๐ฎ๐ฉ
Burayot
2026-06-09 12:57:06
(43 minutes ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.40.174.96 (AU/Australia/96.174.4 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.40.174.96 (AU/Australia/96.174.40.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 09:57:32
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.40.174.96 (96.174.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.174.96 (96.174.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 05:57:25.577602 2026] [security2:error] [pid 4640:tid 4640] [client 34.40.174.96:48144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.title28.itaxcenter.com"] [uri "/.git/config"] [unique_id "aifjhdYmKjRfXSAg4yqpzAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 08:48:40
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.40.174.96 (96.174.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.174.96 (96.174.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 04:48:36.097107 2026] [security2:error] [pid 11673:tid 11673] [client 34.40.174.96:55180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.secure.centuryabsinthe.com"] [uri "/.git/config"] [unique_id "aifTZCqih7Z7XOP5gCSOnAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 08:02:39
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.40.174.96 (96.174.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.174.96 (96.174.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 04:02:36.371832 2026] [security2:error] [pid 25790:tid 25790] [client 34.40.174.96:34592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "4940brooklinedr.com.13waggoners.com"] [uri "/.git/config"] [unique_id "aifInHjapkUug8S2N1BjhgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 07:33:21
(6 hours ago)
34.40.174.96 - - [09/Jun/2026:07:33:19 +0000] "GET /.git/config HTTP/1.1" 404 49466 "-" "Mozilla/5.0 ...
show more
34.40.174.96 - - [09/Jun/2026:07:33:19 +0000] "GET /.git/config HTTP/1.1" 404 49466 "-" "Mozilla/5.0 (iPad; U; CPU OS 4_3 like Mac OS X; en-us) AppleWebKit/533.17.9 (KHTML, like Gecko) Version/5.0.2 Mobile/8F190 Safari/6533.18.5"
...
show less
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-06-09 06:34:25
(7 hours ago)
[TueJun0908:34:20.1558662026][security2:error][pid3964857:tid3965098][client34.40.174.96:0]ModSecuri ...
show more
[TueJun0908:34:20.1558662026][security2:error][pid3964857:tid3965098][client34.40.174.96:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.labaita-lanzo.it.81-17-25-250.cpanel.site\"][uri\"/.git/config\"][unique_id\"aiez7GxsQ4MrJUs1_JzMAwAAAQQ\"]
show less
Hacking
Web App Attack
๐ญ๐บ
DumaNet
2026-06-09 06:30:00
(7 hours ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Jun 08. 09:24:15
Source IP: 34.40. ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Jun 08. 09:24:15
Source IP: 34.40.174.96
Portion of the log(s):
34.40.174.96 - [08/Jun/2026:09:24:15 +0200] "GET /config/.env.local HTTP/1.1" 404 153 "-" "Mozilla/5.0 (Linux; U; Android 4.1.2; en-us; LG-P870/P87020d Build/JZO54K) AppleWebKit/534.30 (KHTML, like Gecko) Version/4.0 Mobile Safari/534.30"
34.40.174.96 - [08/Jun/2026:09:24:15 +0200] "GET /services/.env.local HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux; Android 9; ONEPLUS A3010) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36"
34.40.174.96 - [08/Jun/2026:09:24:15 +0200] "GET /app/.env.prod HTTP/1.1" 404 555 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 5.1; Trident/4.0; .NET CLR 2.0.50727; .NET CLR 3.0.04506.648; .NET CLR 3.5.21022; .NET CLR 3.0.4506.2152; .NET CLR 3.5.30729)"
34.40.174.96 - [08/Jun/2026:09:24:15 +0200] "GET /app/.env.old HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Linux; Android 4.4.4; XT1032 Build/KXB21.14-L1.61) AppleWebKit
show less
Web App Attack
Anonymous
2026-06-09 06:20:01
(7 hours ago)
suspicious request in access.log
Web App Attack
๐ง๐ท
ludarkstar99
2026-06-09 06:15:24
(7 hours ago)
Blocked by os-abuseipdb; 11 hits, proto=tcp, ports=443,80
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 04:20:48
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.40.174.96 (96.174.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.174.96 (96.174.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 00:20:43.544927 2026] [security2:error] [pid 9099:tid 9099] [client 34.40.174.96:45776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mywheatgrass.com"] [uri "/.git/config"] [unique_id "aieUmyqu1hXUMnfFXhvuEwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
SSH-Admin
2026-06-09 04:00:04
(9 hours ago)
Probing for Exploits on ns200
Exploited Host
Web App Attack
๐ฌ๐ง
Oakley
2026-06-09 03:59:29
(9 hours ago)
(confirmed_bot_sig) Confirmed bot
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 03:35:55
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.40.174.96 (96.174.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.174.96 (96.174.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 23:35:48.245737 2026] [security2:error] [pid 8056:tid 8064] [client 34.40.174.96:38746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pre.ahsdistance.org"] [uri "/.git/config"] [unique_id "aieKFGP-zBC-XHM1teAj6wAAAUY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 01:52:36
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.40.174.96 (96.174.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.174.96 (96.174.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 21:52:31.338041 2026] [security2:error] [pid 6156:tid 6156] [client 34.40.174.96:41710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stocks.nautos-usa.com"] [uri "/.git/config"] [unique_id "aidx3zQ-A4NIAsMiDnUL0gAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-08 22:01:56
(15 hours ago)
Auto-ban: >3000 req/min op 2026-06-08
Web App Attack
SSH
Hacking