๐บ๐ธ
TPI-Abuse
2026-09-26 15:44:09
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.93.170.101 (101.170.93.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.93.170.101 (101.170.93.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:44:03.134161 2026] [security2:error] [pid 5117:tid 5135] [client 34.93.170.101:35864] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.magazineofwallstreet.com"] [uri "/.git/config"] [unique_id "arfoQxSmKXR4f3bjH8rYjgAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 15:07:04
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.93.170.101 (101.170.93.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.93.170.101 (101.170.93.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:06:58.379961 2026] [security2:error] [pid 31410:tid 31410] [client 34.93.170.101:42638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.maffiniandbearce.com"] [uri "/.git/config"] [unique_id "arffkpD3lLBk-x46HEKBeAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
magnetosphere-tarpit
2026-09-25 19:56:32
(2 weeks ago)
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not ...
show more
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not exist on this host. Tarpitted, then banned: 10 requests within 24h0m0s
show less
Port Scan
Bad Web Bot
Web App Attack
๐ฌ๐ง
gws-hostmaster
2026-09-25 16:01:08
(2 weeks ago)
ModSecurity OWASP CRS (Anomaly Score: 50): JavaScript Prototype Pollution;JSON-Based SQL Injection;N ...
show more
ModSecurity OWASP CRS (Anomaly Score: 50): JavaScript Prototype Pollution;JSON-Based SQL Injection;Node.js Injection Attack 1/2;PHP Injection Attack: Variable Access Found;Remote Command Execution: Direct Unix Command Execution;Remote Command Execution: Unix Shell Expression Found;Restricted File Access Attempt;SQL Injection Attack: SQL function name detected;URL file extension is restricted by policy;
show less
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-09-24 19:36:17
(2 weeks ago)
[Thu Sep 24 13:36:00.542970 2026] [authz_core:error] [pid 38648:tid 140010279917120] [client 34.93.1 ...
show more
[Thu Sep 24 13:36:00.542970 2026] [authz_core:error] [pid 38648:tid 140010279917120] [client 34.93.170.101:43188] AH01630: client denied by server configuration: /var/www/horde/.env.bak
[Thu Sep 24 13:36:16.230401 2026] [authz_core:error] [pid 38648:tid 140009826842176] [client 34.93.170.101:43188] AH01630: client denied by server configuration: /var/www/horde/.env.dist
[Thu Sep 24 13:36:16.486830 2026] [authz_core:error] [pid 38648:tid 140009885591104] [client 34.93.170.101:43188] AH01630: client denied by server configuration: /var/www/horde/.env.swp
...
show less
Bad Web Bot
๐ซ๐ท
ACE-INFORMATIQUE.NC
2026-09-24 19:00:10
(2 weeks ago)
Web App Attack blocked by Fail2ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 17:13:57
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.93.170.101 (101.170.93.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.93.170.101 (101.170.93.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 13:13:54.229765 2026] [security2:error] [pid 8805:tid 8805] [client 34.93.170.101:53278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.henning.org"] [uri "/.git/config"] [unique_id "arVaUgIjhfXL9NgH7qYHUwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
snhosting
2026-09-24 14:02:15
(2 weeks ago)
34.93.170.101 - - [24/Sep/2026:16:02:05 +0200] "GET /.git/config HTTP/1.1" 200 1628 "-" "Mozilla/5.0 ...
show more
34.93.170.101 - - [24/Sep/2026:16:02:05 +0200] "GET /.git/config HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.93.170.101 - - [24/Sep/2026:16:02:05 +0200] "GET /.env HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.93.170.101 - - [24/Sep/2026:16:02:05 +0200] "GET /.env.local HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.93.170.101 - - [24/Sep/2026:16:02:06 +0200] "GET /.env.production HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.93.170.101 - - [24/Sep/2026:16:02:06 +0200] "GET /.env.staging HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/5
...
show less
DNS Compromise
DNS Poisoning
Phishing
Email Spam
Brute-Force
Web App Attack
SSH
๐จ๐ญ
๐จ๐ญ Hosting
2026-09-24 05:10:38
(2 weeks ago)
Automated WAF report: 200-300 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 08:40:03
(2 weeks ago)
| [Dangerous/India] Aggressive IP 34.93.170.101 (~30 hits). Type: DoS Defender- Web server 400 error ...
show more
| [Dangerous/India] Aggressive IP 34.93.170.101 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐ช๐ธ
robotstxt
2026-09-22 12:14:58
(2 weeks ago)
34.93.170.101 - - [22/Sep/2026:12:14:03 +0000] "GET /.env HTTP/1.1" 403 31 "-" "Mozilla/5.0 (Windows ...
show more
34.93.170.101 - - [22/Sep/2026:12:14:03 +0000] "GET /.env HTTP/1.1" 403 31 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.93.170.101"
34.93.170.101 - - [22/Sep/2026:12:14:03 +0000] "GET /.env.local HTTP/1.1" 403 31 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.93.170.101"
34.93.170.101 - - [22/Sep/2026:12:14:03 +0000] "GET /.env.production HTTP/1.1" 403 31 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.93.170.101"
34.93.170.101 - - [22/Sep/2026:12:14:04 +0000] "GET /.env.staging HTTP/1.1" 403 31 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="34.93.170.101"
34.93.170.101 - - [22/Sep/2026:12:14:04 +0000] "GET /.env.development HTTP/1.1" 403 31 "-" "Mozilla/5.0
...
show less
Web App Attack
๐จ๐ญ
zynex
2026-09-22 10:34:56
(2 weeks ago)
URL Probing: /server/.env
Web App Attack
Anonymous
2026-09-22 08:01:47
(2 weeks ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 07:53:47
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.93.170.101 (101.170.93.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.93.170.101 (101.170.93.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 03:53:39.276921 2026] [security2:error] [pid 11867:tid 11867] [client 34.93.170.101:40174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "act-research.com"] [uri "/.git/config"] [unique_id "arI0A6czcoJ5xD-Jb1b-vQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-09-21 13:42:04
(2 weeks ago)
block ruleset likely probe for CVE-2025-55182 619E65C9C14E5E741C55CC8FD5E5630F031EBB6A
Web App Attack