๐บ๐ธ
IndigoRidge
2026-09-02 16:25:49
(32 minutes ago)
156.225.20.122 - - [02/Sep/2026:12:25:47 -0400] "GET /.git/config HTTP/1.1" 503 5664 "-" "Mozilla/5. ...
show more
156.225.20.122 - - [02/Sep/2026:12:25:47 -0400] "GET /.git/config HTTP/1.1" 503 5664 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
156.225.20.122 - - [02/Sep/2026:12:25:48 -0400] "GET /.git/config HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
156.225.20.122 - - [02/Sep/2026:12:25:48 -0400] "GET /.git/config HTTP/1.1" 503 5664 "http://upstatescrealtor.com/.git/config" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Web App Attack
Anonymous
2026-09-02 16:21:37
(36 minutes ago)
156.225.20.122 - - [02/Sep/2026:16:21:37 +0000] "GET /.git/config HTTP/1.1" 404 7825 "-" "Mozilla/5. ...
show more
156.225.20.122 - - [02/Sep/2026:16:21:37 +0000] "GET /.git/config HTTP/1.1" 404 7825 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 13:52:34
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 156.225.20.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 156.225.20.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 09:52:26.437048 2026] [security2:error] [pid 5066:tid 5066] [client 156.225.20.122:55302] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alccontractorsllc.com"] [uri "/.git/config"] [unique_id "apgqGkfthjKop51i6j87CgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-02 12:38:09
(4 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 156.225.20.122 (SC/Seychelles/-): 1 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 156.225.20.122 (SC/Seychelles/-): 1 in the last 3600 secs
show less
Web App Attack
Anonymous
2026-09-02 07:20:02
(9 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 07:09:01
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 156.225.20.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 156.225.20.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 03:08:53.991624 2026] [security2:error] [pid 16896:tid 16896] [client 156.225.20.122:54368] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "accinternational.net"] [uri "/.git/config"] [unique_id "apfLhT1RR0LrZJH2fWDWZgAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-09-02 06:53:45
(10 hours ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ญ๐บ
DumaNet
2026-09-02 06:49:00
(10 hours ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 01. 14:22:11
Source IP: 156.22 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Sep 01. 14:22:11
Source IP: 156.225.20.122
Portion of the log(s):
156.225.20.122 - [01/Sep/2026:14:22:11 +0200] "POST /index.php HTTP/1.1" 500 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
156.225.20.122 - [01/Sep/2026:14:22:07 +0200] "POST / HTTP/1.1" 500 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
156.225.20.122 - [01/Sep/2026:14:22:00 +0200] "POST /index.php?rest_route=/batch/v1 HTTP/1.1" 500 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
156.225.20.122 - [01/Sep/2026:14:21:44 +0200] "POST /?rest_route=/batch/v1 HTTP/1.1" 500 331 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 06:19:34
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 156.225.20.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 156.225.20.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 02:19:30.000189 2026] [security2:error] [pid 29288:tid 29288] [client 156.225.20.122:51176] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ralphharris.org"] [uri "/wp-config.php.bak"] [unique_id "ape_8UQUmk444DJxJCvywQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 01:38:32
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 156.225.20.122 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 156.225.20.122 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 21:38:25.523933 2026] [security2:error] [pid 23183:tid 23183] [client 156.225.20.122:53710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tradelosangeles.directoryofbikes.com"] [uri "/.git/config"] [unique_id "apd-Ef3SziAXTX8PVZMITAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-09-01 19:50:09
(21 hours ago)
Aggressive web search of vulnerable pages: /.env /database.sql /wp-content/backups/ /wp-content/back ...
show more
Aggressive web search of vulnerable pages: /.env /database.sql /wp-content/backups/ /wp-content/backup/ /wp-content/backup-db/ /wp-content/updr ...
show less
Web App Attack
๐บ๐ธ
mnsf
2026-09-01 13:05:48
(1 day ago)
Abuse Detected (20)
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-09-01 10:17:23
(1 day ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: POST | path: /wp-json/batch/v1 | 2026-09-01 10:17 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-09-01 08:05:53
(1 day ago)
Abuse Detected (11)
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-09-01 00:55:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack