🇺🇸
TPI-Abuse
2026-09-06 17:01:32
(13 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.17.175.68 (68.175.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.175.68 (68.175.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 13:01:24.708617 2026] [security2:error] [pid 14036:tid 14036] [client 34.17.175.68:44088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidwoodard.com"] [uri "/.git/config"] [unique_id "ap2cZF5KQmFdIBzB3pIdgwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 16:38:45
(36 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.17.175.68 (68.175.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.175.68 (68.175.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:38:39.179419 2026] [security2:error] [pid 29104:tid 29107] [client 34.17.175.68:38908] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidtung.com"] [uri "/.git/config"] [unique_id "ap2XD5L9H6d2xuY8_boUkwAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-06 16:20:03
(54 minutes ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 16:07:31
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.17.175.68 (68.175.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.175.68 (68.175.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:07:24.088991 2026] [security2:error] [pid 7220:tid 7220] [client 34.17.175.68:46898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidsonmanagement.net"] [uri "/.git/config"] [unique_id "ap2PvIAhBjXb9p-8stKnRgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
yitzhaq
2026-09-06 15:54:32
(1 hour ago)
34.17.175.68 - - [06/Sep/2026:17:54:25 +0200] "POST / HTTP/1.1" 200 4308 "-" "Mozilla/5.0 (Macintosh ...
show more
34.17.175.68 - - [06/Sep/2026:17:54:25 +0200] "POST / HTTP/1.1" 200 4308 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.17.175.68 - - [06/Sep/2026:17:54:26 +0200] "POST / HTTP/1.1" 200 4308 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.17.175.68 - - [06/Sep/2026:17:54:26 +0200] "GET /.git/config HTTP/1.1" 403 520 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.17.175.68 - - [06/Sep/2026:17:54:26 +0200] "GET /.env HTTP/1.1" 404 26663 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.17.175.68 - - [06/Sep/2026:17:54:27 +0200] "GET /.env.local HTTP/1.1" 404 26663 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 15:10:08
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.175.68 (68.175.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.175.68 (68.175.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:10:01.442948 2026] [security2:error] [pid 4121:tid 4121] [client 34.17.175.68:37302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidquiroa.com"] [uri "/.git/config"] [unique_id "ap2CSRDsypKXvmw9c_YasAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-06 15:00:05
(2 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-06 14:57:28
(2 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 14:43:05
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.175.68 (68.175.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.175.68 (68.175.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:43:01.610815 2026] [security2:error] [pid 22046:tid 22046] [client 34.17.175.68:38382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidocchino.com"] [uri "/.git/config"] [unique_id "ap179e68iw8IGfQKMn8elQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 14:25:00
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.17.175.68 (68.175.17.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.17.175.68 (68.175.17.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:24:56.354907 2026] [security2:error] [pid 17422:tid 17422] [client 34.17.175.68:56296] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidmoisan.org"] [uri "/.git/config"] [unique_id "ap13uLxo14XhPrrfM2_p2AAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
dave
2026-09-06 14:18:54
(2 hours ago)
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity ...
show more
threat-feed-sync observed repeated abuse from this IP after local filtering. scenarios=crowdsecurity/appsec-vpatch,crowdsecurity/vpatch-CVE-2025-55182,crowdsecurity/vpatch-env-access,crowdsecurity/vpatch-git-config observed_by=1_hosts hit_count=124 first_seen=2026-09-06T14:18:43Z last_seen=2026-09-06T14:18:54Z
show less
Web App Attack