🇺🇸
TPI-Abuse
2026-09-06 01:46:12
(13 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.87.225.239 (239.225.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.225.239 (239.225.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:46:09.315899 2026] [security2:error] [pid 860:tid 860] [client 34.87.225.239:38258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "serviciosdedistribucioncastimpex.com.spyasociados.com"] [uri "/api/.git/config"] [unique_id "apzF4QY14NcddFwg2u0YFgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Lea
2026-09-06 01:32:51
(27 minutes ago)
Malicious web probe detected on bearstool.com: 34.87.225.239 - - [05/Sep/2026:21:32:50 -0400] "GET / ...
show more
Malicious web probe detected on bearstool.com: 34.87.225.239 - - [05/Sep/2026:21:32:50 -0400] "GET /site/.git/config HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
show less
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-05 22:05:58
(3 hours ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
🇫🇮
mnazibo
2026-09-05 14:00:08
(12 hours ago)
Date: 05/Sep/2026 16:54:10 | Reported IP: 34.87.225.239 mod_security | id: 930130 | AU/group.my_doma ...
show more
Date: 05/Sep/2026 16:54:10 | Reported IP: 34.87.225.239 mod_security | id: 930130 | AU/group.my_domain/- | Connections: 12 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /api/.git/config; /app/.git/config; /backend/.git/config; /.git/config; /htdocs/.git/config; /html/.git/config; /public/.git/config; /site/.git/config; /src/.git/config; /var/www/.git/config; /wordpress/.git/config; /www/.git/config | Logs: Restricted File Access Attempt
show less
SQL Injection
Brute-Force
Bad Web Bot
🇦🇹
Starburst SysOp Team
2026-09-05 10:03:58
(15 hours ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-vie6-1)
Hacking
Bad Web Bot
🇲🇾
Rizzy
2026-09-05 09:19:50
(16 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 02:34:14
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.225.239 (239.225.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.225.239 (239.225.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 22:34:09.488264 2026] [security2:error] [pid 26241:tid 26241] [client 34.87.225.239:33134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.the-practical-pionus.com"] [uri "/html/.git/config"] [unique_id "apt_ocjLIkAhBbxhSDmmUgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-05 01:25:07
(1 day ago)
34.87.225.239 - - [04/Sep/2026:21:25:06 -0400] "GET /var/www/.git/config HTTP/1.1" 503 5682 "-" "cru ...
show more
34.87.225.239 - - [04/Sep/2026:21:25:06 -0400] "GET /var/www/.git/config HTTP/1.1" 503 5682 "-" "crusader-worker/1.0"
34.87.225.239 - - [04/Sep/2026:21:25:06 -0400] "GET /.git/config HTTP/1.1" 503 5682 "-" "crusader-worker/1.0"
34.87.225.239 - - [04/Sep/2026:21:25:06 -0400] "GET /htdocs/.git/config HTTP/1.1" 503 5682 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇳🇱
e.fierstra
2026-09-04 22:53:50
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:57:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.87.225.239 (239.225.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.225.239 (239.225.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:57:38.286691 2026] [security2:error] [pid 27621:tid 27635] [client 34.87.225.239:50206] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.citrusserviceandconsulting.com"] [uri "/public/.git/config"] [unique_id "aps-0hRXVsx4SlV67SsuMwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 20:38:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.87.225.239 (239.225.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.225.239 (239.225.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 16:37:59.363181 2026] [security2:error] [pid 32092:tid 32092] [client 34.87.225.239:41722] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "directoryofdogs.com"] [uri "/www/.git/config"] [unique_id "apssJ8yj1_ccvPiMr5WTFwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
Dunham Support
2026-09-04 19:12:37
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.87.225.239 (AU/Australia/239.225.87. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.87.225.239 (AU/Australia/239.225.87.34.bc.googleusercontent.com)
show less
SQL Injection
🇩🇪
FeG Deutschland
2026-09-04 15:58:28
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:54:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.87.225.239 (239.225.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.225.239 (239.225.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:54:18.909638 2026] [security2:error] [pid 17552:tid 17552] [client 34.87.225.239:43380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bigkevsperformance.com"] [uri "/var/www/.git/config"] [unique_id "aprNirbVL_R0zaezPts26AAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:39:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.87.225.239 (239.225.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.225.239 (239.225.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:39:47.501968 2026] [security2:error] [pid 1269:tid 1269] [client 34.87.225.239:36246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "timjbutler.com"] [uri "/var/www/.git/config"] [unique_id "apquA9YLCQLNjPl_7HMEjwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack