🇺🇸
TPI-Abuse
2026-09-07 11:39:28
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.232.25 (25.232.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.232.25 (25.232.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 07:39:23.487739 2026] [security2:error] [pid 3056:tid 3056] [client 34.92.232.25:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.c2cservices.com"] [uri "/.git/config"] [unique_id "ap6ia1EkHYuBV5DEBt25DgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 11:22:45
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.232.25 (25.232.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.232.25 (25.232.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 07:22:41.623977 2026] [security2:error] [pid 4920:tid 4920] [client 34.92.232.25:53614] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "weathercarib.net"] [uri "/.git/config"] [unique_id "ap6egfCOnoxlrA98tgZaTgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 11:03:52
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.232.25 (25.232.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.232.25 (25.232.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 07:03:45.180377 2026] [security2:error] [pid 24733:tid 24733] [client 34.92.232.25:57750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "weather.stricklinranch.com"] [uri "/.git/config"] [unique_id "ap6aERzITEQGlzDyVTrY5wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
RamSet
2026-09-07 10:59:48
(4 hours ago)
[wx] HTTP-Probe on port 443 (via domain). 152 distinct paths probed in 33s. Sustained 156 req/min, 1 ...
show more
[wx] HTTP-Probe on port 443 (via domain). 152 distinct paths probed in 33s. Sustained 156 req/min, 151 nonexistent paths (404). Paths: /.git/config, /.env, /.env.local, /.env.production, /.env.staging, /.env.development, /.env.test, /.env.remote, /.env.bak, /.env.backup, /.env.save, /.env.old, /.env.sample, /.env.example, /.env.dev, /.env.prod, /.env.stage, /.env.ci, /.env.docker, /.env.live, /.env.preprod, /.env.uat, /.env.dist, /.env.swp, /.env.txt, /.env.json, /.env.yaml, /.env.yml, /app/.env, /apps/.env, /api/.env, /web/.env, /site/.env, /public/.env, /admin/.env, /backend/.env, /server/.env, /frontend/.env, /src/.env, /core/.env, /core/app/.env, /config/.env, /private/.env, /application/.env, /bootstrap/.env, /database/.env, /storage/.env, /var/www/.env, /var/www/html/.env, /current/.env, /release/.env, /releases/.env, /shared/.env, /deploy/.env, /build/.env, /dist/.env, /public_html/.env, /htdocs/.env, /www/.env, /html/.env
show less
Bad Web Bot
Web App Attack
🇫🇷
pm33
2026-09-07 10:48:11
(5 hours ago)
Probing for resource vulnerabilities HTTP(S)
Web App Attack
🇬🇧
elleray
2026-09-07 10:45:25
(5 hours ago)
Banned by Fail2Ban on apache-wordfence jail
Brute-Force
🇧🇪
cmbplf
2026-09-07 10:35:57
(5 hours ago)
8.126 requests with url.path *.env
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 09:44:32
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.232.25 (25.232.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.232.25 (25.232.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:44:28.965904 2026] [security2:error] [pid 28623:tid 28623] [client 34.92.232.25:53516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wearywillie.com"] [uri "/.git/config"] [unique_id "ap6HfGcUnnuo1E2QQoR0lQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
4server
2026-09-07 09:00:18
(6 hours ago)
[MonSep0711:00:11.7545152026][security2:error][pid4099163:tid4099260][client34.92.232.25:0]ModSecuri ...
show more
[MonSep0711:00:11.7545152026][security2:error][pid4099163:tid4099260][client34.92.232.25:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"webdisk.buletti-panettoni.ch\"][uri\"/.env.bak\"][unique_id\"ap59G_g4hhOtkGBHTg-Q8wAAAAQ\"]
show less
Port Scan
Brute-Force
Web App Attack
🇦🇺
rubixstudios
2026-09-07 02:41:02
(13 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 15:12:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.92.232.25 (25.232.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.232.25 (25.232.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 11:12:13.793731 2026] [security2:error] [pid 21455:tid 21455] [client 34.92.232.25:34184] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.beachweddingaccessories.com"] [uri "/.git/config"] [unique_id "ap2CzWjD4kLU77BXr4CFVgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 14:09:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.92.232.25 (25.232.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.232.25 (25.232.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 10:09:12.064752 2026] [security2:error] [pid 29667:tid 29667] [client 34.92.232.25:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.bbproductionsonline.com"] [uri "/.git/config"] [unique_id "ap10CMkfSrWpKO0dN2qP-gAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-06 14:05:04
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack