🇩🇪
Marc
2026-09-07 18:50:28
(6 hours ago)
34.87.211.97 - - [07/Sep/2026:20:50:27 +0200] "GET /.git/config HTTP/1.1" 404 705 "-" "Mozilla/5.0 ( ...
show more
34.87.211.97 - - [07/Sep/2026:20:50:27 +0200] "GET /.git/config HTTP/1.1" 404 705 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 34.87.211.97 - - [07/Sep/2026:20:50:27 +0200] "GET /.env HTTP/1.1" 404 705 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 34.87.211.97 - - [07/Sep/2026:20:50:28 +0200] "GET /.env.save HTTP/1.1" 404 705 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Brute-Force
🇹🇭
MWA SOC
2026-09-07 18:29:15
(6 hours ago)
Hacking
🇳🇱
e.fierstra
2026-09-07 04:46:12
(20 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 04:22:56
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.211.97 (97.211.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.211.97 (97.211.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 00:22:51.686406 2026] [security2:error] [pid 15218:tid 15218] [client 34.87.211.97:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.theabstractpress.com"] [uri "/.git/config"] [unique_id "ap48GwnmT7wkSkkgd0YaLgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
SwinT
2026-09-07 03:00:03
(22 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇩🇪
Admins@Storch
2026-09-07 02:50:02
(22 hours ago)
OPNsense: 9 hits, proto=tcp, ports=2087,2375
Port Scan
Hacking
🇳🇱
debestelapp
2026-09-07 02:45:12
(22 hours ago)
Web App Attack
🇫🇷
dynamix
2026-09-07 02:22:10
(22 hours ago)
Multiple WAF Violations
Web App Attack
🇩🇪
FD-IX
2026-09-07 02:13:22
(23 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 01:59:04
(23 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
Anonymous
2026-09-07 01:58:17
(23 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.87.211.97 (AU/Australia/97.211.87.34 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.87.211.97 (AU/Australia/97.211.87.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-07 01:56:47
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.211.97 (97.211.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.211.97 (97.211.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 21:56:41.338852 2026] [security2:error] [pid 22193:tid 22193] [client 34.87.211.97:51674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.softwarezz.net"] [uri "/.git/config"] [unique_id "ap4Z2XSp8KbtI1OiiKmlngAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
itsolon
2026-09-07 01:33:22
(23 hours ago)
[07/Sep/2026:03:33:22 +0200] 178874480220.326792 34.87.211.97 53030 217.154.7.177 443
[07/Sep/2026:0 ...
show more
[07/Sep/2026:03:33:22 +0200] 178874480220.326792 34.87.211.97 53030 217.154.7.177 443
[07/Sep/2026:03:33:22 +0200] 178874480220.160999 34.87.211.97 53026 217.154.7.177 443
[07/Sep/2026:03:33:22 +0200] 178874480252.700636 34.87.211.97 53044 217.154.7.177 443
[07/Sep/2026:03:33:22 +0200] 178874480237.634736 34.87.211.97 53014 217.154.7.177 443
[07/Sep/2026:03:33:22 +0200] 17887448024.726388 34.87.211.97 53012 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 01:27:28
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.211.97 (97.211.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.211.97 (97.211.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 21:27:21.151254 2026] [security2:error] [pid 32764:tid 32764] [client 34.87.211.97:44780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.sipa.com.hk"] [uri "/.git/config"] [unique_id "ap4S-XJSsID6fbZomw3hbwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 15:49:21
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.87.211.97 (97.211.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.211.97 (97.211.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:49:14.231746 2026] [security2:error] [pid 4911:tid 4940] [client 34.87.211.97:35338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oftv.xyz"] [uri "/.git/config"] [unique_id "ap2LejFHsX_kaC1Hr4XyQwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack