🇺🇸
TPI-Abuse
2026-09-03 05:22:52
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.32.11.74 (74.11.32.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.11.74 (74.11.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 01:22:44.642593 2026] [security2:error] [pid 17704:tid 17704] [client 34.32.11.74:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.eddysgroup.com"] [uri "/.git/config"] [unique_id "apkEJMQMxC1v6YyW0x1VmgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ecs.ge
2026-09-03 05:04:48
(9 hours ago)
Automatic Fail2Ban report from jail plesk-modsecurity: multiple matching events detected.
Web App Attack
Hacking
🇨🇿
Prcek
2026-09-03 04:42:38
(10 hours ago)
PortScan:HOST=34.32.11.74,DPORTS=443
Port Scan
🇨🇦
danieljamesbertrand
2026-09-03 01:55:53
(13 hours ago)
fail2ban jail=nginx-access-exploit on canadapaywall (automatic report; categories 19,21)
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-03 01:31:15
(13 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇷🇺
DZBOT
2026-09-03 01:02:08
(14 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
🇩🇪
DyhnenTv
2026-09-03 00:32:01
(14 hours ago)
CrowdSec webserver: crowdsecurity/http-sensitive-files
Web App Attack
Bad Web Bot
🇫🇮
mnazibo
2026-09-02 23:30:13
(15 hours ago)
Date: Sep 03 02:24:41 2026 EAT | Reported IP: 34.32.11.74 mod_security | id: 920440 930130 932130 93 ...
show more
Date: Sep 03 02:24:41 2026 EAT | Reported IP: 34.32.11.74 mod_security | id: 920440 930130 932130 932235 932260 933135 934100 934130 942151 942550 949110 920500 | DE/usernameab.my_domain/- | Connections: 1 | Blocked: Permanent Block: [LF_MODSEC] | Logs: ; URL file extension is restricted by policy; URL file extension is restricted by policy; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Restricted File Access Attempt; Remote Command Execution: Unix Shell Expression Found; Remote Command Execution: Unix Shell Expression Found; Remote Command Execution: Unix Command Injection (command without evasion); Remote Command Execution: Unix Command Injection (command without evasion); Remote Command Execution
show less
SQL Injection
Brute-Force
Bad Web Bot
Anonymous
2026-09-02 23:16:36
(15 hours ago)
2026-09-02 19:16:36,524 fail2ban.actions [3492968]: NOTICE [apache-auth] Ban 34.32.11.74
...
Port Scan
Brute-Force
🇺🇸
magnetosphere-tarpit
2026-09-02 20:47:49
(18 hours ago)
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not ...
show more
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not exist on this host. Tarpitted, then banned: 10 requests within 24h0m0s
show less
Port Scan
Bad Web Bot
Web App Attack
🇩🇪
dom4k
2026-09-02 14:31:43
(1 day ago)
34.32.11.74 - - [02/Sep/2026:14:31:42 +0000] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Mac ...
show more
34.32.11.74 - - [02/Sep/2026:14:31:42 +0000] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web Spam
Bad Web Bot
Web App Attack
🇩🇪
ddobko
2026-09-02 13:13:31
(1 day ago)
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 13:12:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.32.11.74 (74.11.32.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.11.74 (74.11.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 09:12:22.593204 2026] [security2:error] [pid 3259:tid 3289] [client 34.32.11.74:33020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.dobairrosuites.com"] [uri "/.git/config"] [unique_id "apggtkyyq0IXAYWgql4C7gAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-02 12:09:48
(1 day ago)
csagent: score 20.4: secrets grab x2, 404 noise floor x2; 1 domain(s) in 2s
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 06:19:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.32.11.74 (74.11.32.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.32.11.74 (74.11.32.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 02:19:26.876700 2026] [security2:error] [pid 27742:tid 27742] [client 34.32.11.74:33190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.diarrheawolves.com"] [uri "/.git/config"] [unique_id "ape_7iUuNx16EO9PM7jSKQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack