๐ฎ๐น
VHosting
2026-09-19 11:20:03
(10 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 11:16:04
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.142.128 (128.142.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.142.128 (128.142.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 07:15:57.711826 2026] [security2:error] [pid 26641:tid 26641] [client 34.17.142.128:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.atlascoombs.com"] [uri "/.git/config"] [unique_id "aq5u7bFKkJuwUtpzPudb2AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-18 22:01:32
(23 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-17.
show less
Web App Attack
SSH
Hacking
๐ฌ๐ง
Aetherweb Ark
2026-09-18 17:15:10
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.17.142.128 (IT/Italy/128.142.17.34.bc.google ...
show more
(mod_security) mod_security (id:949110) triggered by 34.17.142.128 (IT/Italy/128.142.17.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
paulo.apoloni
2026-09-18 13:03:45
(1 day ago)
34.17.142.128 - - [18/Sep/2026:10:03:42 -0300] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (W ...
show more
34.17.142.128 - - [18/Sep/2026:10:03:42 -0300] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.17.142.128 - - [18/Sep/2026:10:03:43 -0300] "GET /.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.17.142.128 - - [18/Sep/2026:10:03:44 -0300] "GET /.env.bak HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.17.142.128 - - [18/Sep/2026:10:03:44 -0300] "GET /.env.backup HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.17.142.128 - - [18/Sep/2026:10:03:44 -0300] "GET /.env.save HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
MPL
2026-09-18 06:05:28
(1 day ago)
tcp/443 (2 or more attempts)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-17 16:12:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.17.142.128 (128.142.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.142.128 (128.142.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 12:12:05.186903 2026] [security2:error] [pid 31304:tid 31304] [client 34.17.142.128:52078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dawnmazur.com"] [uri "/.git/config"] [unique_id "aqwRVZ3tqtDNxvuEaHN-jAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-17 16:04:08
(2 days ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 2s
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-17 14:58:48
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-17 13:07:02
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.17.142.128 (128.142.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.142.128 (128.142.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 09:06:57.378261 2026] [security2:error] [pid 19798:tid 19951] [client 34.17.142.128:40676] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daviscountyossr.org"] [uri "/.git/config"] [unique_id "aqvl8dYvbzONyL5caX4J1AAAAFc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-17 12:21:10
(2 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-17 12:15:02
(2 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 11:52:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.17.142.128 (128.142.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.142.128 (128.142.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 07:52:47.739369 2026] [security2:error] [pid 5605:tid 5605] [client 34.17.142.128:60560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidwoodard.com"] [uri "/.git/config"] [unique_id "aqvUj9vihHUcA-FBCKaprQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 11:35:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.17.142.128 (128.142.17.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.142.128 (128.142.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 07:35:05.231216 2026] [security2:error] [pid 15220:tid 15274] [client 34.17.142.128:34974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidtung.com"] [uri "/.git/config"] [unique_id "aqvQaVzmTF6x-majLL1LJAAAAYo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-17 11:20:07
(2 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack