🇺🇸
TPI-Abuse
2026-09-11 12:08:32
(53 seconds ago)
(mod_security) mod_security (id:210492) triggered by 34.35.168.115 (115.168.35.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.168.115 (115.168.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 08:08:25.739973 2026] [security2:error] [pid 31743:tid 31743] [client 34.35.168.115:35786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "natural-history-conservation.com"] [uri "/.git/config"] [unique_id "aqPvOSNGzAHOaSLZbMtcfQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 10:17:12
(1 hour ago)
Scanner hitting /.git/config on nats-0.osef.cloud (GOOGL-2) — aaguard
Brute-Force
Port Scan
Anonymous
2026-09-11 09:53:46
(2 hours ago)
34.35.168.115 - - [11/Sep/2026:11:53:41 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linu ...
show more
34.35.168.115 - - [11/Sep/2026:11:53:41 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.35.168.115 - - [11/Sep/2026:11:53:42 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.35.168.115 - - [11/Sep/2026:11:53:42 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.35.168.115 - - [11/Sep/2026:11:53:42 +0200] "GET /.git/config HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.35.168.115 - - [11/Sep/2026:11:53:43 +0200] "GET /.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.35.168.115 - - [11/Sep/2026:11:53:43 +0200] "GET /.env.local HTTP/1.1" 403 183
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 09:20:05
(2 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.local HTTP/1.1, GET /.env.staging HTTP/1.1, POST / ...
show more
Bot / scanning and/or hacking attempts: GET /.env.local HTTP/1.1, GET /.env.staging HTTP/1.1, POST / HTTP/1.1, GET /.git/config HTTP/1.1, GET /.env HTTP/1.1, GET /.env.production HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 08:41:44
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.168.115 (115.168.35.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.168.115 (115.168.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 04:41:37.335083 2026] [security2:error] [pid 5542:tid 5576] [client 34.35.168.115:48754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nativeamericantimeline.philacentric.com"] [uri "/.git/config"] [unique_id "aqO-wdQu3Ff9ZK7A7tqSoQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 07:56:35
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.168.115 (115.168.35.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.168.115 (115.168.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 03:56:30.577590 2026] [security2:error] [pid 1818796:tid 1819621] [client 34.35.168.115:56572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nationsrecovery.com"] [uri "/.git/config"] [unique_id "aqO0LhjxZJ4jL5ekSswaRgAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-11 06:04:12
(6 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 3s
Web App Attack
🇺🇸
nationaleventpros.com
2026-09-11 05:56:46
(6 hours ago)
vulnerability scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 05:54:02
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.168.115 (115.168.35.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.168.115 (115.168.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 01:53:54.167290 2026] [security2:error] [pid 30076:tid 30076] [client 34.35.168.115:57584] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nationalenq.com"] [uri "/.git/config"] [unique_id "aqOXctjNmXC4WxNT1X7b1AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-11 05:48:14
(6 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-11 05:11:40
(6 hours ago)
34.35.168.115 - - [11/Sep/2026:07:11:30 +0200] "GET /.git/config HTTP/1.1" 403 623 "-" "Mozilla/5.0 ...
show more
34.35.168.115 - - [11/Sep/2026:07:11:30 +0200] "GET /.git/config HTTP/1.1" 403 623 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.35.168.115 - - [11/Sep/2026:07:11:30 +0200] "GET /.git/config HTTP/1.1" 403 622 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.35.168.115 - - [11/Sep/2026:07:11:31 +0200] "GET /.env HTTP/1.1" 403 623 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.35.168.115 - - [11/Sep/2026:07:11:31 +0200] "GET /.env HTTP/1.1" 403 622 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.35.168.115 - - [11/Sep/2026:07:11:31 +0200] "GET /.env.local HTTP/1.1" 403 623 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.35.168.11
...
show less
DDoS Attack
🇧🇪
cmbplf
2026-09-11 04:34:08
(7 hours ago)
8.007 requests with url.path *.env
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 04:22:03
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.168.115 (115.168.35.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.168.115 (115.168.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 00:21:58.568790 2026] [security2:error] [pid 32175:tid 32175] [client 34.35.168.115:40000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nathsharmaandcompany.com"] [uri "/.git/config"] [unique_id "aqOB5sueHmJOWX6ue-JO2wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 03:20:29
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.35.168.115 (115.168.35.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.35.168.115 (115.168.35.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 23:20:23.183557 2026] [security2:error] [pid 18493:tid 18493] [client 34.35.168.115:42970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nathanburd.com"] [uri "/.git/config"] [unique_id "aqNzd2VCQRi4mbu3yCnjIAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-11 03:12:53
(8 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack