๐บ๐ธ
TPI-Abuse
2026-09-27 00:44:13
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.45.12.17 (17.12.45.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.45.12.17 (17.12.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 20:44:08.853711 2026] [security2:error] [pid 32467:tid 32467] [client 34.45.12.17:46064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.therealseska.com"] [uri "/.git/config"] [unique_id "arhm2D89fblLmGCOYsAvnwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 20:18:16
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.45.12.17 (17.12.45.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.45.12.17 (17.12.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 16:18:13.031729 2026] [security2:error] [pid 28158:tid 28158] [client 34.45.12.17:38414] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.agenesis7.com"] [uri "/.git/config"] [unique_id "argohfuD_aj9hSDaJqtnpQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
DEV-DNS
2026-09-26 10:08:09
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-26 10:07:06
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
kbeezie
2026-09-26 09:54:31
(1 day ago)
34.45.12.17 - - [26/Sep/2026:05:54:31 -0400] "GET /tmp/phpinfo.php HTTP/1.1" 429 564 "-" "Mozilla/5. ...
show more
34.45.12.17 - - [26/Sep/2026:05:54:31 -0400] "GET /tmp/phpinfo.php HTTP/1.1" 429 564 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.45.12.17 - - [26/Sep/2026:05:54:31 -0400] "GET /public/phpinfo.php HTTP/1.1" 429 564 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.45.12.17 - - [26/Sep/2026:05:54:31 -0400] "GET /info HTTP/1.1" 429 564 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.45.12.17 - - [26/Sep/2026:05:54:31 -0400] "GET /php-info.php HTTP/1.1" 429 564 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.45.12.17 - - [26/Sep/2026:05:54:31 -0400] "GET /phpversion.php HTTP/1.1" 429 564 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-26 08:28:56
(1 day ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
๐ณ๐ฑ
Site.eu
2026-09-26 07:34:08
(1 day ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
chrisj
2026-09-26 07:26:29
(1 day ago)
[Sat Sep 26 07:26:28.593610 2026] [proxy_fcgi:error] [pid 217055:tid 217082] [client 34.45.12.17:553 ...
show more
[Sat Sep 26 07:26:28.593610 2026] [proxy_fcgi:error] [pid 217055:tid 217082] [client 34.45.12.17:55304] AH01071: Got error 'Primary script unknown'
[Sat Sep 26 07:26:28.638903 2026] [proxy_fcgi:error] [pid 217055:tid 217085] [client 34.45.12.17:55304] AH01071: Got error 'Primary script unknown'
[Sat Sep 26 07:26:28.684018 2026] [proxy_fcgi:error] [pid 217055:tid 217084] [client 34.45.12.17:55304] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-24 20:06:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.45.12.17 (17.12.45.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.45.12.17 (17.12.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 16:06:49.131052 2026] [security2:error] [pid 8625:tid 8625] [client 34.45.12.17:54536] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brtc.us.joshuashands.org"] [uri "/.git/config"] [unique_id "arWC2fO9KsrDAj3FuyN4DAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 19:31:01
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.45.12.17 (17.12.45.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.45.12.17 (17.12.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 15:30:55.211963 2026] [security2:error] [pid 24358:tid 24358] [client 34.45.12.17:43140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brownlegacy.org"] [uri "/.git/config"] [unique_id "arV6b5xfBUyNsOHqxCJx_wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
UltimWeb
2026-09-23 12:04:33
(4 days ago)
Fail2ban_apache-auth
Brute-Force
Web App Attack
๐ฉ๐ช
club77
2026-09-22 10:39:30
(5 days ago)
34.45.12.17 - - [22/Sep/2026:18:39:28 +0800] "GET /.git/config HTTP/1.1" 404 106947 "-" "Mozilla/5.0 ...
show more
34.45.12.17 - - [22/Sep/2026:18:39:28 +0800] "GET /.git/config HTTP/1.1" 404 106947 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.45.12.17 - - [22/Sep/2026:18:39:29 +0800] "GET /.env HTTP/1.1" 404 102855 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.45.12.17 - - [22/Sep/2026:18:39:29 +0800] "GET /.env.local HTTP/1.1" 404 102909 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-09-22 09:15:53
(5 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-21 22:03:19
(5 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-20.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 21:16:08
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.45.12.17 (17.12.45.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.45.12.17 (17.12.45.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:16:02.314457 2026] [security2:error] [pid 2244:tid 2244] [client 34.45.12.17:54818] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "verifiedcasting.com.independentmusicconference.com"] [uri "/.git/config"] [unique_id "arGekhUgWFle05qpB8BEJwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack