🇩🇪
Jochen Pretli
2026-09-12 13:29:36
(2 days ago)
connection to honeypot
Email Spam
Port Scan
Anonymous
2026-09-04 22:59:37
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 21:40:44
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.198.124.193 (193.124.198.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.124.193 (193.124.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:40:36.404770 2026] [security2:error] [pid 8297:tid 8358] [client 104.198.124.193:43878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail1.absurdotron.com"] [uri "/public/.git/config"] [unique_id "aps61FF0V6dcAmwFugfoiwAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 21:13:14
(1 week ago)
104.198.124.193 mail.rolistore.com - [04/Sep/2026:15:13:11 -0600] "GET /app/.git/config HTTP/1.1" 40 ...
show more
104.198.124.193 mail.rolistore.com - [04/Sep/2026:15:13:11 -0600] "GET /app/.git/config HTTP/1.1" 403 158 "-" "crusader-worker/1.0"
104.198.124.193 mail.rolistore.com - [04/Sep/2026:15:13:11 -0600] "GET /.git/config HTTP/1.1" 403 158 "-" "crusader-worker/1.0"
104.198.124.193 mail.rolistore.com - [04/Sep/2026:15:13:11 -0600] "GET /src/.git/config HTTP/1.1" 403 158 "-" "crusader-worker/1.0"
104.198.124.193 mail.rolistore.com - [04/Sep/2026:15:13:12 -0600] "GET /backend/.git/config HTTP/1.1" 403 158 "-" "crusader-worker/1.0"
104.198.124.193 mail.rolistore.com - [04/Sep/2026:15:13:12 -0600] "GET /api/.git/config HTTP/1.1" 403 158 "-" "crusader-worker/1.0"
104.198.124.193 mail.rolistore.com - [04/Sep/2026:15:13:12 -0600] "GET /www/.git/config HTTP/1.1" 403 158 "-" "crusader-worker/1.0"
104.198.124.193 mail.rolistore.com - [04/Sep/2026:15:13:12 -0600] "GET /html/.git/config HTTP/1.1" 403 158 "-" "crusader-worker/1.0"
104.198.124.193 mail.rolistore.com - [04/Sep/2026:15:13:12 -0600] "GET /pub
...
show less
DDoS Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:09:02
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.198.124.193 (193.124.198.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.124.193 (193.124.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:08:55.773883 2026] [security2:error] [pid 7552:tid 7552] [client 104.198.124.193:52822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.madisonjazzorchestra.com"] [uri "/wordpress/.git/config"] [unique_id "apszZ3fFefNt6kb9Aj1aTgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-04 18:57:13
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 18:45:46
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
mnsf
2026-09-04 18:05:34
(1 week ago)
Too many Status 40X (12)
Scanning/Probing (12)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 16:58:47
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.198.124.193 (193.124.198.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.124.193 (193.124.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 12:58:40.149502 2026] [security2:error] [pid 10131:tid 10131] [client 104.198.124.193:48424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "compliancedepts.com"] [uri "/public/.git/config"] [unique_id "apr4wNl-GCox1pVz8T5DiAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:49:28
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.198.124.193 (193.124.198.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.124.193 (193.124.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:49:25.123842 2026] [security2:error] [pid 12987:tid 12987] [client 104.198.124.193:60256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.luisguacache.com"] [uri "/html/.git/config"] [unique_id "aprohWflIPWcU3B5upLuHAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-04 13:48:03
(1 week ago)
[04/Sep/2026:16:48:03 +0300] -- 104.198.124.193 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.g ...
show more
[04/Sep/2026:16:48:03 +0300] -- 104.198.124.193 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:31:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.198.124.193 (193.124.198.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.124.193 (193.124.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:31:45.160561 2026] [security2:error] [pid 697:tid 697] [client 104.198.124.193:51190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.roseweddingfavors.com"] [uri "/var/www/.git/config"] [unique_id "appXwZzhQoDBKFyiSYFTCgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
voormedia
2026-09-04 04:33:33
(1 week ago)
Accessed trap at '/.git/config'
Web App Attack
🇺🇸
n2nguyenn2nguyen
2026-09-04 04:19:24
(1 week ago)
Blocked by YFC Security on https://1904.brixzly.com — type: directory_scan_attempts
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 01:51:03
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 104.198.124.193 (193.124.198.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.124.193 (193.124.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 21:50:59.393520 2026] [security2:error] [pid 26201:tid 26201] [client 104.198.124.193:56138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "afjm.info"] [uri "/var/www/.git/config"] [unique_id "apokA2mRZ9yzr5iUTLkR6wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack