๐บ๐ธ
TPI-Abuse
2026-09-23 14:53:24
(21 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.22.35.189 (189.35.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.35.189 (189.35.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 10:53:19.946451 2026] [security2:error] [pid 20027:tid 20027] [client 34.22.35.189:48354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brianwhitty.com"] [uri "/site/.git/config"] [unique_id "arPn3_mpvRkgXhxRl5as8AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
billfor
2026-09-23 12:20:39
(2 hours ago)
34.22.35.189 - - [23/Sep/2026:08:20:37 -0400] "GET /wordpress/.git/config HTTP/1.1" 404 0 "-" "crusa ...
show more
34.22.35.189 - - [23/Sep/2026:08:20:37 -0400] "GET /wordpress/.git/config HTTP/1.1" 404 0 "-" "crusader-worker/1.0"
show less
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-23 12:00:09
(3 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-23 10:06:57
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฆ๐บ
KevinNeale
2026-09-23 08:25:20
(6 hours ago)
Fail2Ban recidive block for repeated malicious authentication attempts.
Brute-Force
Web App Attack
๐บ๐ธ
factor1
2026-09-23 06:30:25
(8 hours ago)
CrowdSec at apollo Reports Abuse
Web App Attack
๐ฉ๐ช
sigurg
2026-09-23 05:46:57
(9 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฉ๐ช
netclix.gr
2026-09-23 05:26:55
(9 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.22.35.189 (US/United States/189.35.2 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.22.35.189 (US/United States/189.35.22.34.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-23 05:01:24
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.35.189 (189.35.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.35.189 (189.35.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 01:01:18.393698 2026] [security2:error] [pid 14592:tid 14592] [client 34.22.35.189:43428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "astrologydemo.com"] [uri "/api/.git/config"] [unique_id "arNdHqs_hoqth60q78FnjwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 04:07:54
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.35.189 (189.35.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.35.189 (189.35.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 00:07:50.314851 2026] [security2:error] [pid 1756336:tid 1756336] [client 34.22.35.189:38162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arogun.org"] [uri "/var/www/.git/config"] [unique_id "arNQlkXk3rlYZOl4BGabpQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Kreapptivo
2026-09-23 00:17:48
(14 hours ago)
34.22.35.189 - [2026-09-23T02:17:47+02:00] "GET /www/.git/config HTTP/1.1" 400 "code=400, message=m ...
show more
34.22.35.189 - [2026-09-23T02:17:47+02:00] "GET /www/.git/config HTTP/1.1" 400 "code=400, message=missing or malformed jwt" 44 "api.abschlussfilm.com" "crusader-worker/1.0" "" 14678
34.22.35.189 - [2026-09-23T02:17:47+02:00] "GET /var/www/.git/config HTTP/1.1" 400 "code=400, message=missing or malformed jwt" 44 "api.abschlussfilm.com" "crusader-worker/1.0" "" 19187
34.22.35.189 - [2026-09-23T02:17:47+02:00] "GET /html/.git/config HTTP/1.1" 400 "code=400, message=missing or malformed jwt" 44 "api.abschlussfilm.com" "crusader-worker/1.0" "" 29937
34.22.35.189 - [2026-09-23T02:17:47+02:00] "GET /public/.git/config HTTP/1.1" 400 "code=400, message=missing or malformed jwt" 44 "api.abschlussfilm.com" "crusader-worker/1.0" "" 22103
34.22.35.189 - [2026-09-23T02:17:47+02:00] "GET /api/.git/config HTTP/1.1" 400 "code=400, message=missing or malformed jwt" 44 "api.abschlussfilm.com" "crusader-worker/1.0" "" 26069
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-22 22:28:41
(16 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 21:18:21
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.22.35.189 (189.35.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.22.35.189 (189.35.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:18:14.087070 2026] [security2:error] [pid 18580:tid 18580] [client 34.22.35.189:55158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "agworldmissions.org"] [uri "/public/.git/config"] [unique_id "arLwllsdQhx-XVnJTIEpOwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-22 20:45:58
(18 hours ago)
[22/Sep/2026:23:45:58 +0300] -- 34.22.35.189 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/ ...
show more
[22/Sep/2026:23:45:58 +0300] -- 34.22.35.189 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 20:37:05
(18 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.22.35.189 (189.35.22.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.22.35.189 (189.35.22.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:37:01.763726 2026] [security2:error] [pid 27444:tid 27444] [client 34.22.35.189:57494] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "advancedrentalandservice.com"] [uri "/.git/config"] [unique_id "arLm7R_Sev7lMk0XWmTvwQAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack