🇫🇷
Feelautom
2026-09-12 03:42:59
(6 minutes ago)
[FeelAutom Auto-Ban] PathScan: /.env.backup (Score: 200)
Port Scan
🇺🇸
TPI-Abuse
2026-09-12 03:31:49
(17 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.18.17.179 (179.17.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.17.179 (179.17.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 23:31:43.358169 2026] [security2:error] [pid 27734:tid 27734] [client 34.18.17.179:45802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "heytechiesshow.com"] [uri "/.git/config"] [unique_id "aqTHn6tcitAu8zTr46-htAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-11 16:53:15
(10 hours ago)
Excessive multi-domain requests
Brute-Force
🇦🇺
2000cn.com.au
2026-09-11 05:21:24
(22 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-11 03:17:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.18.17.179 (179.17.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.17.179 (179.17.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 23:17:45.885131 2026] [security2:error] [pid 8540:tid 8540] [client 34.18.17.179:59982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gvimmobilier.com"] [uri "/.git/config"] [unique_id "aqNy2X9PmIY6pWkR4bV4jQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Gwyneth Llewelyn
2026-09-10 21:16:00
(1 day ago)
2026/09/10 22:15:52 [error] 1267648#1267648: *1857 access forbidden by rule, client: 34.18.17.179, s ...
show more
2026/09/10 22:15:52 [error] 1267648#1267648: *1857 access forbidden by rule, client: 34.18.17.179, server: getasecondlife.net, request: "GET /.env HTTP/1.1", host: "getasecondlife.net"
34.18.17.179 - - [10/Sep/2026:22:15:52 +0100] "GET /.env HTTP/1.1" 403 1178 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
2026/09/10 22:15:58 [error] 1267648#1267648: *1857 access forbidden by rule, client: 34.18.17.179, server: getasecondlife.net, request: "GET /app/.env HTTP/1.1", host: "getasecondlife.net"
show less
Brute-Force
Web App Attack
Anonymous
2026-09-10 06:27:45
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-10 06:11:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.18.17.179 (179.17.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.17.179 (179.17.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 02:11:45.803067 2026] [security2:error] [pid 31431:tid 31474] [client 34.18.17.179:40136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "icbc-canada.com"] [uri "/.git/config"] [unique_id "aqJKIXNkqeK6GZcKL0gLeAAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ruusvuu
2026-09-10 05:21:08
(1 day ago)
Automated abuse report: 25 attack/probe requests from Google LLC / QA.
Targeted paths: /phpinfo, /gc ...
show more
Automated abuse report: 25 attack/probe requests from Google LLC / QA.
Targeted paths: /phpinfo, /gcp-credentials.json, /credentials.json, /google-credentials.json, /.config/gcloud/application_default_credentials.json.
Sample log lines:
[icantell] 34.18.17.179 - - [10/Sep/2026:05:21:07 +0000] "GET /.config/gcloud/application_default_credentials.json HTTP/1.1" 404 2651 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/…
[icantell] 34.18.17.179 - - [10/Sep/2026:05:21:07 +0000] "GET /application_default_credentials.json HTTP/1.1" 404 2651 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, …
[icantell] 34.18.17.179 - - [10/Sep/2026:05:21:07 +0000] "GET /key.json HTTP/1.1" 404 2651 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0…
Detected by an automated web-server log monitor.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 04:49:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.18.17.179 (179.17.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.17.179 (179.17.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 00:49:29.034613 2026] [security2:error] [pid 12667:tid 12667] [client 34.18.17.179:48652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "icafe.bz"] [uri "/.git/config"] [unique_id "aqI22XIliaMU6rvwKRAJVQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-10 04:20:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇳🇱
maxxsense
2026-09-10 04:10:21
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.18.17.179 (QA/Qatar/179.17.18.34.bc. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.18.17.179 (QA/Qatar/179.17.18.34.bc.googleusercontent.com)
show less
SQL Injection
🇧🇾
lns.bz
2026-09-10 04:09:00
(1 day ago)
Too many 404 requests [BY]
Web App Attack
🇩🇪
Hazzard
2026-09-10 04:02:16
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇩🇪
ghostwarriors
2026-09-10 03:50:07
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack