🇫🇷
Octopuce
2026-09-07 02:27:44
(3 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 02:00:23
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.76.170.79 (79.170.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.170.79 (79.170.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 22:00:19.797020 2026] [security2:error] [pid 11493:tid 11493] [client 34.76.170.79:58930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stewarttaylor.com"] [uri "/.git/config"] [unique_id "ap4asybGySGp0fqsPTXu2gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 01:29:02
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.76.170.79 (79.170.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.170.79 (79.170.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 21:28:58.153365 2026] [security2:error] [pid 1298769:tid 1298836] [client 34.76.170.79:60602] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stewardship360.com"] [uri "/.git/config"] [unique_id "ap4TWuzpUE8uChzG_TzQ6QAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-07 01:09:40
(4 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 00:21:42
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.76.170.79 (79.170.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.170.79 (79.170.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 20:21:36.580816 2026] [security2:error] [pid 15832:tid 15832] [client 34.76.170.79:58014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stevescottcoaching.com"] [uri "/.git/config"] [unique_id "ap4DkBARtjoAMT7jiUbrogAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇿
Antinson
2026-09-07 00:07:13
(6 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
🇩🇪
Nightreaver
2026-09-06 22:10:03
(7 hours ago)
34.76.170.79 - - [07/Sep/2026:00:10:02 0200] "GET /.env.production HTTP/1.1" 404 518 "-" "Mozilla/5 ...
show more
34.76.170.79 - - [07/Sep/2026:00:10:02 0200] "GET /.env.production HTTP/1.1" 404 518 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.76.170.79 - - [07/Sep/2026:00:10:03 0200] "GET /.env.staging HTTP/1.1" 404 518 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.76.170.79 - - [07/Sep/2026:00:10:03 0200] "GET /.env.development HTTP/1.1" 404 518 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.76.170.79 - - [07/Sep/2026:00:10:03 0200] "GET /.env.test HTTP/1.1" 404 518 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.76.170.79 - - [07/Sep/2026:00:10:03 0200] "GET /.env.remote HTTP/1.1" 404 518 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"[...]
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 20:49:29
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.76.170.79 (79.170.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.170.79 (79.170.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:49:24.588356 2026] [security2:error] [pid 24734:tid 24734] [client 34.76.170.79:37508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stevedegroodt.com"] [uri "/.git/config"] [unique_id "ap3R1JfcBR8oEeXkHczFhAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
grassau.com
2026-09-06 18:40:43
(11 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.76.170.79 (BE/Belgium/Brussels Capit ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.76.170.79 (BE/Belgium/Brussels Capital/Brussels/79.170.76.34.bc.googleusercontent.com)
show less
SQL Injection
🇳🇱
Site.eu
2026-09-06 18:27:40
(11 hours ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 17:24:24
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.76.170.79 (79.170.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.170.79 (79.170.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 13:24:19.566445 2026] [security2:error] [pid 21140:tid 21140] [client 34.76.170.79:46974] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sternscape.com"] [uri "/.git/config"] [unique_id "ap2hwxPtLdYvFZCVy6cWQAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Mangelot Hosting
2026-09-06 16:50:36
(13 hours ago)
(modsecurity) srv104 ModSecurity 34.76.170.79 (BE/Belgium/79.170.76.34.bc.googleusercontent.com): 30 ...
show more
(modsecurity) srv104 ModSecurity 34.76.170.79 (BE/Belgium/79.170.76.34.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
🇧🇪
cmbplf
2026-09-06 15:41:41
(14 hours ago)
12.215 requests with url.path *.env
201 requests with url.path *.php.bak
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 15:20:17
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.76.170.79 (79.170.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.170.79 (79.170.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:20:12.273978 2026] [security2:error] [pid 21557:tid 21557] [client 34.76.170.79:57048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sterlingandtime.com"] [uri "/.git/config"] [unique_id "ap2ErLCV3C_TFG-DdAwoeAAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-06 15:07:10
(15 hours ago)
Multiple WAF Violations
Web App Attack