πΊπΈ
TPI-Abuse
2026-06-15 09:41:57
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.40.201.45 (45.201.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.201.45 (45.201.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 05:41:53.655301 2026] [security2:error] [pid 2508:tid 2526] [client 34.40.201.45:47142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.proto.wizart.org"] [uri "/www/.git/config"] [unique_id "ai_I4UKDQsymwr7jQkUrkAAAAI4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-06-15 09:28:03
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 07:20:14
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.40.201.45 (45.201.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.201.45 (45.201.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 03:20:09.190066 2026] [security2:error] [pid 17770:tid 17770] [client 34.40.201.45:56840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jambmaster.com"] [uri "/.git/config"] [unique_id "ai-nqffd5kJnEVY6Vm-exAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Petros Stefanakis
2026-06-15 07:05:05
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.40.201.45 (AU/Australia/45.201.40.34 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.40.201.45 (AU/Australia/45.201.40.34.bc.googleusercontent.com)
show less
SQL Injection
π΅π±
jekob
2026-06-15 07:04:10
(3 days ago)
Automated malicious activity detected (6 events)
Hacking
Web App Attack
π©πͺ
4server
2026-06-15 06:57:38
(3 days ago)
[MonJun1508:57:32.4260952026][security2:error][pid3921116:tid3921138][client34.40.201.45:0]ModSecuri ...
show more
[MonJun1508:57:32.4260952026][security2:error][pid3921116:tid3921138][client34.40.201.45:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.martinairsagl.ch.136-243-54-122.cpanel.site\"][uri\"/.git/config\"][unique_id\"ai-iXDRj6IUSlEDyt8bM3gAAARM\"]
show less
Port Scan
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 04:32:42
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.40.201.45 (45.201.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.201.45 (45.201.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 00:32:36.071277 2026] [security2:error] [pid 18011:tid 18011] [client 34.40.201.45:53070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rocklundtechnology.brenna-droege.com"] [uri "/.git/config"] [unique_id "ai-AZIYOsJ4nZkblxRyewwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
gadix
2026-06-15 04:12:04
(3 days ago)
[15/Jun/2026:06:12:03.634076 +0200] ai97k5osKmxwxOENSzU6RwAAABE 34.40.201.45 52456 127.0.0.1 7081
[1 ...
show more
[15/Jun/2026:06:12:03.634076 +0200] ai97k5osKmxwxOENSzU6RwAAABE 34.40.201.45 52456 127.0.0.1 7081
[15/Jun/2026:06:12:03.662531 +0200] ai97k5osKmxwxOENSzU6SAAAAAw 34.40.201.45 52466 127.0.0.1 7081
[15/Jun/2026:06:12:03.665545 +0200] ai97k5osKmxwxOENSzU6SQAAAAU 34.40.201.45 52480 127.0.0.1 7081
...
show less
Web App Attack
π©πͺ
stinpriza
2026-06-15 04:10:53
(3 days ago)
common Web Exploits being scanned
Web App Attack
π³π±
debestelapp
2026-06-15 04:00:10
(3 days ago)
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 03:44:21
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.40.201.45 (45.201.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.201.45 (45.201.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 23:44:14.733084 2026] [security2:error] [pid 29696:tid 29696] [client 34.40.201.45:33410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mcdonaldmooreshootingsports.effectivefirearms.com"] [uri "/api/.git/config"] [unique_id "ai91DmKg8ePg4E0eF6MTmgAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Mangelot Hosting
2026-06-15 03:06:17
(3 days ago)
(modsecurity) srv102 ModSecurity 34.40.201.45 (AU/Australia/45.201.40.34.bc.googleusercontent.com): ...
show more
(modsecurity) srv102 ModSecurity 34.40.201.45 (AU/Australia/45.201.40.34.bc.googleusercontent.com): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 03:01:44
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.40.201.45 (45.201.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.201.45 (45.201.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 23:01:38.609861 2026] [security2:error] [pid 32537:tid 32537] [client 34.40.201.45:60558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.valuerec.jmarkcapital.com"] [uri "/build/.git/config"] [unique_id "ai9rEhtgQ8EiEAZUQm3u1gAAAG0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-06-15 02:24:49
(3 days ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-06-15 02:06:07
(3 days ago)
Scanning/Probing (30)
Brute-Force
Web App Attack