🇺🇸
TPI-Abuse
2026-09-10 06:13:40
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.155.234 (234.155.186.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.155.234 (234.155.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 02:13:34.332025 2026] [security2:error] [pid 15156:tid 15156] [client 34.186.155.234:41012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "walkingwithafricans.org"] [uri "/.git/config"] [unique_id "aqJKjpNjkDprvJaXMclTIwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 03:42:44
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.155.234 (234.155.186.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.155.234 (234.155.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 23:42:40.144289 2026] [security2:error] [pid 15403:tid 15403] [client 34.186.155.234:38362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thetheaterathollywoodandvine.com"] [uri "/.git/config"] [unique_id "aqInMFq3d7-e0Q2dY35GqQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-10 00:18:39
(9 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇳🇱
Savvii
2026-09-10 00:01:15
(9 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 20:58:24
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.155.234 (234.155.186.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.155.234 (234.155.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 16:58:19.925373 2026] [security2:error] [pid 22350:tid 22350] [client 34.186.155.234:54138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "schrankhome.com"] [uri "/.git/config"] [unique_id "aqHIa39KfhtCDIaxKRUMuAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 20:36:32
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.155.234 (234.155.186.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.155.234 (234.155.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 16:36:27.980592 2026] [security2:error] [pid 10403:tid 10403] [client 34.186.155.234:34880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "toepert.bknj2.org"] [uri "/.git/config"] [unique_id "aqHDS6BsDOS9azom72igCwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-09 20:23:09
(13 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 20:17:41
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.155.234 (234.155.186.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.155.234 (234.155.186.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 16:17:37.536771 2026] [security2:error] [pid 2098:tid 2098] [client 34.186.155.234:52404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "todotex.com"] [uri "/.git/config"] [unique_id "aqG-4ZYH1vwsg8oKdv6ODAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
MarkGGN
2026-09-09 20:05:57
(13 hours ago)
Web attack. 34.186.155.234 - - [09/Sep/2026:22:05:56 +0200] "GET /.git/config HTTP/1.1" 403 177 "-" ...
show more
Web attack. 34.186.155.234 - - [09/Sep/2026:22:05:56 +0200] "GET /.git/config HTTP/1.1" 403 177 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.186.155.234 - - [09/Sep/2026:22:05:56 +0200] "GET /.env HTTP/1.1" 403 177 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Web App Attack
🇧🇪
cmbplf
2026-09-09 19:38:40
(14 hours ago)
2.717 requests with url.path *.env
359 requests with url.path *phpinfo.php
Brute-Force
Bad Web Bot
🇳🇱
sernate
2026-09-09 18:41:27
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.186.155.234 (US/United States/234.155.186.34 ...
show more
(mod_security) mod_security (id:210492) triggered by 34.186.155.234 (US/United States/234.155.186.34.bc.googleusercontent.com): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_MODSEC
show less
Brute-Force
🇩🇪
FD-IX
2026-09-09 18:07:46
(15 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-09 15:20:03
(18 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-09 14:53:20
(19 hours ago)
34.186.155.234 - - [09/Sep/2026:16:53:15 +0200] "GET /.env HTTP/1.1" 404 513 "-" "Mozilla/5.0 (X11; ...
show more
34.186.155.234 - - [09/Sep/2026:16:53:15 +0200] "GET /.env HTTP/1.1" 404 513 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.186.155.234 - - [09/Sep/2026:16:53:16 +0200] "GET /.env.local HTTP/1.1" 404 513 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.186.155.234 - - [09/Sep/2026:16:53:16 +0200] "GET /.env.production HTTP/1.1" 404 513 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.186.155.234 - - [09/Sep/2026:16:53:16 +0200] "GET /.env.staging HTTP/1.1" 404 513 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.186.155.234 - - [09/Sep/2026:16:53:16 +0200] "GET /.env.development HTTP/1.1" 404 513 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.186.155.234 - - [09/Sep/2026:16:53:
show less
Web App Attack
Hacking
🇺🇸
WellSpring
2026-09-09 14:52:05
(19 hours ago)
env leak on wellspr.ing/frontend/.env — WellSpr.ing/NetSentinel civic-AI security layer
Web App Attack