๐บ๐ธ
TPI-Abuse
2026-09-02 17:40:11
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.85.203 (203.85.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.85.203 (203.85.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 13:40:07.311021 2026] [security2:error] [pid 17945:tid 17945] [client 34.87.85.203:55570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thesmithcouple.com"] [uri "/.git/config"] [unique_id "aphfd9T74adt-4JBY9iNUwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-02 16:37:17
(14 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 16:20:15
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.85.203 (203.85.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.85.203 (203.85.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 12:20:10.572982 2026] [security2:error] [pid 27440:tid 27440] [client 34.87.85.203:48724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thesiteworks.com"] [uri "/.git/config"] [unique_id "aphMut3Fe0sBzsfod2TUZAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 15:28:39
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.85.203 (203.85.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.85.203 (203.85.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 11:28:32.606767 2026] [security2:error] [pid 27492:tid 27492] [client 34.87.85.203:56818] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thesilverlegion.org"] [uri "/.git/config"] [unique_id "aphAoLCeN4xCGr2DxH4afQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Webmestre
2026-09-02 14:39:00
(16 hours ago)
Attempts against non-existent WordPress and PHP pages /backend/.env, /wp-content/.env
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 14:29:06
(16 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.87.85.203 (203.85.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.87.85.203 (203.85.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 10:29:00.172302 2026] [security2:error] [pid 29303:tid 29303] [client 34.87.85.203:47240] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "theshitmyaisays.com"] [uri "/.git/config"] [unique_id "apgyrANpthpfx9YIlbKr5gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 13:32:08
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.85.203 (203.85.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.85.203 (203.85.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 09:32:03.078699 2026] [security2:error] [pid 16192:tid 16192] [client 34.87.85.203:58476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theseventhcongregationofladderdayvixens.org"] [uri "/.git/config"] [unique_id "apglU_chBf6iuDY_h_21SQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 13:12:37
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.85.203 (203.85.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.85.203 (203.85.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 09:12:29.158309 2026] [security2:error] [pid 5634:tid 5634] [client 34.87.85.203:35576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theseoscribe.com"] [uri "/.git/config"] [unique_id "apggvbQ2ZHaizZCcc3ZBowAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-02 13:05:39
(18 hours ago)
Too many Status 50X (21)
Scanning/Probing (16)
Brute-Force
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-02 12:10:09
(19 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.87.85.203 (SG/Singapore/203.85.87.34.bc.goog ...
show more
(mod_security) mod_security (id:949110) triggered by 34.87.85.203 (SG/Singapore/203.85.87.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ฌ๐ง
sc user
2026-09-02 10:23:48
(20 hours ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-02 09:38:29
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.85.203 (203.85.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.85.203 (203.85.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 05:38:22.185891 2026] [security2:error] [pid 6519:tid 6519] [client 34.87.85.203:42880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "therustedtree.com"] [uri "/.git/config"] [unique_id "apfujtWENEslVgBoQkyEEQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-02 07:15:10
(1 day ago)
Web App Attack
๐ซ๐ท
dynamix
2026-09-02 06:08:28
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-02 06:05:09
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking