Anonymous
2026-09-05 21:53:12
(3 hours ago)
Bot / seems abusive / Apache connections: 61
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇩🇪
seal
2026-09-05 21:49:01
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/CVE-2017-9841
SSH
Brute-Force
🇺🇸
TPI-Abuse
2026-09-05 21:32:46
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 167.172.97.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.97.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:32:38.160574 2026] [security2:error] [pid 23224:tid 23224] [client 167.172.97.125:33652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.urbnet.com"] [uri "/.git/config"] [unique_id "apyKdjajxSviZmw9xO2S7wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
tmiland
2026-09-05 21:24:44
(3 hours ago)
(nginx_404) Dot directory Honeypot Trap 167.172.97.125 (DE/Germany/-): 2 in the last 3600 secs; IP: ...
show more
(nginx_404) Dot directory Honeypot Trap 167.172.97.125 (DE/Germany/-): 2 in the last 3600 secs; IP: 167.172.97.125; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 167.172.97.125 - - [05/Sep/2026:23:24:38 +0200] "GET /.git/config HTTP/1.1" 404 11225 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36" 167.172.97.125 - - [05/Sep/2026:23:24:39 +0200] "GET /.git/config HTTP/1.1" 404 11224 "http://autoconfig.*.*/.git/config" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36"
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-05 20:34:00
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 167.172.97.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.97.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:33:54.469677 2026] [security2:error] [pid 13535:tid 13535] [client 167.172.97.125:55890] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.ramseycountycorruption.com"] [uri "/.git/config"] [unique_id "apx8sjSBB4qTXj1h1JWeygAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
poundawebsiteltd
2026-09-05 20:27:14
(4 hours ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 167.172.97 ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 167.172.97.125 (DE/Germany/-): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 167.172.97.125 (DE/Germany/-): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 20:01:15
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 167.172.97.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.97.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:01:07.740981 2026] [security2:error] [pid 4386:tid 4386] [client 167.172.97.125:52274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.morninginc.com"] [uri "/.git/config"] [unique_id "apx1A1fmaB0x3rmK67eI6wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 19:33:58
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 167.172.97.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.97.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 15:33:52.524019 2026] [security2:error] [pid 4193:tid 4193] [client 167.172.97.125:35834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.kennedysplace.com"] [uri "/.git/config"] [unique_id "apxuoL2lCnAGN8JXlVtCZQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
TheDjRider
2026-09-05 19:32:23
(5 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-05T19:32:21.553503775Z. Context: http_status=404
show less
Web App Attack
🇫🇷
Octopuce
2026-09-05 19:25:02
(5 hours ago)
Aggressive web search of vulnerable pages: //assets/plugins/jQuery-File-Upload/server/php/ //vendor/ ...
show more
Aggressive web search of vulnerable pages: //assets/plugins/jQuery-File-Upload/server/php/ //vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php ...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 18:56:30
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 167.172.97.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.97.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 14:56:22.857151 2026] [security2:error] [pid 5240:tid 5240] [client 167.172.97.125:35066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.franzexpress.com"] [uri "/.git/config"] [unique_id "apxl1gCU11MrP0ziFgTPwwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 18:25:43
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 167.172.97.125 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 167.172.97.125 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 14:25:38.561249 2026] [security2:error] [pid 3505780:tid 3505929] [client 167.172.97.125:50074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autoconfig.crosstheatre.pwrcoupling.com"] [uri "/.git/config"] [unique_id "apxeoqeVUu6W99IeSwHdggAAAhc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
factor1
2026-09-05 18:03:00
(6 hours ago)
CrowdSec at saturn Reports Abuse
Web App Attack
🇮🇹
VHosting
2026-09-05 17:50:03
(7 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇵🇱
strefapi_com
2026-09-05 17:44:18
(7 hours ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack