🇺🇸
TPI-Abuse
2026-09-11 12:33:36
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.116.21 (21.116.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.116.21 (21.116.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 08:33:32.275163 2026] [security2:error] [pid 18125:tid 18125] [client 34.17.116.21:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.distro.media"] [uri "/.git/config"] [unique_id "aqP1HOMHZZ_NlDCBU-wtWQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-11 12:23:57
(15 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.17.116.21 (IT/Italy/21.116.17.34.bc.googleus ...
show more
(mod_security) mod_security (id:949110) triggered by 34.17.116.21 (IT/Italy/21.116.17.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 11:15:56
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.116.21 (21.116.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.116.21 (21.116.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 07:15:51.117941 2026] [security2:error] [pid 3694:tid 3694] [client 34.17.116.21:56586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.diarrheawolves.com"] [uri "/.git/config"] [unique_id "aqPi5znQFiW9-yvCmH0kAwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 10:02:29
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.116.21 (21.116.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.116.21 (21.116.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 06:02:25.174302 2026] [security2:error] [pid 1818796:tid 1819614] [client 34.17.116.21:56224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.destination-kitchen.com"] [uri "/.git/config"] [unique_id "aqPRsRjxZJ4jL5ekSswruwAAAU8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 09:21:32
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.116.21 (21.116.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.116.21 (21.116.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 05:21:27.732678 2026] [security2:error] [pid 4545:tid 4545] [client 34.17.116.21:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dentguyvt.com"] [uri "/.git/config"] [unique_id "aqPIF1gx3CNUeucoYxeaXAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-11 07:15:40
(20 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 1s
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 07:09:09
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.116.21 (21.116.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.116.21 (21.116.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 03:09:03.520922 2026] [security2:error] [pid 29933:tid 29933] [client 34.17.116.21:51482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.davidsonmanagement.net"] [uri "/.git/config"] [unique_id "aqOpD4BW2olYjth6EgCG8QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
pipeline.es
2026-09-10 14:38:13
(1 day ago)
Web scanning / probing for vulnerable paths
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 10:19:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.17.116.21 (21.116.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.116.21 (21.116.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 06:19:55.341628 2026] [security2:error] [pid 26866:tid 26866] [client 34.17.116.21:34638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davedoeswater.com"] [uri "/.git/config"] [unique_id "aqKES2X2J6lB57QEX4tnFwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
pipeline.es
2026-09-10 09:52:13
(1 day ago)
Web scanning / probing for vulnerable paths | URL: /frontend/.env | Evidence: davantitravel.pt 34.17 ...
show more
Web scanning / probing for vulnerable paths | URL: /frontend/.env | Evidence: davantitravel.pt 34.17.116.21 - - [10/Sep/2026:11:51:43 +0200] \"GET /frontend/.env HTTP/1.1\" 404 21011 \"-\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=IT | ASN: GOOGLE-CLOUD-PLATFORM | Country: IT
show less
Port Scan
Web App Attack
🇩🇪
tg_de
2026-09-10 09:44:57
(1 day ago)
554 attempts since 10.09.2026 11:28:27 CEST - last search for: /
Web App Attack
🇩🇪
McClay
2026-09-10 09:43:24
(1 day ago)
Illegal access attempt:34.17.116.21 - - [10/Sep/2026:11:43:23 +0200] "GET /.git/config HTTP/1.1" 404 ...
show more
Illegal access attempt:34.17.116.21 - - [10/Sep/2026:11:43:23 +0200] "GET /.git/config HTTP/1.1" 404 605 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
🇫🇷
masterguru
2026-09-10 09:14:06
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇳🇱
e.fierstra
2026-09-10 09:12:51
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇨🇭
Origon
2026-09-10 09:11:29
(1 day ago)
http-sensitive-files - IP: 34.17.116.21 - time="2026-09-10T11:11:29+02:00" level=info msg="(555f66b ...
show more
http-sensitive-files - IP: 34.17.116.21 - time="2026-09-10T11:11:29+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 34.17.116.21 (IT/396982) : 4h ban on Ip 34.17.116.21" module=db
show less
Web App Attack