🇳🇱
Savvii
2026-09-04 22:50:54
(2 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:56:29
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.1.43 (43.1.138.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.1.43 (43.1.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:56:26.138682 2026] [security2:error] [pid 26651:tid 26651] [client 34.138.1.43:56784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.unaweep.com"] [uri "/site/.git/config"] [unique_id "aps-ijguSHAwoKy8sNUNewAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:40:38
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.1.43 (43.1.138.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.1.43 (43.1.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:40:30.391260 2026] [security2:error] [pid 28706:tid 28706] [client 34.138.1.43:51798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.modernsalessolutions.com"] [uri "/var/www/.git/config"] [unique_id "aps6zm80q6jDGVdi9pAoqgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 21:37:18
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 21:24:26
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇨🇭
Origon
2026-09-04 21:18:01
(4 hours ago)
http-sensitive-files - IP: 34.138.1.43 - time="2026-09-04T23:18:00+02:00" level=info msg="(555f66b4 ...
show more
http-sensitive-files - IP: 34.138.1.43 - time="2026-09-04T23:18:00+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 34.138.1.43 (US/396982) : 4h ban on Ip 34.138.1.43" module=db
show less
Web App Attack
🇩🇪
FD-IX
2026-09-04 21:04:42
(4 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:00:07
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.1.43 (43.1.138.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.1.43 (43.1.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 16:59:56.860378 2026] [security2:error] [pid 13757:tid 13757] [client 34.138.1.43:37634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dreamhome.dhappraisalservices.com"] [uri "/www/.git/config"] [unique_id "apsxTKcf0h8C35c7LHU22gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
Antinson
2026-09-04 19:27:21
(5 hours ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 15:46:47
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.1.43 (43.1.138.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.1.43 (43.1.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:46:44.387357 2026] [security2:error] [pid 28728:tid 28728] [client 34.138.1.43:60170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.leonardodecaprio.com"] [uri "/app/.git/config"] [unique_id "aprn5KUp69pDiTfiy0sLPwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
NewWavesApp
2026-09-04 14:04:07
(11 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.138.1.43 (US/United States/43.1.138. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.138.1.43 (US/United States/43.1.138.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
🇧🇪
cmbplf
2026-09-04 05:44:09
(19 hours ago)
168 requests with url.path *.git/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 05:28:11
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.1.43 (43.1.138.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.1.43 (43.1.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:28:04.498851 2026] [security2:error] [pid 8797:tid 8797] [client 34.138.1.43:53868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.advantstudio.com"] [uri "/var/www/.git/config"] [unique_id "appW5BSUsXI8COZG_B8klgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:28:08
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.138.1.43 (43.1.138.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.138.1.43 (43.1.138.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:28:03.595042 2026] [security2:error] [pid 16055:tid 16055] [client 34.138.1.43:47698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.eaglesnestfuelfarm.com"] [uri "/.git/config"] [unique_id "appI0xzZt3EMFYMwZxi2kwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 04:20:37
(20 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking