๐บ๐ธ
TPI-Abuse
2026-10-02 15:40:26
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.7.172.143 (143.172.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.172.143 (143.172.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:40:22.793978 2026] [security2:error] [pid 1132575:tid 1132575] [client 34.7.172.143:43492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asburys.org"] [uri "/.htpasswd"] [unique_id "ar_QZvpS8m3gQnE6TEGu-QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Campus France
2026-10-02 14:52:26
(1 week ago)
[Fri Oct 02 16:52:25.511831 2026] [php:error] [pid 3980840] [client 34.7.172.143:36444] script '/var ...
show more
[Fri Oct 02 16:52:25.511831 2026] [php:error] [pid 3980840] [client 34.7.172.143:36444] script '/var/www/html/brume.org/document.php' not found or unable to stat
[Fri Oct 02 16:52:26.371343 2026] [php:error] [pid 3980762] [client 34.7.172.143:36468] script '/var/www/html/brume.org/test.php' not found or unable to stat
[Fri Oct 02 16:52:26.387482 2026] [php:error] [pid 3980775] [client 34.7.172.143:36516] script '/var/www/html/brume.org/info.php' not found or unable to stat
[Fri Oct 02 16:52:26.388054 2026] [php:error] [pid 3980853] [client 34.7.172.143:36496] script '/var/www/html/brume.org/phpinfo.php' not found or unable to stat
[Fri Oct 02 16:52:26.392158 2026] [php:error] [pid 3980762] [client 34.7.172.143:36468] script '/var/www/html/brume.org/pi.php' not found or unable to stat
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 14:20:17
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.7.172.143 (143.172.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.172.143 (143.172.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:20:03.532447 2026] [security2:error] [pid 547:tid 547] [client 34.7.172.143:55418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aceshd.mroxygen.org"] [uri "/.htpasswd"] [unique_id "ar-9k3Qh0GG-5hk4ONkORAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
U.N.Owen
2026-10-02 13:34:39
(1 week ago)
34.7.172.143 - - [02/Oct/2026:16:34:38 +0300] "GET /w3gdnz36mf67mnq90p6r HTTP/2.0" 404 5366 "-" "Moz ...
show more
34.7.172.143 - - [02/Oct/2026:16:34:38 +0300] "GET /w3gdnz36mf67mnq90p6r HTTP/2.0" 404 5366 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
34.7.172.143 - - [02/Oct/2026:16:34:38 +0300] "GET /0zajk1lu36jpyfszmu9o HTTP/2.0" 404 5366 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
34.7.172.143 - - [02/Oct/2026:16:34:38 +0300] "GET /manifest.json HTTP/2.0" 404 5366 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.7.172.143 - - [02/Oct/2026:16:34:38 +0300] "GET /static/manifest.json HTTP/2.0" 404 5366 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.7.172.143 - - [02/Oct/2026:16:34:38 +0300] "GET /asset-manifest.json HTTP/2.0" 404 5366 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
34.7.172.143
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 11:28:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.7.172.143 (143.172.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.172.143 (143.172.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:28:00.848028 2026] [security2:error] [pid 15716:tid 15716] [client 34.7.172.143:33810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "allisonstiles.org"] [uri "/.htpasswd"] [unique_id "ar-VQOJ-Ey0HqLmvaGwnaQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 10:39:55
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.7.172.143 (143.172.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.172.143 (143.172.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 06:39:50.758259 2026] [security2:error] [pid 18915:tid 18915] [client 34.7.172.143:55758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.arcticwarriors.org"] [uri "/.env.js"] [unique_id "ar-J9pqKcRKCPYqbwnpkVwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 08:30:06
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.7.172.143 (143.172.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.172.143 (143.172.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 04:29:59.450162 2026] [security2:error] [pid 23532:tid 23532] [client 34.7.172.143:60000] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flinthillsveterans.org"] [uri "/.htpasswd"] [unique_id "ar9rh9IKwuJz6JTr72wxSgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
melroy89
2026-10-02 08:20:07
(1 week ago)
2026/10/02 10:20:06 [error] 1985743#1985743: *323884 limiting requests, excess: 5.914 by zone "ip", ...
show more
2026/10/02 10:20:06 [error] 1985743#1985743: *323884 limiting requests, excess: 5.914 by zone "ip", client: "34.7.172.143", server: "_", request_line: "GET /constants.js HTTP/1.1", host: "build.melroy.org"
2026/10/02 10:20:06 [error] 1985743#1985743: *323884 limiting requests, excess: 5.776 by zone "ip", client: "34.7.172.143", server: "_", request_line: "GET /credentials.js HTTP/1.1", host: "build.melroy.org"
2026/10/02 10:20:06 [error] 1985743#1985743: *323884 limiting requests, excess: 5.677 by zone "ip", client: "34.7.172.143", server: "_", request_line: "GET /config.json.js HTTP/1.1", host: "build.melroy.org"
...
show less
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-10-02 08:06:53
(1 week ago)
34.7.172.143 - - [02/Oct/2026:09:06:51 +0100] "GET /model/info HTTP/1.1" 404 53854 "-" "Mozilla/5.0 ...
show more
34.7.172.143 - - [02/Oct/2026:09:06:51 +0100] "GET /model/info HTTP/1.1" 404 53854 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 07:49:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.7.172.143 (143.172.7.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.7.172.143 (143.172.7.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 03:49:43.644489 2026] [security2:error] [pid 12552:tid 12574] [client 34.7.172.143:39320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amphoracollectors.org"] [uri "/@fs/app/.env"] [unique_id "ar9iFwo8ostI5-e8PHQinwAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-10-02 07:25:03
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-10-02 07:21:57
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ซ๐ฎ
Kotisivu.org
2026-10-02 07:01:45
(1 week ago)
Automated web scanner probe: GET /.ssh/id_ed25519 on status.kotisivu.org.
Brute-Force
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-10-02 06:38:01
(1 week ago)
2026-10-02 08:36:53 GET /__/firebase/init.json [301] && 2026-10-02 08:36:53 GET /ngsw.json [301] && ...
show more
2026-10-02 08:36:53 GET /__/firebase/init.json [301] && 2026-10-02 08:36:53 GET /ngsw.json [301] && 2026-10-02 08:36:54 GET /config.json [301] && 238 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
dot.mg
2026-10-02 06:35:02
(1 week ago)
Bad behaviour
Web Spam