๐บ๐ธ
TPI-Abuse
2026-09-29 09:16:31
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.63.127.137 (137.127.63.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.127.137 (137.127.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 05:16:23.702598 2026] [security2:error] [pid 20043:tid 20043] [client 34.63.127.137:52784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "totenclaus.es"] [uri "/.git/config"] [unique_id "aruB58YksX25OMdzgK7EQQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-29 07:21:47
(1 week ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 06:57:18
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.63.127.137 (137.127.63.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.127.137 (137.127.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 02:57:12.000792 2026] [security2:error] [pid 20469:tid 20553] [client 34.63.127.137:46970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "totalservicesandmorellc.com"] [uri "/.git/config"] [unique_id "arthSGJfdbLHCwMx9ffLjAAAAMc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-28 22:00:52
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-27.
show less
Web App Attack
SSH
Hacking
๐ง๐ช
cmbplf
2026-09-27 08:08:59
(1 week ago)
35.260 requests in 1 hour (2mos2w6d)
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-09-27 07:24:46
(1 week ago)
20 attempts against mh-misbehave-ban on choy
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-27 07:15:03
(1 week ago)
Bot / scanning and/or hacking attempts: GET /.env.backup HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.en ...
show more
Bot / scanning and/or hacking attempts: GET /.env.backup HTTP/1.1, GET /.env.prod HTTP/1.1, GET /.env.ci HTTP/1.1, GET /.env.remote HTTP/1.1, GET /.env.test HTTP/1.1, GET /.env.docker HTTP/1.1, GET /.env.live HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env.stage HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.preprod HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.staging HTTP/1.1, GET /.env.development HTTP/1.1, GET /.env.sample HTTP/1.1, GET /.env.old HTTP/1.1, GET / HTTP/1.1
show less
Hacking
Web App Attack
๐ง๐ท
Halux
2026-09-27 06:19:02
(1 week ago)
34.63.127.137 Probing protected path or service
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 20:27:52
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.63.127.137 (137.127.63.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.127.137 (137.127.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 16:27:48.620577 2026] [security2:error] [pid 1900:tid 1900] [client 34.63.127.137:46116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cowetaappliance.com"] [uri "/.git/config"] [unique_id "argqxN4cbTiq01gFdVo1DAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 14:11:39
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.63.127.137 (137.127.63.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.127.137 (137.127.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 10:11:32.404057 2026] [security2:error] [pid 19853:tid 19853] [client 34.63.127.137:57128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "36sovereignchambers.com"] [uri "/.git/config"] [unique_id "araBFP_zcdOqIatfcrIhUwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 13:56:07
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.63.127.137 (137.127.63.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.127.137 (137.127.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 09:56:02.210141 2026] [security2:error] [pid 11264:tid 11264] [client 34.63.127.137:53248] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "36quant.com"] [uri "/.git/config"] [unique_id "arZ9cgjKkvpWr6jmIqjR6QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 18:56:18
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.63.127.137 (137.127.63.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.127.137 (137.127.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:56:12.863388 2026] [security2:error] [pid 11231:tid 11231] [client 34.63.127.137:38764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.arcticwarriors.org"] [uri "/.git/config"] [unique_id "arVyTK3rfE813CEAHu8CpgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-09-24 17:23:04
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted] 34.63.127.137 (US/United States/Iowa/Co ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.63.127.137 (US/United States/Iowa/Council Bluffs/137.127.63.34.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
big-cloud.nl
2026-09-21 18:49:31
(2 weeks ago)
Try to access /.git/config
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-21 15:50:08
(2 weeks ago)
Excessive 404/403 errors
Brute-Force