πΊπΈ
TPI-Abuse
2026-09-16 08:08:08
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.76.14 (14.76.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.76.14 (14.76.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 04:07:59.539884 2026] [security2:error] [pid 29842:tid 29842] [client 34.80.76.14:57138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.countrycottagetogo.buffaloweddingdeejay.com"] [uri "/.git/config"] [unique_id "aqpOXyz67MID_0WitQNiawAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 07:50:51
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.76.14 (14.76.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.76.14 (14.76.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 03:50:46.387352 2026] [security2:error] [pid 30177:tid 30177] [client 34.80.76.14:54650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.countertop.mooseled.com"] [uri "/.git/config"] [unique_id "aqpKVqDZd5UFUZvMUHDd0QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-09-16 06:58:20
(5 hours ago)
Automated web vulnerability and path enumeration scan with excessive 404 requests
Bad Web Bot
Web App Attack
πΊπΈ
Victor LΓ³pez
2026-09-16 06:31:45
(5 hours ago)
videoprenatal.com 34.80.76.14 - - [16/Sep/2026:01:31:40 -0500] "GET /.git/config HTTP/2.0" 404 20704 ...
show more
videoprenatal.com 34.80.76.14 - - [16/Sep/2026:01:31:40 -0500] "GET /.git/config HTTP/2.0" 404 20704 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" -
videoprenatal.com 34.80.76.14 - - [16/Sep/2026:01:31:43 -0500] "GET /.env HTTP/2.0" 404 20700 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" -
videoprenatal.com 34.80.76.14 - - [16/Sep/2026:01:31:44 -0500] "GET /.env.local HTTP/2.0" 404 20702 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" -
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 06:30:49
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.76.14 (14.76.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.76.14 (14.76.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 02:30:43.517769 2026] [security2:error] [pid 12265:tid 12265] [client 34.80.76.14:55848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cottrellfamily.com.cottrel.com"] [uri "/.git/config"] [unique_id "aqo3k_grgcXhWZmZ8fAm9QAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 04:35:38
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.76.14 (14.76.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.76.14 (14.76.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 00:35:33.630642 2026] [security2:error] [pid 28860:tid 28860] [client 34.80.76.14:46860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.coteaching.marveldirectory.com"] [uri "/.git/config"] [unique_id "aqoclVGKclOE5G6AfycgIQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
rubixstudios
2026-09-16 02:53:02
(9 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
π«π·
masterguru
2026-09-16 02:12:50
(9 hours ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-09-16 01:23:05
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.76.14 (14.76.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.76.14 (14.76.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:22:57.166600 2026] [security2:error] [pid 9139:tid 9139] [client 34.80.76.14:55476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "victorvictorinc.com.victorvictor.biz"] [uri "/.git/config"] [unique_id "aqnvcXPaEXbdndsbGlWZFAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-09-16 00:25:01
(11 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
π²πΎ
Rizzy
2026-09-16 00:10:35
(11 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πͺπΈ
pipeline.es
2026-09-15 23:29:11
(12 hours ago)
Web scanning / probing for vulnerable paths | URL: /.env.dev | Evidence: www.grimalditour.com 34.80. ...
show more
Web scanning / probing for vulnerable paths | URL: /.env.dev | Evidence: www.grimalditour.com 34.80.76.14 - - [16/Sep/2026:01:27:47 +0200] \"GET /.env.dev HTTP/1.1\" 404 30096 \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=TW | ASN: GOOGLE-CLOUD-PLATFORM | Country: TW
show less
Port Scan
Web App Attack
π¬π§
consul.to
2026-09-15 21:18:18
(14 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-15 17:50:03
(18 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.local HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env. ...
show more
Bot / scanning and/or hacking attempts: GET /.env.local HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env.sample HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env.development HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env.staging HTTP/1.1, GET /.env.save HTTP/1.1, GET /.env.backup HTTP/1.1, POST / HTTP/1.1, GET /.git/config HTTP/1.1, GET /.env HTTP/1.1, GET /.env.test HTTP/1.1, GET /.env.production HTTP/1.1, GET /.env.remote HTTP/1.1
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 17:31:37
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.80.76.14 (14.76.80.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.80.76.14 (14.76.80.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:31:30.039199 2026] [security2:error] [pid 8605:tid 8605] [client 34.80.76.14:56470] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.nutandboltguy.com"] [uri "/.git/config"] [unique_id "aqmA8slw_xN7GuPNWIdSsAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack