๐บ๐ธ
TPI-Abuse
2026-09-20 11:06:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.131.126.148 (148.126.131.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.126.148 (148.126.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 07:06:32.434723 2026] [security2:error] [pid 16567:tid 16567] [client 34.131.126.148:48076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "4211swf.com.micahgartman.com"] [uri "/.git/config"] [unique_id "aq--OHXHLU3XXoODfuj7RwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 09:08:05
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.131.126.148 (148.126.131.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.126.148 (148.126.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 05:07:57.435858 2026] [security2:error] [pid 13706:tid 13770] [client 34.131.126.148:45816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "41bravo.com"] [uri "/.git/config"] [unique_id "aq-ibcoNeOAeHc5VrF277wAAAZU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 15:40:00
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.131.126.148 (148.126.131.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.126.148 (148.126.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 11:39:55.182001 2026] [security2:error] [pid 6069:tid 6069] [client 34.131.126.148:51036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.abdulhameeds.art"] [uri "/.git/config"] [unique_id "aq6sy8ecvb5ekTdVDvkZ_wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-19 14:30:50
(3 days ago)
Malware host detected by rbl.malware.expert. RBL lookup of 148.126.131.34.rbl.malware.expert succeed ...
show more
Malware host detected by rbl.malware.expert. RBL lookup of 148.126.131.34.rbl.malware.expert succeeded at REMOTE_ADDR. (400010-stl2-14)
show less
Hacking
๐ฆ๐บ
rubixstudios
2026-09-19 12:15:03
(3 days ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 10:29:13
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.131.126.148 (148.126.131.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.126.148 (148.126.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 06:29:09.893452 2026] [security2:error] [pid 19984:tid 19984] [client 34.131.126.148:59268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "20dekopas.com"] [uri "/.git/config"] [unique_id "aq0SdUZKEj1hnBq4JThbQwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WellSpring
2026-09-18 07:03:31
(4 days ago)
env leak on 208.today/site/.env โ WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
Anonymous
2026-09-17 04:51:47
(6 days ago)
Vulnerability scan
Web App Attack
๐ซ๐ท
masterguru
2026-09-17 04:47:03
(6 days ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
Anonymous
2026-09-17 04:17:52
(6 days ago)
Automated report from fail2ban.
Detected: automated probing for vulnerable/administrative endpoints ...
show more
Automated report from fail2ban.
Detected: automated probing for vulnerable/administrative endpoints (e.g. wp-login.php, phpMyAdmin) consistent with bot scanning.
Jail: nginx-botsearch
Failed attempts recorded: 2
Report time: 2026-09-17 04:17:52 UTC
This IP has been automatically and permanently blocked at our network perimeter.
Evidence (most recent matched log lines, redacted):
$f2bV_matches
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 04:03:00
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.131.126.148 (148.126.131.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.126.148 (148.126.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 00:02:53.097242 2026] [security2:error] [pid 8098:tid 8098] [client 34.131.126.148:48934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "constructiondomex.com"] [uri "/.git/config"] [unique_id "aqtmbQCh4nQri_OI8JaV9wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 03:38:42
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.131.126.148 (148.126.131.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.126.148 (148.126.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 23:38:37.126609 2026] [security2:error] [pid 5397:tid 5397] [client 34.131.126.148:56712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "constantrose.clayrivers.com"] [uri "/.git/config"] [unique_id "aqtgvSQztsHvOCpQ_GJKKQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-17 03:30:09
(6 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 03:20:28
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.131.126.148 (148.126.131.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.126.148 (148.126.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 23:20:24.727495 2026] [security2:error] [pid 31524:tid 31524] [client 34.131.126.148:56288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "consolidatedoperationsgroup.com"] [uri "/.git/config"] [unique_id "aqtceH0oqXom-x5XxwAbuwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-15 20:03:34
(1 week ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack