🇺🇸
TPI-Abuse
2026-09-11 10:33:40
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.141.28 (28.141.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.141.28 (28.141.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 06:33:37.115047 2026] [security2:error] [pid 5903:tid 5903] [client 34.145.141.28:59552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3dworld-wide.com"] [uri "/.git/config"] [unique_id "aqPZAZEg8citqeZxl8vufAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
ecode hosting
2026-09-11 10:18:04
(17 hours ago)
Domain : 3dteknoloji.com.tr
Rule : env
2026-09-11 10:15:46 10.100.1.20 GET /.env.production - 443 - ...
show more
Domain : 3dteknoloji.com.tr
Rule : env
2026-09-11 10:15:46 10.100.1.20 GET /.env.production - 443 - 34.145.141.28 HTTP/1.1 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 - 3dteknoloji.com.tr 404 0 0 1896 359 2952 - -
show less
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-11 10:07:52
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.141.28 (28.141.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.141.28 (28.141.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 06:07:44.850359 2026] [security2:error] [pid 23517:tid 23517] [client 34.145.141.28:55824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3dsportschannel.com"] [uri "/.git/config"] [unique_id "aqPS8DRdU92CSLGkp-aHTQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 09:32:28
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.141.28 (28.141.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.141.28 (28.141.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 05:32:22.475846 2026] [security2:error] [pid 15365:tid 15365] [client 34.145.141.28:44986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3dprinting.raynernet.com"] [uri "/.git/config"] [unique_id "aqPKpnc_TSfugP8gz1zU8gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Zundapper
2026-09-11 09:00:45
(18 hours ago)
34.145.141.28 - - [11/Sep/2026:11:00:42 +0200] "GET /phpinfo HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Win ...
show more
34.145.141.28 - - [11/Sep/2026:11:00:42 +0200] "GET /phpinfo HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.145.141.28 - - [11/Sep/2026:11:00:43 +0200] "GET /info HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.145.141.28 - - [11/Sep/2026:11:00:44 +0200] "GET /_profiler/phpinfo HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.145.141.28 - - [11/Sep/2026:11:00:44 +0200] "GET /_environment HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.145.141.28 - - [11/Sep/2026:11:00:44 +0200] "GET /webroot/index.php/_environment HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0
...
show less
Web App Attack
Port Scan
🇺🇸
TPI-Abuse
2026-09-11 07:25:03
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.145.141.28 (28.141.145.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.145.141.28 (28.141.145.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 03:24:55.358068 2026] [security2:error] [pid 5542:tid 5583] [client 34.145.141.28:46776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3dfilament.com"] [uri "/.git/config"] [unique_id "aqOsx9Qu3Ff9ZK7A7tqLLQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
dtorrer
2026-09-11 07:03:00
(20 hours ago)
General vulnerability scan.
Port Scan
🇩🇪
itsolon
2026-09-11 06:05:18
(21 hours ago)
[11/Sep/2026:08:05:16 +0200] 178910671652.146076 34.145.141.28 0 217.154.7.177 443
[11/Sep/2026:08:0 ...
show more
[11/Sep/2026:08:05:16 +0200] 178910671652.146076 34.145.141.28 0 217.154.7.177 443
[11/Sep/2026:08:05:16 +0200] 178910671631.367844 34.145.141.28 0 217.154.7.177 443
[11/Sep/2026:08:05:17 +0200] 178910671729.064892 34.145.141.28 0 217.154.7.177 443
[11/Sep/2026:08:05:17 +0200] 178910671752.239175 34.145.141.28 0 217.154.7.177 443
[11/Sep/2026:08:05:18 +0200] 178910671838.316611 34.145.141.28 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-11 03:51:00
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-11 02:45:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇫🇷
Octopuce
2026-09-10 21:34:13
(1 day ago)
Aggressive web search of vulnerable pages: /.env /.env.local /.env.production /.env.staging /.env.de ...
show more
Aggressive web search of vulnerable pages: /.env /.env.local /.env.production /.env.staging /.env.development /.env.test /.env.remote /.env.bak ...
show less
Web App Attack
🇺🇸
WellSpring
2026-09-10 20:31:41
(1 day ago)
env leak on 252.today/public/.env — WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack