๐บ๐ธ
TPI-Abuse
2026-09-29 20:11:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.128.88.59 (59.88.128.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.88.59 (59.88.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:11:43.038097 2026] [security2:error] [pid 15002:tid 15002] [client 34.128.88.59:50142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.boat-registration-turkey.com.boatregistrationdelaware.com"] [uri "/.git/config"] [unique_id "arwbf8Qd-cWdSC_w346IXwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-28 12:10:49
(2 days ago)
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-10al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.128.88.59 - - [28/Sep/2026:14:10:31 +0200] "GET /.git/config HTTP/1.1" 404 2105 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-28 09:42:15
(2 days ago)
csagent: score 20.1: secrets grab x2, 404 noise floor x1; 1 domain(s) in 5s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 08:36:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.128.88.59 (59.88.128.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.88.59 (59.88.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 04:35:56.756441 2026] [security2:error] [pid 8640:tid 8673] [client 34.128.88.59:36232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.workingwithseniors.richardleeweatherman.com"] [uri "/.git/config"] [unique_id "arom7Et6UNlo_oAjhkLvPAAAAQM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 06:34:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.128.88.59 (59.88.128.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.88.59 (59.88.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 02:34:37.084834 2026] [security2:error] [pid 20713:tid 20713] [client 34.128.88.59:46302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.workequity.kporterdesign.com"] [uri "/.git/config"] [unique_id "aroKfc_HwyHJGtfQl5ZLuQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 06:07:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.128.88.59 (59.88.128.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.88.59 (59.88.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 02:07:23.896062 2026] [security2:error] [pid 23051:tid 23124] [client 34.128.88.59:36832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.workbykathryn.workconfident.com"] [uri "/.git/config"] [unique_id "aroEG6Z05VMFjhpBKpKHeAAAARY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 03:52:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.128.88.59 (59.88.128.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.88.59 (59.88.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 23:52:55.040615 2026] [security2:error] [pid 24109:tid 24109] [client 34.128.88.59:58020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.words.gmacguffin.com"] [uri "/.git/config"] [unique_id "arnkl5jnoYS_Hka4SZkyWAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
maxxsense
2026-09-27 18:49:47
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.128.88.59 (ID/Indonesia/59.88.128.34 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.128.88.59 (ID/Indonesia/59.88.128.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-27 18:35:54
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.128.88.59 (59.88.128.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.88.59 (59.88.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 14:35:48.153219 2026] [security2:error] [pid 513:tid 513] [client 34.128.88.59:49096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.welleracore.com.darkcodedesign.net"] [uri "/.git/config"] [unique_id "arliBLDRG7MKh1JRb3P3DQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-27 17:14:13
(3 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
ne1for23
2026-09-27 17:02:31
(3 days ago)
Attempting to probe for sensitive information accidently exposed via git config.
34.128.88.59 - - [ ...
show more
Attempting to probe for sensitive information accidently exposed via git config.
34.128.88.59 - - [27/Sep/2026:17:02:30 +0000] "GET /.git/config HTTP/1.1" 403 555 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-27 00:22:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.128.88.59 (59.88.128.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.88.59 (59.88.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 20:22:12.755453 2026] [security2:error] [pid 28348:tid 28348] [client 34.128.88.59:57044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wendeeholtcamp.wendeenicole.com"] [uri "/.git/config"] [unique_id "arhhtAQKuoon42qIosRshgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-26 22:42:30
(3 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 20:36:27
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.128.88.59 (59.88.128.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.128.88.59 (59.88.128.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 16:36:23.990015 2026] [security2:error] [pid 30369:tid 30369] [client 34.128.88.59:34186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.lowkeytiki.com"] [uri "/.git/config"] [unique_id "argsx9d7ysf0-d2mnnCrkQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-26 15:55:02
(4 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack