π©πͺ
Lino Project
2026-09-29 12:47:25
(19 hours ago)
34.187.77.243 - - [29/Sep/2026:14:47:21 +0200] "GET /.git/config HTTP/1.1" 404 418 "-" "Mozilla/5.0 ...
show more
34.187.77.243 - - [29/Sep/2026:14:47:21 +0200] "GET /.git/config HTTP/1.1" 404 418 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 09:37:20
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.187.77.243 (243.77.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.77.243 (243.77.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 05:37:12.491714 2026] [security2:error] [pid 4277:tid 4277] [client 34.187.77.243:53186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.creativeawardsaz.com"] [uri "/.git/config"] [unique_id "aruGyBB52Y7V10OmTonXAgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ghostwarriors
2026-09-29 07:50:04
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
π©πͺ
yitzhaq
2026-09-29 07:22:02
(1 day ago)
34.187.77.243 - - [29/Sep/2026:09:21:59 +0200] "GET /resources/.env HTTP/1.1" 404 516 "-" "Mozilla/5 ...
show more
34.187.77.243 - - [29/Sep/2026:09:21:59 +0200] "GET /resources/.env HTTP/1.1" 404 516 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.187.77.243 - - [29/Sep/2026:09:21:59 +0200] "GET /assets/.env HTTP/1.1" 404 516 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.187.77.243 - - [29/Sep/2026:09:21:59 +0200] "GET /uploads/.env HTTP/1.1" 404 516 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.187.77.243 - - [29/Sep/2026:09:21:59 +0200] "GET /internal/.env HTTP/1.1" 404 516 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.187.77.243 - - [29/Sep/2026:09:21:59 +0200] "GET /tools/.env HTTP/1.1" 404 516 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safar
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-29 04:54:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.187.77.243 (243.77.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.77.243 (243.77.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 00:54:43.080275 2026] [security2:error] [pid 18717:tid 18738] [client 34.187.77.243:51456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cookmanufacturinggroup.com"] [uri "/.git/config"] [unique_id "artEkwXn_sj-GauVX7FXBQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-09-28 22:02:06
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-27.
show less
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-09-28 07:32:09
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.187.77.243 (243.77.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.77.243 (243.77.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 03:32:03.706839 2026] [security2:error] [pid 3016:tid 3016] [client 34.187.77.243:50098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.adamsclothiers.com"] [uri "/.git/config"] [unique_id "aroX85iFIDPyaxd59szd5wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
e.fierstra
2026-09-28 05:52:42
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
π³π±
ConsulHosting
2026-09-27 09:33:35
(2 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
π΅π±
Budyn
2026-09-27 04:18:48
(3 days ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: mail.astropot.online | URI: /.git/config | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
π¦πΊ
screwlooseit.com.au
2026-09-26 11:04:03
(3 days ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/243.77.187.34.bc.googleuserconten ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/243.77.187.34.bc.googleusercontent.com
show less
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-09-26 07:35:22
(4 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
π³π±
Mangelot Hosting
2026-09-25 02:31:03
(5 days ago)
(modsecurity) srv103 ModSecurity 34.187.77.243 (NL/The Netherlands/243.77.187.34.bc.googleuserconten ...
show more
(modsecurity) srv103 ModSecurity 34.187.77.243 (NL/The Netherlands/243.77.187.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-24 19:09:08
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.187.77.243 (243.77.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.77.243 (243.77.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 15:09:01.452546 2026] [security2:error] [pid 26370:tid 26370] [client 34.187.77.243:33770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "onevoicefoundationlb.org"] [uri "/.git/config"] [unique_id "arV1TeOIKhkOB9GkMKfLgAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-24 03:44:44
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.187.77.243 (243.77.187.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.187.77.243 (243.77.187.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 23:44:39.372904 2026] [security2:error] [pid 8191:tid 8191] [client 34.187.77.243:43782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jamelrobinson.com"] [uri "/.git/config"] [unique_id "arScp64OYzBp9WXXqjxaCQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack