🇺🇸
TPI-Abuse
2026-09-05 10:30:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.17.135.100 (100.135.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.135.100 (100.135.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 06:30:30.272569 2026] [security2:error] [pid 32243:tid 32243] [client 34.17.135.100:34156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.feaverslane.com"] [uri "/.git/config"] [unique_id "apvvRpmSTVASPE2CmSeJUAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 08:54:46
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.17.135.100 (100.135.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.135.100 (100.135.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 04:54:40.168154 2026] [security2:error] [pid 17112:tid 17112] [client 34.17.135.100:55440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.fales.org"] [uri "/.git/config"] [unique_id "apvY0M-2TlZJ2nf-Ji010AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
rellik
2026-09-05 07:39:00
(2 days ago)
Brute Force Scanning Critical Directories
Hacking
Brute-Force
Web App Attack
🇷🇴
clauss
2026-09-05 02:32:05
(2 days ago)
34.17.135.100 - - [05/Sep/2026:05:32:04 +0300] "GET /.git/config HTTP/1.1" 401 36 "-" "Mozilla/5.0 ( ...
show more
34.17.135.100 - - [05/Sep/2026:05:32:04 +0300] "GET /.git/config HTTP/1.1" 401 36 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.17.135.100 - - [05/Sep/2026:05:32:04 +0300] "GET /.env.local HTTP/1.1" 401 36 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 01:26:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.17.135.100 (100.135.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.135.100 (100.135.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 21:26:21.693874 2026] [security2:error] [pid 28035:tid 28035] [client 34.17.135.100:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.empoweruamerica.org"] [uri "/.git/config"] [unique_id "aptvvaqzy5XZVJ89LI5NNwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-04 23:30:03
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇩🇪
4server
2026-09-04 20:29:09
(2 days ago)
[FriSep0422:29:08.0292952026][security2:error][pid623760:tid623827][client34.17.135.100:0]ModSecurit ...
show more
[FriSep0422:29:08.0292952026][security2:error][pid623760:tid623827][client34.17.135.100:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpcontacts.ecosuber.com\"][uri\"/.env.bak\"][unique_id\"apsqFNMwYhqk6UBlh4zVewAAAIY\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 19:13:30
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.17.135.100 (100.135.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.135.100 (100.135.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 15:13:23.834433 2026] [security2:error] [pid 3400899:tid 3401002] [client 34.17.135.100:58794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.earthtravel.net"] [uri "/.git/config"] [unique_id "apsYUz5yzRy2NsbRVfMj9AAAAdc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:13:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.17.135.100 (100.135.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.135.100 (100.135.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:13:50.580663 2026] [security2:error] [pid 3264:tid 3264] [client 34.17.135.100:39856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.drbolen.com"] [uri "/.git/config"] [unique_id "aprgLhd1bNUcKTP3aERPUwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:09:28
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.17.135.100 (100.135.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.135.100 (100.135.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:09:23.660259 2026] [security2:error] [pid 2382:tid 2382] [client 34.17.135.100:39706] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.indie100.com"] [uri "/.git/config"] [unique_id "appSgyCtWfeOnIqSpImaEgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-03 21:30:04
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 11:40:36
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.17.135.100 (100.135.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.135.100 (100.135.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 07:40:32.591018 2026] [security2:error] [pid 17915:tid 17915] [client 34.17.135.100:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.grainavi.com"] [uri "/.git/config"] [unique_id "aplcsKz7cd26IsyYnKomFgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-09-03 09:18:07
(4 days ago)
[ThuSep0311:18:01.8689042026][security2:error][pid2704117:tid2704223][client34.17.135.100:0]ModSecur ...
show more
[ThuSep0311:18:01.8689042026][security2:error][pid2704117:tid2704223][client34.17.135.100:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpcontacts.gmint.ch\"][uri\"/.env.bak\"][unique_id\"apk7SaVBzYnqVV6ibjPrsQAAAYk\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 08:18:58
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.17.135.100 (100.135.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.135.100 (100.135.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 04:18:53.799366 2026] [security2:error] [pid 26039:tid 26039] [client 34.17.135.100:36030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.glamorgirl.net"] [uri "/.git/config"] [unique_id "apktbYLrkIe0XjNE2hLWagAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-03 04:24:40
(4 days ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 1s
Web App Attack