🇺🇸
TPI-Abuse
2026-09-03 14:51:54
(12 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.63.203.8 (8.203.63.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.203.8 (8.203.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 10:51:46.429567 2026] [security2:error] [pid 5097:tid 5109] [client 34.63.203.8:8192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "7sons.net"] [uri "/.git/config"] [unique_id "apmJgsb6XT_mx19ZZJR3ygAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 09:43:22
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.63.203.8 (8.203.63.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.203.8 (8.203.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 05:43:15.821165 2026] [security2:error] [pid 31786:tid 31786] [client 34.63.203.8:24456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "title-26.com"] [uri "/.git/config"] [unique_id "aplBMxZTzprkyn2LzvTOwgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-09-03 08:41:53
(6 hours ago)
[ThuSep0310:41:48.5049222026][security2:error][pid2655066:tid2655217][client34.63.203.8:0]ModSecurit ...
show more
[ThuSep0310:41:48.5049222026][security2:error][pid2655066:tid2655217][client34.63.203.8:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"sito-online.ch\"][uri\"/.git/config\"][unique_id\"apkyzNeIMAFILkAleMjSeAAAARM\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 09:23:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.63.203.8 (8.203.63.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.203.8 (8.203.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 05:23:37.756602 2026] [security2:error] [pid 15152:tid 15152] [client 34.63.203.8:34034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zoticus.com"] [uri "/.git/config"] [unique_id "apfrGQU4cxGMXu4VDJwavgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
billfor
2026-09-02 09:11:24
(1 day ago)
34.63.203.8 - - [02/Sep/2026:05:11:21 -0400] "GET /.git/config HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Win ...
show more
34.63.203.8 - - [02/Sep/2026:05:11:21 -0400] "GET /.git/config HTTP/1.1" 404 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
show less
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-01 21:59:51
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-31.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-01 21:04:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.63.203.8 (8.203.63.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.203.8 (8.203.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 17:04:46.524235 2026] [security2:error] [pid 31190:tid 31190] [client 34.63.203.8:58444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sislau.net"] [uri "/.git/config"] [unique_id "apc97urIU6enJG4d2XDI5gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
oisecnet
2026-09-01 21:02:20
(1 day ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-09-01. 237 requests from this ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-09-01. 237 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 15:57:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.63.203.8 (8.203.63.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.203.8 (8.203.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 11:57:48.072507 2026] [security2:error] [pid 14168:tid 14168] [client 34.63.203.8:32830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "messengersforchrist.charity"] [uri "/.git/config"] [unique_id "apb1_NDd_w7ToZnTkZ6CngAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 10:25:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.63.203.8 (8.203.63.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.203.8 (8.203.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:25:04.321889 2026] [security2:error] [pid 24766:tid 24766] [client 34.63.203.8:22670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "integratic.com.co"] [uri "/.git/config"] [unique_id "apaoAEZthSYDyTYJohagDAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 08:29:42
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.63.203.8 (8.203.63.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.203.8 (8.203.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 04:29:35.359548 2026] [security2:error] [pid 13667:tid 13667] [client 34.63.203.8:27998] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "littlehorneng.com"] [uri "/.git/config"] [unique_id "apaM75s5F8SD17kSLKfgKwAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
HERA - Operations
2026-09-01 04:55:31
(2 days ago)
club-herrmann - searching for vulnerable scripts: config 2026/09/01 06:55:31
Web App Attack
🇩🇪
Jochen Pretli
2026-09-01 03:31:14
(2 days ago)
connection to honeypot
Email Spam
Port Scan
Anonymous
2026-08-31 16:32:02
(2 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇺🇸
TPI-Abuse
2026-08-31 15:26:53
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.63.203.8 (8.203.63.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.63.203.8 (8.203.63.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 11:26:47.008843 2026] [security2:error] [pid 25111:tid 25111] [client 34.63.203.8:50552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "raaksystems.com"] [uri "/.git/config"] [unique_id "apWdN-rponCEv8HbxpAejgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack