🇺🇸
TPI-Abuse
2026-09-08 10:08:15
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.106.115 (115.106.50.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.106.115 (115.106.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 06:08:11.427978 2026] [security2:error] [pid 20409:tid 20409] [client 34.50.106.115:35686] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "robbieburnsnight.com"] [uri "/.git/config"] [unique_id "ap_ei3BOlssYIWRiQwU7BwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:14:50
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.106.115 (115.106.50.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.106.115 (115.106.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:14:44.470512 2026] [security2:error] [pid 16323:tid 16323] [client 34.50.106.115:35972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rocketcityhotwheelers.com"] [uri "/.git/config"] [unique_id "ap_SBMjdmkEvrcYvhhqJCQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 04:54:49
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.50.106.115 (115.106.50.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.106.115 (115.106.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:54:43.110919 2026] [security2:error] [pid 11173:tid 11200] [client 34.50.106.115:57478] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rockabyecotons.com"] [uri "/.git/config"] [unique_id "ap-VExBMchdiXlqovH2yvQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-08 03:33:00
(20 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇺🇸
wteiken
2026-09-08 03:25:47
(20 hours ago)
rocinante.teiken.net:443 34.50.106.115:37246 - - [07/Sep/2026:23:25:44 -0400] "GET /.git/config HTTP ...
show more
rocinante.teiken.net:443 34.50.106.115:37246 - - [07/Sep/2026:23:25:44 -0400] "GET /.git/config HTTP/1.1" 404 561 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
rocinante.teiken.net:443 34.50.106.115:37246 - - [07/Sep/2026:23:25:45 -0400] "GET /.env HTTP/1.1" 404 561 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
rocinante.teiken.net:443 34.50.106.115:37246 - - [07/Sep/2026:23:25:45 -0400] "GET /.env.local HTTP/1.1" 404 561 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
rocinante.teiken.net:443 34.50.106.115:37246 - - [07/Sep/2026:23:25:46 -0400] "GET /.env.production HTTP/1.1" 404 561 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
rocinante.teiken.net:443 34.50.106.115:37246 - - [07
...
show less
Web App Attack
🇫🇷
Octopuce
2026-09-08 03:18:43
(20 hours ago)
Aggressive web search of vulnerable pages: / /.env /.env.local /app/.env /apps/.env ...
Web App Attack
🇬🇧
consul.to
2026-09-08 02:24:15
(21 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇧🇷
Halux
2026-09-08 01:31:27
(22 hours ago)
34.50.106.115 Probing protected path or service
Web App Attack
🇦🇺
screwlooseit.com.au
2026-09-08 00:42:31
(22 hours ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/115.106.50.34.bc.googleuserconten ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/115.106.50.34.bc.googleusercontent.com
show less
Web App Attack
🇺🇸
brightenfield
2026-09-08 00:37:12
(23 hours ago)
Web App Attack
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-07 23:45:08
(23 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-09-07 23:42:57
(23 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.50.106.115 (ID/Indonesia/115.106.50. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.50.106.115 (ID/Indonesia/115.106.50.34.bc.googleusercontent.com)
show less
SQL Injection
🇳🇱
Site.eu
2026-09-07 22:37:33
(1 day ago)
Excessive 404/403 errors
Brute-Force
🇳🇱
Mangelot Hosting
2026-09-07 22:37:26
(1 day ago)
(php_susp_dir) srv103 PHP Suspicious Directory 34.50.106.115 (ID/Indonesia/115.106.50.34.bc.googleus ...
show more
(php_susp_dir) srv103 PHP Suspicious Directory 34.50.106.115 (ID/Indonesia/115.106.50.34.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 21:50:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.50.106.115 (115.106.50.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.50.106.115 (115.106.50.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 17:50:27.063944 2026] [security2:error] [pid 2462391:tid 2462391] [client 34.50.106.115:41312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "robstax.com.cctaxpro.com"] [uri "/.git/config"] [unique_id "ap8xo0nKAIaTjaz7scVR4wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack