🇺🇸
TPI-Abuse
2026-09-01 11:21:53
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 34.47.80.110 (110.80.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.47.80.110 (110.80.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 07:21:49.373956 2026] [security2:error] [pid 17223:tid 17223] [client 34.47.80.110:36376] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "omronparts.com"] [uri "/.git/config"] [unique_id "apa1TfUAOB5MPAGSZt-XCgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
voormedia
2026-09-01 11:20:38
(1 week ago)
Accessed trap at '/.git/config'
Web App Attack
🇳🇱
ipoac.nl
2026-09-01 11:18:08
(1 week ago)
-:443 34.47.80.110 - - [01/Sep/2026:13:18:06 +0200] - "GET /.git/config HTTP/1.1" 404 1968 "-" "Mozi ...
show more
-:443 34.47.80.110 - - [01/Sep/2026:13:18:06 +0200] - "GET /.git/config HTTP/1.1" 404 1968 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Bad Web Bot
🇺🇦
URAN Publishing Service
2026-09-01 10:40:36
(2 weeks ago)
[01/Sep/2026:13:40:36 +0300] -- 34.47.80.110 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/ ...
show more
[01/Sep/2026:13:40:36 +0300] -- 34.47.80.110 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 09:16:18
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.47.80.110 (110.80.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.80.110 (110.80.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:16:14.401635 2026] [security2:error] [pid 2032:tid 2032] [client 34.47.80.110:36566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "omnithermal.com"] [uri "/.git/config"] [unique_id "apaX3sNLx55q2Cc_dBvCSAAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-01 07:11:47
(2 weeks ago)
(mod_security-custom) mod_security (id:210492) triggered by 34.47.80.110 (KR/South Korea/Seoul/Yongs ...
show more
(mod_security-custom) mod_security (id:210492) triggered by 34.47.80.110 (KR/South Korea/Seoul/Yongsan-dong/110.80.47.34.bc.googleusercontent.com/[AS396982 GOOGLE-CLOUD-PLATFORM]): 1 in the last 3600 secs (0-srv1)
show less
Hacking
Anonymous
2026-09-01 02:02:16
(2 weeks ago)
Banned by Fail2Ban on server
Web App Attack
🇺🇸
TPI-Abuse
2026-08-31 15:42:07
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.47.80.110 (110.80.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.80.110 (110.80.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 11:42:01.082187 2026] [security2:error] [pid 10411:tid 10411] [client 34.47.80.110:48712] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ourhotmail.com"] [uri "/.git/config"] [unique_id "apWgycq1CowXhAO2-x3fHgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-08-31 11:45:03
(2 weeks ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇨🇦
Dunham Support
2026-08-31 11:39:28
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted] 34.47.80.110 (KR/South Korea/110.80.47. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.47.80.110 (KR/South Korea/110.80.47.34.bc.googleusercontent.com)
show less
SQL Injection
🇩🇪
Manuel Braeuer
2026-08-31 11:09:08
(2 weeks ago)
34.47.80.110 - - [31/Aug/2026:13:09:07 +0200] "GET /.git/config HTTP/1.1" 403 6257 "-" "Mozilla/5.0 ...
show more
34.47.80.110 - - [31/Aug/2026:13:09:07 +0200] "GET /.git/config HTTP/1.1" 403 6257 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.47.80.110 - - [31/Aug/2026:13:09:07 +0200] "GET /.env HTTP/1.1" 403 6257 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.47.80.110 - - [31/Aug/2026:13:09:07 +0200] "GET /.env.local HTTP/1.1" 403 6257 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.47.80.110 - - [31/Aug/2026:13:09:08 +0200] "GET /.env.production HTTP/1.1" 403 6257 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.47.80.110 - - [31/Aug/2026:13:09:08 +0200] "GET /.env.staging HTTP/1.1" 403 6257 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
...
show less
Web App Attack
🇳🇱
Site.eu
2026-08-31 09:49:27
(2 weeks ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-08-31 07:21:07
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.47.80.110 (110.80.47.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.80.110 (110.80.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 03:21:01.371900 2026] [security2:error] [pid 372:tid 372] [client 34.47.80.110:35142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "otcraftworks.com"] [uri "/.git/config"] [unique_id "apUrXXigiDcQYsQU1w0P3QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
kkw
2026-08-31 06:26:38
(2 weeks ago)
[REDACTED] 34.47.80.110 - - [31/Aug/2026:08:26:37 +0200] "GET /.git/config HTTP/1.1" 401 793 "-" "Mo ...
show more
[REDACTED] 34.47.80.110 - - [31/Aug/2026:08:26:37 +0200] "GET /.git/config HTTP/1.1" 401 793 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-08-31 05:00:03
(2 weeks ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack