🇵🇱
strefapi_com
2026-09-07 01:05:50
(1 hour ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 23:57:30
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.204.140 (140.204.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.204.140 (140.204.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 19:57:24.782756 2026] [security2:error] [pid 13199:tid 13199] [client 34.97.204.140:53392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ambarsolar.aguasolar.com"] [uri "/.git/config"] [unique_id "ap395D8lxbIYtnwWdOhtigAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 23:40:13
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇩🇪
big-cloud.nl
2026-09-06 23:38:46
(2 hours ago)
Try to access /.git/config
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 21:00:17
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.204.140 (140.204.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.204.140 (140.204.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:00:08.956645 2026] [security2:error] [pid 26082:tid 26082] [client 34.97.204.140:50978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amazingsculpture.mitchellart.com"] [uri "/.git/config"] [unique_id "ap3UWIuo5XcwX4ic296RXAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 20:16:43
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.204.140 (140.204.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.204.140 (140.204.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:16:38.073209 2026] [security2:error] [pid 13113:tid 13113] [client 34.97.204.140:37764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amazingerection.amazingwelding.com"] [uri "/.git/config"] [unique_id "ap3KJtLe4Oq2Wcyc4IYXBQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 19:28:42
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.204.140 (140.204.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.204.140 (140.204.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:28:37.781662 2026] [security2:error] [pid 19253:tid 19253] [client 34.97.204.140:33852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amazeconsultants.org"] [uri "/.git/config"] [unique_id "ap2-5dL34pKE5lMHZEKtZwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 17:54:17
(8 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇵🇫
www.gregorymariani.com
2026-09-06 17:52:36
(8 hours ago)
34.97.204.140 - - [06/Sep/2026:17:52:34 +0000] "GET /.git/config HTTP/1.1" 404 179 "-" "Mozilla/5.0 ...
show more
34.97.204.140 - - [06/Sep/2026:17:52:34 +0000] "GET /.git/config HTTP/1.1" 404 179 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 535 0.010 [default-shop-oscar-amartyne-8080] [] 10.244.58.74:8080 179 0.011 404 dcbe1ca1555346a92e1f60b993ac582e
34.97.204.140 - - [06/Sep/2026:17:52:35 +0000] "GET /.env HTTP/1.1" 404 179 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 528 0.006 [default-shop-oscar-amartyne-8080] [] 10.244.58.74:8080 179 0.006 404 1b3c62b6365e694afd5c56df3d25ee32
34.97.204.140 - - [06/Sep/2026:17:52:35 +0000] "GET /.env.local HTTP/1.1" 404 179 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 534 0.007 [default-shop-oscar-amartyne-8080] [] 10.244.58.74:8080 179 0.008 404 d0b6c8d30c49dcd563ac1c332beb55ba
34.97.204.140 - - [06/Sep/2026:17:52:35 +0000] "GET /.env.production HTTP/1.1" 404 179 "-" "Mozi
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 17:42:16
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.97.204.140 (140.204.97.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.204.140 (140.204.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 13:42:13.143547 2026] [security2:error] [pid 11305:tid 11305] [client 34.97.204.140:41148] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.amarrasdeescobar.com.cerrovictoria.com"] [uri "/.git/config"] [unique_id "ap2l9anQ51i6Cthgzs2jKwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 17:33:16
(8 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇬🇧
consul.to
2026-09-06 17:04:39
(9 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
Site.eu
2026-09-06 16:53:37
(9 hours ago)
Excessive 404/403 errors
Brute-Force
🇫🇷
Octopuce
2026-09-06 15:58:06
(10 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
🇮🇹
VHosting
2026-09-06 15:05:04
(11 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack