🇺🇸
TPI-Abuse
2026-09-04 21:46:20
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.31.209 (209.31.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.31.209 (209.31.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:46:14.520952 2026] [security2:error] [pid 31737:tid 31737] [client 34.158.31.209:36042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.hillsperth.com"] [uri "/html/.git/config"] [unique_id "aps8JlIj8kw9Q7jAIYcDGQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-04 21:43:31
(3 hours ago)
Multiple WAF Violations
Web App Attack
🇲🇾
Rizzy
2026-09-04 21:41:17
(3 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇮🇹
CoreTech srl
2026-09-04 20:08:56
(5 hours ago)
cloudlinux2 fail2ban: 2026-09-04 22:04:43,352 fail2ban.filter [1594]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-04 22:04:43,352 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 155.2.215.108 - 2026-09-04 22:04:42cloudlinux2 fail2ban: 2026-09-04 22:06:16,034 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.158.31.209 - 2026-09-04 22:06:16cloudlinux2 fail2ban: 2026-09-04 22:06:16,053 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.158.31.209 - 2026-09-04 22:06:16cloudlinux2 fail2ban: 2026-09-04 22:06:16,045 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.158.31.209 - 2026-09-04 22:06:16cloudlinux2 fail2ban: 2026-09-04 22:06:16,118 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.158.31.209 - 2026-09-04 22:06:16cloudlinux2 fail2ban: 2026-09-04 22:06:16,570 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Ban 34.158.31.209cloudlinux2 fail2ban: 2026-09-04 22:06:16,062 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 34.158.31.209 - 2026-09-04 22:06:16cloudlinux2 fail2ban:
show less
Web App Attack
Anonymous
2026-09-04 18:40:05
(6 hours ago)
GET /var/www/.git/config HTTP/1.1
...
Web App Attack
🇸🇪
SkyDancer
2026-09-04 17:27:15
(7 hours ago)
Multiple login attempts via RDP and/or SSH using wrong credentials. Attack automatically blocked by ...
show more
Multiple login attempts via RDP and/or SSH using wrong credentials. Attack automatically blocked by SkyDancer Ai via interface.
show less
Hacking
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-04 15:58:26
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.31.209 (209.31.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.31.209 (209.31.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:58:22.990581 2026] [security2:error] [pid 32739:tid 32739] [client 34.158.31.209:60218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nagareinkpaper.es"] [uri "/wordpress/.git/config"] [unique_id "aprqnvAf266X_xFhd8sEFwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-04 14:12:00
(11 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇸🇪
SkyDancer
2026-09-04 11:44:07
(13 hours ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
🇳🇱
MyGlobalFlowers
2026-09-04 10:28:40
(14 hours ago)
Multiple WAF Violations
Web App Attack
🇳🇱
e.fierstra
2026-09-04 09:55:04
(15 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-04 09:15:49
(16 hours ago)
34.158.31.209 - - [04/Sep/2026:05:15:49 -0400] "GET /.git/config HTTP/1.1" 404 6026 "-" "crusader-wo ...
show more
34.158.31.209 - - [04/Sep/2026:05:15:49 -0400] "GET /.git/config HTTP/1.1" 404 6026 "-" "crusader-worker/1.0"
34.158.31.209 - - [04/Sep/2026:05:15:49 -0400] "GET /html/.git/config HTTP/1.1" 404 6026 "-" "crusader-worker/1.0"
34.158.31.209 - - [04/Sep/2026:05:15:49 -0400] "GET /htdocs/.git/config HTTP/1.1" 404 6026 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:29:18
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.31.209 (209.31.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.31.209 (209.31.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:29:12.558166 2026] [security2:error] [pid 7590:tid 7599] [client 34.158.31.209:48374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.aisapy.com"] [uri "/api/.git/config"] [unique_id "appXKBHAoQGRWaCyWYV4IQAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
openstrike.co.uk
2026-09-04 05:13:52
(20 hours ago)
12 attacks on VC URLs:
GET /htdocs/.git/config HTTP/1.1
Hacking
🇺🇸
TPI-Abuse
2026-09-04 04:56:39
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.31.209 (209.31.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.31.209 (209.31.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:56:32.975869 2026] [security2:error] [pid 11261:tid 11261] [client 34.158.31.209:40174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.chadfishman.com"] [uri "/wordpress/.git/config"] [unique_id "appPgPdfsw8FKKHRhVHVngAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack