🇺🇸
TPI-Abuse
2026-09-04 21:04:18
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.128.125.82 (82.125.128.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.125.82 (82.125.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:04:12.470631 2026] [security2:error] [pid 3843083:tid 3843108] [client 34.128.125.82:38572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.evolutionaryethics.com"] [uri "/wordpress/.git/config"] [unique_id "apsyTDPuTRZCQ4WD1tNccwAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-04 21:01:41
(5 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 19:18:26
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.128.125.82 (82.125.128.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.125.82 (82.125.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 15:18:21.194672 2026] [security2:error] [pid 17066:tid 17066] [client 34.128.125.82:52508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "teapartynapkins.com"] [uri "/.git/config"] [unique_id "apsZfWhu0HG40mZyuuIQYwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
clamehost.it
2026-09-04 19:13:27
(7 hours ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 18:46:50
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇵🇱
Budyn
2026-09-04 14:29:18
(12 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: ts3mb.budyn.wtf | URI: /backend/.git/config | UA: crusader-worker/1.0 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
Anonymous
2026-09-04 11:10:39
(15 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 10:57:00
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.128.125.82 (82.125.128.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.125.82 (82.125.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:56:56.458812 2026] [security2:error] [pid 3886:tid 3886] [client 34.128.125.82:54974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "internationalavionics.com"] [uri "/site/.git/config"] [unique_id "apqj-LJXOusc7sJ1DjjIEQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇬
HighWay
2026-09-04 08:27:22
(18 hours ago)
34.128.125.82 - - [04/Sep/2026:08:27:16 +0000] "GET /www/.git/config HTTP/1.1" 403 5515 "-" "crusade ...
show more
34.128.125.82 - - [04/Sep/2026:08:27:16 +0000] "GET /www/.git/config HTTP/1.1" 403 5515 "-" "crusader-worker/1.0"
34.128.125.82 - - [04/Sep/2026:08:27:16 +0000] "GET /api/.git/config HTTP/1.1" 403 5515 "-" "crusader-worker/1.0"
34.128.125.82 - - [04/Sep/2026:08:27:16 +0000] "GET /var/www/.git/config HTTP/1.1" 403 5515 "-" "crusader-worker/1.0"
...
show less
Port Scan
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:00:44
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.128.125.82 (82.125.128.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.125.82 (82.125.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:00:39.551297 2026] [security2:error] [pid 29237:tid 29237] [client 34.128.125.82:40214] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hcadwin.com"] [uri "/site/.git/config"] [unique_id "appCZwFqPtLm-k66zRigLAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack