-09-25 23:33:39
(8 hours ago)
Hacking website
Hacking
๐ฉ๐ช
filstal.org
2026-09-25 23:08:37
(8 hours ago)
Automated bot: spoofed/impossible user-agent, web scraping or automated request patterns detected. U ...
show more
Automated bot: spoofed/impossible user-agent, web scraping or automated request patterns detected. UA:
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
ut-addicted.com
2026-09-25 23:08:09
(8 hours ago)
\[Sat Sep 26 01:08:07.746772 2026\] \[:error\] \[pid 23276:tid 140352566568704\] \[client 35.231.34. ...
show more
\[Sat Sep 26 01:08:07.746772 2026\] \[:error\] \[pid 23276:tid 140352566568704\] \[client 35.231.34.37:54130\] \[client 35.231.34.37\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 5\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "mail.ut-addicted.com"\] \[uri "/.git/config"\] \[unique_id "arb@1-7f5lhZLw4YmXXXzgAAAQY"\]
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 22:48:18
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.231.34.37 (37.34.231.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.34.37 (37.34.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 18:48:12.274466 2026] [security2:error] [pid 10160:tid 10160] [client 35.231.34.37:42852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.undergroundh2o.com"] [uri "/.git/config"] [unique_id "arb6LMVcHUHq-yK3uCSCDgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
UMP-PL
2026-09-25 22:46:37
(8 hours ago)
Webserver scan (backups, phpadmin, etc.)
Web App Attack
Anonymous
2026-09-25 22:44:20
(8 hours ago)
sensitive path probe detected by fail2ban
...
Port Scan
Web App Attack
๐ฉ๐ช
sternwart
2026-09-25 22:43:27
(8 hours ago)
Automatisch erkannt: Zugriff auf /.git/config (3d.alpasana.ch)
Web App Attack
Bad Web Bot
Anonymous
2026-09-25 22:05:08
(9 hours ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐ซ๐ท
dynamix
2026-09-25 21:57:35
(9 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 21:44:52
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.231.34.37 (37.34.231.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.34.37 (37.34.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 17:44:45.284844 2026] [security2:error] [pid 22882:tid 22882] [client 35.231.34.37:58434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.totaleventsandtents.com"] [uri "/.git/config"] [unique_id "arbrTUjGQNVBp9xkCLajpgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-25 21:41:57
(9 hours ago)
35.231.34.37 - - [25/Sep/2026:18:41:56 -0300] "GET /.git/config HTTP/1.1" 403 118 "-" "-"
...
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-09-25 21:23:15
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.231.34.37 (37.34.231.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.34.37 (37.34.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 17:23:13.108313 2026] [security2:error] [pid 2090:tid 2090] [client 35.231.34.37:35788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.titicacacatamarans.com"] [uri "/.git/config"] [unique_id "arbmQTvstL4LQhQlgf_7rgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Lino Project
2026-09-25 21:21:41
(10 hours ago)
35.231.34.37 - - [25/Sep/2026:23:21:40 +0200] "GET /.git/config HTTP/1.1" 403 5252 "-" "-"
...
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-25 21:17:08
(10 hours ago)
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35. ...
show more
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35.231.34.37 - - \[25/Sep/2026:23:17:01 +0200\] "GET /.git/config HTTP/1.1" 404 5823 "-" "-"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 21:07:08
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.231.34.37 (37.34.231.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.231.34.37 (37.34.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 17:07:05.443404 2026] [security2:error] [pid 31936:tid 31936] [client 35.231.34.37:52074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.thn.bz"] [uri "/.git/config"] [unique_id "arbieanLkQzFUNIIYoi-QQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack