🇳🇱
Site.eu
2026-09-07 16:56:40
(19 minutes ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 15:53:05
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.87.242.251 (251.242.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.242.251 (251.242.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 11:52:59.310055 2026] [security2:error] [pid 477:tid 477] [client 34.87.242.251:43796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thecrimsonpirate.com"] [uri "/.git/config"] [unique_id "ap7d29rw3lCre2lNt3biogAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-07 15:15:21
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 14:41:56
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.242.251 (251.242.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.242.251 (251.242.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 10:41:51.757893 2026] [security2:error] [pid 21969:tid 22017] [client 34.87.242.251:50686] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thecraftsycat.com"] [uri "/.git/config"] [unique_id "ap7NL3Tx6omXApDQ8OtWjAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
sc user
2026-09-07 14:03:12
(3 hours ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
🇺🇸
TPI-Abuse
2026-09-07 12:44:16
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.242.251 (251.242.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.242.251 (251.242.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 08:44:10.995236 2026] [security2:error] [pid 3339:tid 3339] [client 34.87.242.251:38476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thecorinthians.info"] [uri "/.git/config"] [unique_id "ap6xmok2ZyXbMOjP1khCXgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
rubixstudios
2026-09-07 12:21:02
(4 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇩🇪
ghostwarriors
2026-09-07 12:20:10
(4 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-07 12:18:06
(4 hours ago)
34.87.242.251 - - [07/Sep/2026:14:18:04 +0200] "GET /.env.save HTTP/1.1" 303 609 "-" "Mozilla/5.0 (W ...
show more
34.87.242.251 - - [07/Sep/2026:14:18:04 +0200] "GET /.env.save HTTP/1.1" 303 609 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.87.242.251 - - [07/Sep/2026:14:18:04 +0200] "GET /.env.old HTTP/1.1" 303 607 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.87.242.251 - - [07/Sep/2026:14:17:59 +0200] "GET / HTTP/1.1" 200 5527 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.87.242.251 - - [07/Sep/2026:14:18:00 +0200] "POST / HTTP/1.1" 200 1506 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.87.242.251 - - [07/Sep/2026:14:18:01 +0200] "GET /.git/config HTTP/1.1" 403 517 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.87.242.251 - - [07/Sep/2026:14:18:01 +0200] "P
show less
Web App Attack
Hacking
🇺🇸
mnsf
2026-09-07 11:05:16
(6 hours ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 10:49:56
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.242.251 (251.242.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.242.251 (251.242.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 06:49:52.006856 2026] [security2:error] [pid 248645:tid 248670] [client 34.87.242.251:35094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thecomputergreek.com"] [uri "/.git/config"] [unique_id "ap6W0LMYLLAJ740JtICU4QAAAJc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Lee Daniel
2026-09-07 10:16:54
(6 hours ago)
34.87.242.251 - - [07/Sep/2026:06:16:53 -0400] "GET /.env HTTP/1.1" 403 6307 "-" "Mozilla/5.0 (Windo ...
show more
34.87.242.251 - - [07/Sep/2026:06:16:53 -0400] "GET /.env HTTP/1.1" 403 6307 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
nyt
2026-09-07 08:41:57
(8 hours ago)
Sensitive File Probe
Web App Attack
🇳🇱
e.fierstra
2026-09-07 07:11:53
(10 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 19:27:41
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.242.251 (251.242.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.242.251 (251.242.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:27:36.386441 2026] [security2:error] [pid 19837:tid 19837] [client 34.87.242.251:48100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thereisaplaceonearth.com"] [uri "/.git/config"] [unique_id "ap2-qIauF6yjS2d8DeW6fwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack