🇺🇸
TPI-Abuse
2026-09-11 11:09:45
(15 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.65.75.220 (220.75.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.75.220 (220.75.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 07:09:38.934644 2026] [security2:error] [pid 489:tid 489] [client 34.65.75.220:40532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "susansambou.org"] [uri "/.git/config"] [unique_id "aqPhco-W9ZnhFCMW5tBeuAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 10:37:13
(47 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.65.75.220 (220.75.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.75.220 (220.75.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 06:37:10.192101 2026] [security2:error] [pid 30163:tid 30163] [client 34.65.75.220:50120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "susanleeward.com"] [uri "/.git/config"] [unique_id "aqPZ1rSOAV6TVKD--3lDbAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-11 09:30:03
(1 hour ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇩🇪
marten_o
2026-09-11 09:25:00
(1 hour ago)
34.65.75.220 - - [11/Sep/2026:11:25:00 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 500 574 "-" "Mozilla/5 ...
show more
34.65.75.220 - - [11/Sep/2026:11:25:00 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 500 574 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 421 772
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 08:25:41
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.75.220 (220.75.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.75.220 (220.75.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 04:25:33.606742 2026] [security2:error] [pid 25331:tid 25331] [client 34.65.75.220:49096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "surviquo.com"] [uri "/.git/config"] [unique_id "aqO6_XsRxgo63t2BwMG-AgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 06:52:27
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.75.220 (220.75.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.75.220 (220.75.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 02:52:21.164148 2026] [security2:error] [pid 7007:tid 7007] [client 34.65.75.220:44162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "survey.joebankx.com"] [uri "/.git/config"] [unique_id "aqOlJdZ86aaJFIRMXogHrAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Vegascosmetics
2026-09-11 05:06:36
(6 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 85>=65, Abuse 100, NonEU, first-seen)
show less
Hacking
Exploited Host
Web App Attack
🇫🇷
Octopuce
2026-09-11 04:29:23
(6 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
🇪🇸
pipeline.es
2026-09-11 04:15:38
(7 hours ago)
Web scanning / probing for vulnerable paths | URL: /cms/.env | Evidence: altovolta.es 34.65.75.220 - ...
show more
Web scanning / probing for vulnerable paths | URL: /cms/.env | Evidence: altovolta.es 34.65.75.220 - - [11/Sep/2026:06:15:25 +0200] \"GET /cms/.env HTTP/1.1\" 404 206 \"-\" \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=CH | ASN: GOOGLE-CLOUD-PLATFORM | Country: CH
show less
Port Scan
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-11 03:59:13
(7 hours ago)
[11/Sep/2026:06:59:13 +0300] -- 34.65.75.220 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/ ...
show more
[11/Sep/2026:06:59:13 +0300] -- 34.65.75.220 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 02:37:35
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.65.75.220 (220.75.65.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.65.75.220 (220.75.65.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 22:37:28.857526 2026] [security2:error] [pid 3450:tid 3450] [client 34.65.75.220:40060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "surfsideautomotive.com.rosemeadefarms.com"] [uri "/.git/config"] [unique_id "aqNpaNeEHCMaBJk7MZLqRQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
maxxsense
2026-09-10 13:29:52
(21 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.65.75.220 (CH/Switzerland/220.75.65. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.65.75.220 (CH/Switzerland/220.75.65.34.bc.googleusercontent.com)
show less
SQL Injection
🇬🇧
Aetherweb Ark
2026-09-10 12:11:27
(23 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.65.75.220 (CH/Switzerland/220.75.65.34.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 34.65.75.220 (CH/Switzerland/220.75.65.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇬🇧
consul.to
2026-09-10 11:46:23
(23 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-10 10:50:23
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking