๐บ๐ธ
TPI-Abuse
2026-09-17 02:57:55
(44 minutes ago)
(mod_security) mod_security (id:949110) triggered by 34.35.122.20 (20.122.35.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.35.122.20 (20.122.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:57:49.819644 2026] [security2:error] [pid 16822:tid 16822] [client 34.35.122.20:44408] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "psqeng.com"] [uri "/.git/config"] [unique_id "aqtXLTfDUzE8R2MVJTXT-AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
0xffffffff
2026-09-17 02:06:55
(1 hour ago)
[2026-09-17 05:06:52.665701] [authz_core:error] [pid 268599:tid 131438016669376] [client 34.35.122.2 ...
show more
[2026-09-17 05:06:52.665701] [authz_core:error] [pid 268599:tid 131438016669376] [client 34.35.122.20:0] AH01630: client denied by server configuration: /var/www/*/.git , error_notes:config-files , URI:'/.git/config'
[2026-09-17 05:06:53.121095] [authz_core:error] [pid 268598:tid 131437831857856] [client 34.35.122.20:0] AH01630: client denied by server configuration: /var/www/*/.env , error_notes:config-files , URI:'/.env'
[2026-09-17 05:06:53.303392] [authz_core:error] [pid 268598:tid 131437823448768] [client 34.35.122.20:0] AH01630: client denied by server configuration: /var/www/*/.env.local , error_notes:config-files , URI:'/.env.local'
[2026-09-17 05:06:53.483494] [authz_core:error] [pid 268598:tid 131437815039680] [client 34.35.122.20:0] AH01630: client denied by server configuration: /var/www/*/.env.production , error_notes:dot-files , URI:'/.env.production'
[2026-09-17 05:06:53.663814] [authz_core:error] [pid 268598:tid 131438016669376] [client 34.35.122.20:0] AH01630: client denied by server configur
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-16 17:57:32
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.122.20 (20.122.35.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.122.20 (20.122.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 13:57:25.073541 2026] [security2:error] [pid 28456:tid 28456] [client 34.35.122.20:49816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "moonstonenightclub.com"] [uri "/.git/config"] [unique_id "aqrYhfeRB21LGFsGWRwgywAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 17:26:43
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.122.20 (20.122.35.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.122.20 (20.122.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 13:26:36.705393 2026] [security2:error] [pid 22153:tid 22153] [client 34.35.122.20:39224] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "moonlightmotel.com"] [uri "/.git/config"] [unique_id "aqrRTCDmDN6f6PwMpUy03gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 17:09:03
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.122.20 (20.122.35.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.122.20 (20.122.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 13:08:59.786247 2026] [security2:error] [pid 26617:tid 26617] [client 34.35.122.20:51452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "moonfamilies.com"] [uri "/.git/config"] [unique_id "aqrNK53DB8SuKaLZ8u5FygAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-09-16 16:28:11
(11 hours ago)
2026-09-16 18:26:23 GET /.git/config [301] && 2026-09-16 18:26:23 GET /.env [301] && 2026-09-16 18:2 ...
show more
2026-09-16 18:26:23 GET /.git/config [301] && 2026-09-16 18:26:23 GET /.env [301] && 2026-09-16 18:26:25 GET /.env.bak [301] && 175 more within 20 minutes
show less
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-16 16:23:45
(11 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ซ๐ท
Lunix
2026-09-16 16:05:54
(11 hours ago)
Brute-Force
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-16 14:44:40
(12 hours ago)
Web scanning / probing for vulnerable paths | URL: /_phpinfo.php | Evidence: monturista.com 34.35.12 ...
show more
Web scanning / probing for vulnerable paths | URL: /_phpinfo.php | Evidence: monturista.com 34.35.122.20 - - [16/Sep/2026:16:43:58 +0200] \"GET /_phpinfo.php HTTP/1.1\" 404 21764 \"-\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=ZA | ASN: GOOGLE-CLOUD-PLATFORM | Country: ZA
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:59:23
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.122.20 (20.122.35.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.122.20 (20.122.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:59:06.837166 2026] [security2:error] [pid 12504:tid 12504] [client 34.35.122.20:54430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "montgomeryhistoricalsociety.org"] [uri "/.git/config"] [unique_id "aqqgqlIkGL7nIJidQthWSQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:33:06
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.122.20 (20.122.35.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.122.20 (20.122.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:32:58.115663 2026] [security2:error] [pid 21422:tid 21422] [client 34.35.122.20:38504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "monteriggioni.montepulciano.org"] [uri "/.git/config"] [unique_id "aqqailvCr_MY1tVYfAo0ogAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 13:22:20
(14 hours ago)
Flagged as abuse by IisGuard automated detection (tier L5, score 90/100). Reasons: Reputation=1, Bad ...
show more
Flagged as abuse by IisGuard automated detection (tier L5, score 90/100). Reasons: Reputation=1, BadPath=25, Rate=2,1, Diversity=10, CanaryOverride=90.
show less
Web App Attack
DDoS Attack
Bad Web Bot
๐ฌ๐ง
consul.to
2026-09-16 13:20:58
(14 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฎ๐น
VHosting
2026-09-16 13:10:03
(14 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:05:28
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.122.20 (20.122.35.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.122.20 (20.122.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:05:23.500329 2026] [security2:error] [pid 27797:tid 27797] [client 34.35.122.20:60374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "montebiancoltd.com"] [uri "/.git/config"] [unique_id "aqqUE0Jqa850hTvldIzSPAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack