πΊπΈ
TPI-Abuse
2026-09-15 05:54:05
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.142.161.185 (185.161.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.161.185 (185.161.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 01:54:00.313407 2026] [security2:error] [pid 8237:tid 8237] [client 34.142.161.185:42052] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agkgt.org"] [uri "/.git/config"] [unique_id "aqjdePpGkUtj-QtT31FxAwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
debestelapp
2026-09-15 05:35:11
(4 days ago)
Web App Attack
π©πͺ
SΓ©fora Srl
2026-09-15 05:28:58
(4 days ago)
crowdsecurity/http-sensitive-files detected by CrowdSec
Web App Attack
π©πͺ
LRob
2026-09-15 05:04:10
(4 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-15 05:04 UTC
show less
Hacking
Web App Attack
Anonymous
2026-09-15 03:15:02
(4 days ago)
suspicious request in access.log
Web App Attack
πͺπΈ
pipeline.es
2026-09-15 03:06:59
(4 days ago)
Web scanning / probing for vulnerable paths | URL: /.env.old | Evidence: agilityturismo.com.br 34.14 ...
show more
Web scanning / probing for vulnerable paths | URL: /.env.old | Evidence: agilityturismo.com.br 34.142.161.185 - - [15/Sep/2026:05:06:39 +0200] \"GET /.env.old HTTP/1.1\" 404 19438 \"-\" \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=SG | ASN: GOOGLE-CLOUD-PLATFORM | Country: SG
show less
Port Scan
Web App Attack
π¦πΊ
rubixstudios
2026-09-15 01:58:02
(4 days ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
π³π±
Site.eu
2026-09-15 01:51:07
(4 days ago)
Excessive multi-domain requests
Brute-Force
π¨π
backslash
2026-09-15 00:48:04
(4 days ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
π©πͺ
snhosting
2026-09-14 23:34:16
(4 days ago)
34.142.161.185 - - [15/Sep/2026:01:34:06 +0200] "GET /.git/config HTTP/1.1" 200 1628 "-" "Mozilla/5. ...
show more
34.142.161.185 - - [15/Sep/2026:01:34:06 +0200] "GET /.git/config HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.142.161.185 - - [15/Sep/2026:01:34:06 +0200] "GET /.env HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.142.161.185 - - [15/Sep/2026:01:34:06 +0200] "GET /.env.local HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.142.161.185 - - [15/Sep/2026:01:34:07 +0200] "GET /.env.production HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.142.161.185 - - [15/Sep/2026:01:34:07 +0200] "GET /.env.staging HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, li
...
show less
DNS Compromise
DNS Poisoning
Phishing
Email Spam
Brute-Force
Web App Attack
SSH
πΊπΈ
Lee Daniel
2026-09-14 17:35:00
(4 days ago)
34.142.161.185 - - [14/Sep/2026:13:35:00 -0400] "GET /.env HTTP/1.1" 403 6288 "-" "Mozilla/5.0 (X11; ...
show more
34.142.161.185 - - [14/Sep/2026:13:35:00 -0400] "GET /.env HTTP/1.1" 403 6288 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-09-14 14:07:02
(4 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
πΈπͺ
vaia.cloud
2026-09-13 15:20:02
(5 days ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
Anonymous
2026-09-12 09:20:54
(6 days ago)
GET / HTTP/1.1
POST / HTTP/1.1
POST / HTTP/1.1
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-12 04:49:31
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.142.161.185 (185.161.142.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.142.161.185 (185.161.142.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 00:49:20.404003 2026] [security2:error] [pid 1804:tid 1804] [client 34.142.161.185:41024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "4211swf.com.micahgartman.com"] [uri "/.git/config"] [unique_id "aqTZ0D2gU5l5a9lt0lQ7IwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack