๐บ๐ธ
TPI-Abuse
2026-08-25 17:16:47
(2 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.87.77.20 (20.77.87.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.77.20 (20.77.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 13:16:39.597653 2026] [security2:error] [pid 6692:tid 6692] [client 34.87.77.20:46166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rayeliotschwartz.com"] [uri "/.git/config"] [unique_id "ao3N95ro0VQ09WMYi5oIbwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-08-25 17:13:02
(6 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-25 16:06:42
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.87.77.20 (20.77.87.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.77.20 (20.77.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 12:06:34.398180 2026] [security2:error] [pid 31391:tid 31391] [client 34.87.77.20:17444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "insua.com"] [uri "/.git/config"] [unique_id "ao29iiUyWnpRBNBFAOX7XAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-25 16:05:08
(1 hour ago)
Abuse Detected (14)
Brute-Force
Web App Attack
๐ช๐ธ
el-brujo
2026-08-25 15:59:15
(1 hour ago)
25/Aug/2026:17:59:14.562769 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
25/Aug/2026:17:59:14.562769 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 34.87.77.20] ModSecurity: Warning. Matched phrase "/.git/" at REQUEST_FILENAME. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "125"] [id "930130"] [msg "Restricted File Access Attempt"] [data "Matched Data: /.git/ found within REQUEST_FILENAME: /.git/config"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [tag "PCI/6.5.4"] [hostname "hostench.eu"] [uri "/.git/config"] [unique_id "ao270sjm7QTpb9lCvTYuoQAEgi8"]
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 15:49:06
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.87.77.20 (20.77.87.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.77.20 (20.77.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 11:49:00.306860 2026] [security2:error] [pid 6421:tid 6421] [client 34.87.77.20:61670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "goldenfrytech.net"] [uri "/.git/config"] [unique_id "ao25bEVj4-UHBhcQAaNHdwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-08-25 15:23:07
(1 hour ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.87.77.20 (SG/Singapore/20.77.87. ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.87.77.20 (SG/Singapore/20.77.87.34.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 15:18:34
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.77.20 (20.77.87.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.77.20 (20.77.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 11:18:30.521447 2026] [security2:error] [pid 16341:tid 16400] [client 34.87.77.20:20786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dermatologybriargate.com"] [uri "/.git/config"] [unique_id "ao2yRs8u9dpSFXhJ50QXuwAAAgk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-08-25 15:02:19
(2 hours ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 15:01:20
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.77.20 (20.77.87.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.77.20 (20.77.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 11:01:13.503531 2026] [security2:error] [pid 20927:tid 20927] [client 34.87.77.20:63574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chandlerowen.com"] [uri "/.git/config"] [unique_id "ao2uOc8TH6G--G_b_XOX_QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-08-25 14:49:29
(2 hours ago)
Try to access /.git/config
Web App Attack
๐ฌ๐ง
AvonleaConsulting
2026-08-25 14:45:49
(2 hours ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 14:35:27
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.77.20 (20.77.87.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.77.20 (20.77.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 10:35:19.004578 2026] [security2:error] [pid 27899:tid 27899] [client 34.87.77.20:49020] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amdavies15.com"] [uri "/.git/config"] [unique_id "ao2oJ61M6RN7aWIdnXFMegAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 14:19:57
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.77.20 (20.77.87.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.77.20 (20.77.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 10:19:50.677518 2026] [security2:error] [pid 6308:tid 6308] [client 34.87.77.20:37562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "4lazy.com"] [uri "/.env"] [unique_id "ao2khpBGKPTPNeYtEzVafAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-08-25 13:56:13
(3 hours ago)
[TueAug2515:56:06.5653862026][security2:error][pid143187:tid143422][client34.87.77.20:0]ModSecurity: ...
show more
[TueAug2515:56:06.5653862026][security2:error][pid143187:tid143422][client34.87.77.20:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"4hosts.net\"][uri\"/.env\"][unique_id\"ao2e9rk4SqreXnJXLnFVWQAAARI\"]
show less
Hacking
Web App Attack