๐บ๐ธ
TPI-Abuse
2026-09-16 07:50:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.154.86.134 (134.86.154.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.86.134 (134.86.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 03:50:16.075971 2026] [security2:error] [pid 15976:tid 15976] [client 34.154.86.134:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.empoweruamerica.org"] [uri "/.git/config"] [unique_id "aqpKOEmURcAgpoSO_CqtegAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
pm33
2026-09-16 02:26:45
(1 day ago)
Probing for resource vulnerabilities HTTP(S)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:45:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.154.86.134 (134.86.154.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.86.134 (134.86.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:45:25.213893 2026] [security2:error] [pid 11507:tid 11507] [client 34.154.86.134:51946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.darkcodedesign.net"] [uri "/.git/config"] [unique_id "aqn0tfHLbxt7YhQrylud7QAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:52:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.154.86.134 (134.86.154.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.86.134 (134.86.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:52:20.883374 2026] [security2:error] [pid 6233:tid 6233] [client 34.154.86.134:49008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.boulevardflowergardens.com"] [uri "/.git/config"] [unique_id "aqm-FF2y3Csl2dtX1MAB6gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 18:59:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.154.86.134 (134.86.154.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.86.134 (134.86.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:59:24.121830 2026] [security2:error] [pid 19081:tid 19081] [client 34.154.86.134:52970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.bnaior.org"] [uri "/.git/config"] [unique_id "aqmVjPkoYABbsBDzkuam1gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Blexyel
2026-09-15 18:39:14
(1 day ago)
34.154.86.134 - - [15/Sep/2026:20:39:14 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 ...
show more
34.154.86.134 - - [15/Sep/2026:20:39:14 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
Anonymous
2026-09-15 14:30:45
(2 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
WellSpring
2026-09-15 13:03:47
(2 days ago)
env leak on wellspr.ing/backend/.env โ WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-15 11:29:24
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-15 09:20:18
(2 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
netman
2026-09-15 09:16:34
(2 days ago)
HTTP: 34.154.86.134 blocked because of 100 failures
...
DDoS Attack
Web App Attack
๐ซ๐ท
baphomet
2026-09-15 07:47:11
(2 days ago)
Probed planted web canary URI (not a real app path).
HTTP request completed against planted URIs (.e ...
show more
Probed planted web canary URI (not a real app path).
HTTP request completed against planted URIs (.env/wp-login/xmlrpc/phpmyadmin/.git).
jail=nginx-canary proto=tcp port=80,443 failures>=2 class=web-app-probe
these paths are not real apps on this host; hit is hostile recon
when=2026-09-15T07:47:11Z sensor=fail2ban role=web-canary
src=34.154.86.134
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 04:24:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.154.86.134 (134.86.154.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.154.86.134 (134.86.154.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 00:24:29.186448 2026] [security2:error] [pid 30801:tid 30808] [client 34.154.86.134:39770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yourwitch.com"] [uri "/.git/config"] [unique_id "aqjIfQjTh_HagT-KXn1r8QAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack