๐ฉ๐ช
FD-IX
2026-09-15 22:34:20
(5 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-15 21:26:19
(6 hours ago)
(modsecurity) srv104 ModSecurity 34.17.167.12 (IT/Italy/12.167.17.34.bc.googleusercontent.com): 30 i ...
show more
(modsecurity) srv104 ModSecurity 34.17.167.12 (IT/Italy/12.167.17.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
abenage
2026-09-15 21:23:09
(6 hours ago)
34.17.167.12 - - [15/Sep/2026:15:23:09 -0600] "GET /phpinfo.php HTTP/1.1" 404 564 "-" "Mozilla/5.0 ( ...
show more
34.17.167.12 - - [15/Sep/2026:15:23:09 -0600] "GET /phpinfo.php HTTP/1.1" 404 564 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-15 20:52:47
(7 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.17.167.12 (IT/Italy/12.167.17.34.bc.googleus ...
show more
(mod_security) mod_security (id:949110) triggered by 34.17.167.12 (IT/Italy/12.167.17.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-15 14:58:10
(12 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฉ๐ช
Hazzard
2026-09-15 13:25:15
(14 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ซ๐ท
Little Iguana
2026-09-15 12:43:21
(15 hours ago)
Attempt to hack Wordpress Login, XMLRPC or other login
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-15 11:43:14
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.167.12 (12.167.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.167.12 (12.167.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 07:43:08.154539 2026] [security2:error] [pid 26319:tid 26319] [client 34.17.167.12:55894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.basicsa.com"] [uri "/.git/config"] [unique_id "aqkvTFyzfCypVPSD1hWK_AAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-15 11:11:56
(16 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 08:55:03
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.167.12 (12.167.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.167.12 (12.167.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 04:54:55.159762 2026] [security2:error] [pid 6107:tid 6107] [client 34.17.167.12:34990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.baptismnapkins.com"] [uri "/.git/config"] [unique_id "aqkH307KVyPM-CR_AgXREgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-15 05:20:03
(22 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ซ๐ท
Sorgin Informatique
2026-09-15 03:08:16
(1 day ago)
soe-6 : Trying access system files=>/phpinfo.php(phpinfo.php)
Hacking
๐บ๐ธ
TPI-Abuse
2025-11-08 06:35:42
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 34.17.167.12 (12.167.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.17.167.12 (12.167.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 08 01:35:37.396554 2025] [security2:error] [pid 9116:tid 9116] [client 34.17.167.12:38956] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||dodojuice.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "dodojuice.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQ7kuR66Kda_tRtpPqQbIAAAABE"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-08 00:44:59
(10 months ago)
(mod_security) mod_security (id:225170) triggered by 34.17.167.12 (12.167.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:225170) triggered by 34.17.167.12 (12.167.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 07 19:44:53.556754 2025] [security2:error] [pid 18207:tid 18207] [client 34.17.167.12:44176] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||gp-cm.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "gp-cm.com"] [uri "/wp-json/wp/v2/users"] [unique_id "aQ6ShSf2ZE-U-4A-WFJ9XgAAAAI"], referer: https://www.google.com
show less
Brute-Force
Bad Web Bot
Web App Attack