๐บ๐ธ
TPI-Abuse
2026-10-03 00:19:38
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.76.91.169 (169.91.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.91.169 (169.91.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 20:19:32.462108 2026] [security2:error] [pid 20877:tid 20877] [client 34.76.91.169:56336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.millergrain.com"] [uri "/.env"] [unique_id "asBKFJFCeyHcUcepMuLgtgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-10-01 02:24:25
(2 days ago)
812 limiting connections by zone (9m59s)
DDoS Attack
๐ฉ๐ช
4server
2026-10-01 01:27:35
(2 days ago)
[ThuOct0103:27:30.8618102026][security2:error][pid288359:tid288371][client34.76.91.169:0]ModSecurity ...
show more
[ThuOct0103:27:30.8618102026][security2:error][pid288359:tid288371][client34.76.91.169:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"serban.ch\"][uri\"/.git/HEAD\"][unique_id\"ar23AmrBtF-EBHWLc-bv3wAAAAE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ช๐ธ
bohl-aiG5aef
2026-10-01 00:26:47
(2 days ago)
Suricata Alert [SID:2031502] ET INFO Request to Hidden Environment File - Inbound
Hacking
๐ณ๐ฑ
Alt255
2026-09-30 19:39:52
(2 days ago)
[ti-10al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-10al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 34.76.91.169 - - [30/Sep/2026:21:39:49 +0200] "GET /.vite/manifest.json HTTP/1.1" 404 7873 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.76.91.169 - - [30/Sep/2026:21:39:49 +0200] "GET /_nuxt/manifest.json HTTP/1.1" 404 7873 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.76.91.169 - - [30/Sep/2026:21:39:49 +0200] "GET /runtime-config.json HTTP/1.1" 404 7873 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.76.91.169 - - [30/Sep/2026:21:39:49 +0200] "GET /stats.json HTTP/1.1" 404 7873 "-"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-30 09:19:10
(2 days ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.76.91.169 - - [30/Sep/2026:11:18:59 +0200] "GET /wp-config.php.bak HTTP/1.1" 404 14991 "-" "Mozilla/5.0 (compatible; scanner/1.0)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 03:44:11
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.76.91.169 (169.91.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.91.169 (169.91.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:44:07.844957 2026] [security2:error] [pid 16996:tid 17008] [client 34.76.91.169:48320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aaenroll.com"] [uri "/.git/HEAD"] [unique_id "aryFh17RAD5sN-UfORQA7gAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 21:11:14
(3 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฆ๐บ
screwlooseit.com.au
2026-09-29 18:00:30
(3 days ago)
Blocked by CSF 13 firewall - Rule: US/United States/169.91.76.34.bc.googleusercontent.com
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-29 17:07:29
(3 days ago)
Excessive 404/403 errors
Brute-Force
๐ณ๐ฑ
Alt255
2026-09-29 15:48:56
(3 days ago)
[ti-27al] Excessive 404 errors (web scanning): 50 suspicious requests detected by fail2ban jail apac ...
show more
[ti-27al] Excessive 404 errors (web scanning): 50 suspicious requests detected by fail2ban jail apache-404. Example: 34.76.91.169 - - [29/Sep/2026:17:48:39 +0200] "GET /sw.js HTTP/1.1" 404 7819 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.76.91.169 - - [29/Sep/2026:17:48:39 +0200] "GET /asset-manifest.json HTTP/1.1" 404 7819 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.76.91.169 - - [29/Sep/2026:17:48:39 +0200] "GET /_nuxt/entry.js HTTP/1.1" 404 7819 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.76.91.169 - - [29/Sep/2026:17:48:39 +0200] "GET /runtime.js HTTP/1.1" 404 7819 "-" "Mozilla/5.0 (Windows NT 1
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
000rosiu
2026-09-29 15:39:47
(3 days ago)
Triggered Cloudflare WAF (firewallManaged) from BE.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpo ...
show more
Triggered Cloudflare WAF (firewallManaged) from BE.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /wp-config.php | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-29 10:13:14
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.76.91.169 (169.91.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.91.169 (169.91.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 06:13:08.303751 2026] [security2:error] [pid 1373:tid 1373] [client 34.76.91.169:39112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "10bestrealtors.com"] [uri "/.git/HEAD"] [unique_id "aruPNEjV6buDa-G4WSkRpQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 01:37:57
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.76.91.169 (169.91.76.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.76.91.169 (169.91.76.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 21:37:53.013533 2026] [security2:error] [pid 6961:tid 6961] [client 34.76.91.169:36162] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arellasoc.com"] [uri "/.env"] [unique_id "arsWcbDsMdnnyVmjjXUt0QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-29 00:06:06
(4 days ago)
Not following 301 redirects โ wasted requests | method: GET | path: / | ua: Mozilla/5.0 (Windows NT ...
show more
Not following 301 redirects โ wasted requests | method: GET | path: / | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Bad Web Bot