🇺🇸
TPI-Abuse
2026-09-12 03:56:40
(49 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.88.214.165 (165.214.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.214.165 (165.214.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 23:56:36.133709 2026] [security2:error] [pid 10316:tid 10316] [client 34.88.214.165:44530] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wakims.com"] [uri "/.git/config"] [unique_id "aqTNdIwdD74ZrqfkXL8_pgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 03:07:11
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.88.214.165 (165.214.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.214.165 (165.214.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 23:07:05.963002 2026] [security2:error] [pid 27799:tid 27799] [client 34.88.214.165:50420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "waltersnet.com"] [uri "/.git/config"] [unique_id "aqTB2WiX3IygszVfS11fcwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 02:49:01
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.88.214.165 (165.214.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.214.165 (165.214.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 22:48:54.507679 2026] [security2:error] [pid 18137:tid 18137] [client 34.88.214.165:48524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "walterceron.com"] [uri "/.git/config"] [unique_id "aqS9lm9C1Ro2CwVFHw3B9gAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
4server
2026-09-12 02:42:35
(2 hours ago)
[SatSep1204:42:30.2069832026][security2:error][pid1766714:tid1766971][client34.88.214.165:0]ModSecur ...
show more
[SatSep1204:42:30.2069832026][security2:error][pid1766714:tid1766971][client34.88.214.165:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"walter-worndli.ch.xn--walter-wrndli-pmb.ch\"][uri\"/\"][unique_id\"aqS8FmDjmI_EY1oWIC5MUgAAAQ
show less
Hacking
Web App Attack
🇩🇪
Philister11
2026-09-12 02:42:30
(2 hours ago)
CrowdSec: crowdsecurity/http-admin-interface-probing (FI/AS396982)
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-10 23:52:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.214.165 (165.214.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.214.165 (165.214.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 19:52:03.864734 2026] [security2:error] [pid 31604:tid 31613] [client 34.88.214.165:60412] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "totheendsoftheearth.com"] [uri "/.git/config"] [unique_id "aqNCowSca30zUdnY5STGggAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 23:33:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.214.165 (165.214.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.214.165 (165.214.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 19:33:38.039730 2026] [security2:error] [pid 19216:tid 19243] [client 34.88.214.165:44616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "totalservicesandmorellc.com"] [uri "/.git/config"] [unique_id "aqM-UmFdE4de7xxXNjw6bwAAANc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
gigatech
2026-09-10 23:20:04
(1 day ago)
Webserver Probing
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 22:02:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.88.214.165 (165.214.88.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.88.214.165 (165.214.88.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 18:02:50.446866 2026] [security2:error] [pid 14449:tid 14449] [client 34.88.214.165:50936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "torresyrellenos.com"] [uri "/.git/config"] [unique_id "aqMpCtQjDXwLANv5CpLCjQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
Francisco Vallejo
2026-09-10 21:52:20
(1 day ago)
[Thu Sep 10 23:52:19.793410 2026] [authz_core:error] [pid 191767:tid 133113023809216] [client 34.88. ...
show more
[Thu Sep 10 23:52:19.793410 2026] [authz_core:error] [pid 191767:tid 133113023809216] [client 34.88.214.165:34644] AH01630: client denied by server configuration: proxy:http://localhost:9091/
[Thu Sep 10 23:52:19.864207 2026] [authz_core:error] [pid 191767:tid 133113032201920] [client 34.88.214.165:34644] AH01630: client denied by server configuration: proxy:http://localhost:9091/
[Thu Sep 10 23:52:19.936450 2026] [authz_core:error] [pid 191767:tid 133112503723712] [client 34.88.214.165:34644] AH01630: client denied by server configuration: proxy:http://localhost:9091/
[Thu Sep 10 23:52:20.007105 2026] [authz_core:error] [pid 191767:tid 133112512116416] [client 34.88.214.165:34644] AH01630: client denied by server configuration: proxy:http://localhost:9091/
[Thu Sep 10 23:52:20.080400 2026] [authz_core:error] [pid 191767:tid 133113007023808] [client 34.88.214.165:34644] AH01630: client denied by server configuration: proxy:http://localhost:9091/.git/config
...
show less
Brute-Force
SSH
🇫🇮
000rosiu
2026-09-10 21:50:44
(1 day ago)
Triggered Cloudflare WAF (firewallManaged) from FI.
Action: BLOCK | Protocol: HTTP/1.1 (POST) | Endp ...
show more
Triggered Cloudflare WAF (firewallManaged) from FI.
Action: BLOCK | Protocol: HTTP/1.1 (POST) | Endpoint: / | UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇫🇮
oh.mg
2026-09-10 09:54:10
(1 day ago)
34.88.214.165 - - [10/Sep/2026:11:54:10 +0200] "POST / HTTP/1.1" 403 557 "-" "Mozilla/5.0 (Windows N ...
show more
34.88.214.165 - - [10/Sep/2026:11:54:10 +0200] "POST / HTTP/1.1" 403 557 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.88.214.165 - - [10/Sep/2026:11:54:10 +0200] "POST / HTTP/1.1" 403 557 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.88.214.165 - - [10/Sep/2026:11:54:10 +0200] "POST / HTTP/1.1" 403 557 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.88.214.165 - - [10/Sep/2026:11:54:10 +0200] "GET /.git/config HTTP/1.1" 403 557 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.88.214.165 - - [10/Sep/2026:11:54:10 +0200] "GET /.env HTTP/1.1" 403 4507 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇨🇭
zynex
2026-09-10 09:49:26
(1 day ago)
URL Probing: /backend/.env
Web App Attack
🇵🇱
sledzik1984
2026-09-10 09:15:41
(1 day ago)
34.88.214.165 - - [10/Sep/2026:11:15:41 +0200] "GET /admin/phpinfo.php HTTP/1.1" 404 188 "-" "Mozill ...
show more
34.88.214.165 - - [10/Sep/2026:11:15:41 +0200] "GET /admin/phpinfo.php HTTP/1.1" 404 188 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.88.214.165 - - [10/Sep/2026:11:15:41 +0200] "GET /test/phpinfo.php HTTP/1.1" 404 188 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.88.214.165 - - [10/Sep/2026:11:15:41 +0200] "GET /dev/phpinfo.php HTTP/1.1" 404 188 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-09-10 09:07:40
(1 day ago)
2026-09-10 11:07:39,675 fail2ban.actions [634]: NOTICE [apache-noscript] Ban 34.88.214.165
2 ...
show more
2026-09-10 11:07:39,675 fail2ban.actions [634]: NOTICE [apache-noscript] Ban 34.88.214.165
2026-09-10 11:07:39,752 fail2ban.actions [634]: NOTICE [apache-custom] Ban 34.88.214.165
2026-09-10 11:07:39,775 fail2ban.actions [634]: NOTICE [apache-php-scans] Ban 34.88.214.165
...
show less
Brute-Force
Web App Attack