๐บ๐ธ
TPI-Abuse
2026-09-26 15:35:42
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.159.83.153 (153.83.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.83.153 (153.83.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:35:36.778764 2026] [security2:error] [pid 13282:tid 13282] [client 34.159.83.153:46072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "baptismnapkins.com"] [uri "/.git/config"] [unique_id "arfmSGBNenVcub7NWCUCUwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-09-25 17:04:22
(1 day ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.159.83. ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 34.159.83.153 (DE/Germany/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 34.159.83.153 (DE/Germany/153.83.159.34.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 19:19:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.159.83.153 (153.83.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.83.153 (153.83.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 15:19:27.920725 2026] [security2:error] [pid 2184:tid 2184] [client 34.159.83.153:43838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.difusionens.org"] [uri "/.git/config"] [unique_id "arV3v983VuhW7kDV3HDm5gAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
chrisj
2026-09-24 18:34:27
(2 days ago)
[Thu Sep 24 18:34:26.259505 2026] [proxy_fcgi:error] [pid 160555:tid 160643] [client 34.159.83.153:6 ...
show more
[Thu Sep 24 18:34:26.259505 2026] [proxy_fcgi:error] [pid 160555:tid 160643] [client 34.159.83.153:60626] AH01071: Got error 'Primary script unknown'
[Thu Sep 24 18:34:26.362048 2026] [proxy_fcgi:error] [pid 160555:tid 160618] [client 34.159.83.153:60626] AH01071: Got error 'Primary script unknown'
[Thu Sep 24 18:34:26.464281 2026] [proxy_fcgi:error] [pid 160555:tid 160613] [client 34.159.83.153:60626] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐ฉ๐ช
XICTRON
2026-09-24 15:35:05
(2 days ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐ฉ๐ช
gadix
2026-09-24 14:08:34
(2 days ago)
[24/Sep/2026:16:08:29.548792 +0200] arUu3SxxJUcgB3zDELs0_AAAABM 34.159.83.153 47228 127.0.0.1 7081
[ ...
show more
[24/Sep/2026:16:08:29.548792 +0200] arUu3SxxJUcgB3zDELs0_AAAABM 34.159.83.153 47228 127.0.0.1 7081
[24/Sep/2026:16:08:29.591811 +0200] arUu3SxxJUcgB3zDELs0_QAAAAs 34.159.83.153 47236 127.0.0.1 7081
[2
...
show less
Web App Attack
๐ท๐ด
clauss
2026-09-21 14:28:16
(5 days ago)
34.159.83.153 - - [21/Sep/2026:17:28:15 +0300] "GET /.git/config HTTP/1.1" 403 177 "-" "Mozilla/5.0 ...
show more
34.159.83.153 - - [21/Sep/2026:17:28:15 +0300] "GET /.git/config HTTP/1.1" 403 177 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.159.83.153 - - [21/Sep/2026:17:28:15 +0300] "GET /.env.local HTTP/1.1" 403 177 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-21 14:10:30
(5 days ago)
34.159.83.153 - - [21/Sep/2026:14:09:58 +0000] "POST / HTTP/1.1" 403 16594 "-" "Mozilla/5.0 (Windows ...
show more
34.159.83.153 - - [21/Sep/2026:14:09:58 +0000] "POST / HTTP/1.1" 403 16594 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.159.83.153"
34.159.83.153 - - [21/Sep/2026:14:09:58 +0000] "POST / HTTP/1.1" 403 16594 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.159.83.153"
34.159.83.153 - - [21/Sep/2026:14:09:59 +0000] "GET /.git/config HTTP/1.1" 403 12486 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.159.83.153"
34.159.83.153 - - [21/Sep/2026:14:09:59 +0000] "GET /.env HTTP/1.1" 403 12482 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.159.83.153"
34.159.83.153 - - [21/Sep/2026:14:09:59 +0000] "GET /.env.local HTTP/1.1" 403 12484 "-" "Mozilla/5.0 (Windows NT 10
...
show less
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 11:55:03
(5 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-21 10:00:01
(5 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ซ๐ท
RodGel
2026-09-21 07:48:48
(5 days ago)
Multiple 404 errors (Potential brute force attempt)
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-20 18:11:16
(6 days ago)
20 attempts against mh-misbehave-ban on solar
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 17:42:48
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.159.83.153 (153.83.159.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.159.83.153 (153.83.159.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 13:42:43.738914 2026] [security2:error] [pid 8717:tid 8717] [client 34.159.83.153:34302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "m2oblivion.com"] [uri "/.git/config"] [unique_id "arAbE9njkKCUNch3bd3BWQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack