🇷🇴
clauss
2026-09-04 01:36:42
(1 hour ago)
34.17.120.24 - - [04/Sep/2026:04:36:41 +0300] "GET /.git/config HTTP/1.1" 401 36 "-" "Mozilla/5.0 (W ...
show more
34.17.120.24 - - [04/Sep/2026:04:36:41 +0300] "GET /.git/config HTTP/1.1" 401 36 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.17.120.24 - - [04/Sep/2026:04:36:41 +0300] "GET /.env.local HTTP/1.1" 401 36 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇮🇹
VHosting
2026-09-03 21:10:03
(6 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 13:28:33
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.120.24 (24.120.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.120.24 (24.120.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 09:28:28.107072 2026] [security2:error] [pid 26604:tid 26604] [client 34.17.120.24:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.distro.media"] [uri "/.git/config"] [unique_id "apl1_FUQ1M3PBeydNY0BuwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 11:02:08
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.120.24 (24.120.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.120.24 (24.120.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 07:02:05.626611 2026] [security2:error] [pid 996532:tid 996549] [client 34.17.120.24:50284] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.destination-kitchen.com"] [uri "/.git/config"] [unique_id "aplTrV_WVoYYsPpRGyxivgAAAEY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-03 08:26:18
(18 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 1s
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 08:20:43
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.120.24 (24.120.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.120.24 (24.120.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 04:20:38.850986 2026] [security2:error] [pid 26711:tid 26711] [client 34.17.120.24:59470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.davidsonmanagement.net"] [uri "/.git/config"] [unique_id "apkt1rYIMfpS8yytfcdPxwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-09-03 03:15:08
(1 day ago)
[ThuSep0305:15:05.3591732026][security2:error][pid2329109:tid2329146][client34.17.120.24:0]ModSecuri ...
show more
[ThuSep0305:15:05.3591732026][security2:error][pid2329109:tid2329146][client34.17.120.24:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpcontacts.creazione-siti-web-ticino.ch\"][uri\"/.env.bak\"][unique_id\"apjmOeFpFTKRdyinZL86twAAAEU\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 00:47:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.17.120.24 (24.120.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.120.24 (24.120.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 20:47:28.209704 2026] [security2:error] [pid 26160:tid 26160] [client 34.17.120.24:47448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.frenosilent.ar"] [uri "/.git/config"] [unique_id "apjDoF8lgZUI6dXJx_R9ugAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 23:24:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.17.120.24 (24.120.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.120.24 (24.120.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 19:24:24.319510 2026] [security2:error] [pid 3896:tid 3896] [client 34.17.120.24:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.forsaleincr.com"] [uri "/.git/config"] [unique_id "apiwKJXvgyXwKiKsHZ4ceQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 22:49:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.17.120.24 (24.120.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.120.24 (24.120.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 18:49:16.650288 2026] [security2:error] [pid 11221:tid 11314] [client 34.17.120.24:48846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.colinkyffinmusic.com"] [uri "/.git/config"] [unique_id "apin7IxVKizXSiPGFPpWugAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 21:17:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.17.120.24 (24.120.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.120.24 (24.120.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 17:17:52.522291 2026] [security2:error] [pid 29654:tid 29654] [client 34.17.120.24:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.cloudex.click"] [uri "/.git/config"] [unique_id "apiSgAWurlj5LeWpmONROwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-02 20:05:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 18:36:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.17.120.24 (24.120.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.120.24 (24.120.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 14:35:53.774780 2026] [security2:error] [pid 4530:tid 4530] [client 34.17.120.24:51304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.feaverslane.com"] [uri "/.git/config"] [unique_id "aphsicrbleKiIxJSJY_vpwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 16:58:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.17.120.24 (24.120.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.120.24 (24.120.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 12:57:54.279514 2026] [security2:error] [pid 19712:tid 19712] [client 34.17.120.24:57464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.fairfieldfarms.net"] [uri "/.git/config"] [unique_id "aphVkhTHuJRrRpcEwsZzBQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
rellik
2026-09-02 16:04:00
(1 day ago)
Brute Force Scanning Critical Directories
Hacking
Brute-Force
Web App Attack