Anonymous
2026-09-07 08:50:03
(9 minutes ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
🇺🇸
TPI-Abuse
2026-09-07 08:37:22
(22 minutes ago)
(mod_security) mod_security (id:210492) triggered by 34.94.100.175 (175.100.94.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.100.175 (175.100.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:37:18.094694 2026] [security2:error] [pid 8248:tid 8248] [client 34.94.100.175:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webfrog.ws"] [uri "/.git/config"] [unique_id "ap53vv20nfOOOXNZXOxSEwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-07 08:30:16
(29 minutes ago)
Excessive multi-domain requests
Brute-Force
🇧🇷
dominioz
2026-09-07 07:19:58
(1 hour ago)
2026-09-07 07:19:24 GET /.git/config - - 34.94.100.175 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64; ...
show more
2026-09-07 07:19:24 GET /.git/config - - 34.94.100.175 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 508
2026-09-07 07:19:25 GET /.env - - 34.94.100.175 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 494
2026-09-07 07:19:27 GET /.env.bak - - 34.94.100.175 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 245
2026-09-07 07:19:29 GET /.env.old - - 34.94.100.175 HTTP/1.1 Mozilla/5.0+(Windows+NT+10.0;+Win64;+x64)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 245
...
show less
Web App Attack
Anonymous
2026-09-07 07:14:27
(1 hour ago)
Web application attack detected.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 06:10:09
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.94.100.175 (175.100.94.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.100.175 (175.100.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:10:05.645335 2026] [security2:error] [pid 30502:tid 30502] [client 34.94.100.175:36458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.curatorialstudio.com"] [uri "/.git/config"] [unique_id "ap5VPdArmBQ_8BjTyChOggAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
electronico
2026-09-07 05:30:29
(3 hours ago)
34.94.100.175 - - [07/Sep/2026:16:30:26 +1100] "GET /.env.local HTTP/1.1" 404 2104 "-" "Mozilla/5.0 ...
show more
34.94.100.175 - - [07/Sep/2026:16:30:26 +1100] "GET /.env.local HTTP/1.1" 404 2104 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.94.100.175 - - [07/Sep/2026:16:30:26 +1100] "GET /.env.production HTTP/1.1" 404 2104 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.94.100.175 - - [07/Sep/2026:16:30:26 +1100] "GET /.env.staging HTTP/1.1" 404 2104 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.94.100.175 - - [07/Sep/2026:16:30:26 +1100] "GET /.env.development HTTP/1.1" 404 2104 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.94.100.175 - - [07/Sep/2026:16:30:27 +1100] "GET /.env.test HTTP/1.1" 404 2104 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTM
...
show less
Brute-Force
Web App Attack
Anonymous
2026-09-07 04:46:25
(4 hours ago)
[Mon Sep 07 06:46:24.310239 2026] [proxy_fcgi:error] [pid 159831:tid 159873] [client 34.94.100.175:4 ...
show more
[Mon Sep 07 06:46:24.310239 2026] [proxy_fcgi:error] [pid 159831:tid 159873] [client 34.94.100.175:47094] AH01071: Got error 'Primary script unknown'
[Mon Sep 07 06:46:24.647781 2026] [proxy_fcgi:error] [pid 159831:tid 159876] [client 34.94.100.175:47094] AH01071: Got error 'Primary script unknown'
[Mon Sep 07 06:46:24.897972 2026] [proxy_fcgi:error] [pid 159831:tid 159874] [client 34.94.100.175:47094] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
🇬🇧
blueskysystems
2026-09-07 04:30:02
(4 hours ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
🇬🇧
cg-design.co.uk
2026-09-07 04:00:38
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.94.100.175 (US/United States/175.100 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.94.100.175 (US/United States/175.100.94.34.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-07 03:55:35
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.94.100.175 (175.100.94.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.94.100.175 (175.100.94.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 23:55:30.314906 2026] [security2:error] [pid 15646:tid 15646] [client 34.94.100.175:47034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.crochetfreepatterns.com"] [uri "/.git/config"] [unique_id "ap41snmCmBeJSzuMT1e7xwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
ecode hosting
2026-09-07 01:37:04
(7 hours ago)
Domain : MailEnable WebMail
Rule : hack
2026-09-07 01:35:01 10.100.1.20 GET /php.php - 443 - 104.22. ...
show more
Domain : MailEnable WebMail
Rule : hack
2026-09-07 01:35:01 10.100.1.20 GET /php.php - 443 - 104.22.20.9 Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 - 404 0 2 215 - 34.94.100.175
show less
Hacking
SQL Injection
Brute-Force
🇩🇪
ghostwarriors
2026-09-07 01:20:06
(7 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-07 01:03:18
(7 hours ago)
34.94.100.175 - - [07/Sep/2026:03:03:13 +0200] "GET /.env.local HTTP/1.1" 404 740 "-" "Mozilla/5.0 ( ...
show more
34.94.100.175 - - [07/Sep/2026:03:03:13 +0200] "GET /.env.local HTTP/1.1" 404 740 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.94.100.175 - - [07/Sep/2026:03:03:13 +0200] "GET /.env.production HTTP/1.1" 404 740 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.94.100.175 - - [07/Sep/2026:03:03:13 +0200] "GET /.env.staging HTTP/1.1" 404 740 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.94.100.175 - - [07/Sep/2026:03:03:14 +0200] "GET /.env.development HTTP/1.1" 404 740 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.94.100.175 - - [07/Sep/2026:03:03:14 +0200] "GET /.env.test HTTP/1.1" 404 740 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Saf
show less
Web App Attack
Hacking
Anonymous
2026-09-07 00:10:04
(8 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection