🇺🇸
Lee Daniel
2026-09-12 01:54:44
(3 minutes ago)
212.237.120.142 - - [11/Sep/2026:21:54:44 -0400] "GET /.env HTTP/1.1" 403 6309 "http://ridethetideba ...
show more
212.237.120.142 - - [11/Sep/2026:21:54:44 -0400] "GET /.env HTTP/1.1" 403 6309 "http://ridethetidebarbados.com/.env" "curl/8.4.0"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-12 01:33:30
(24 minutes ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇩🇪
DEV-DNS
2026-09-12 01:29:53
(28 minutes ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇺🇸
TPI-Abuse
2026-09-12 01:27:36
(30 minutes ago)
(mod_security) mod_security (id:210492) triggered by 212.237.120.142 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 212.237.120.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 21:27:31.650462 2026] [security2:error] [pid 27672:tid 27672] [client 212.237.120.142:5934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sparemediagroup.com"] [uri "/.git/HEAD"] [unique_id "aqSqg0uNUo7ZRr8bkD5H0wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
JaRoNL
2026-09-12 01:10:32
(47 minutes ago)
212.237.120.142 - - \[12/Sep/2026:03:10:30 +0200\] "GET /.git/HEAD HTTP/1.1" 301 466 "-" "python-req ...
show more
212.237.120.142 - - \[12/Sep/2026:03:10:30 +0200\] "GET /.git/HEAD HTTP/1.1" 301 466 "-" "python-requests/2.31.0"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 01:09:25
(48 minutes ago)
(mod_security) mod_security (id:210492) triggered by 212.237.120.142 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 212.237.120.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 21:09:20.035708 2026] [security2:error] [pid 8688:tid 8688] [client 212.237.120.142:13314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jkg1.com"] [uri "/.git/HEAD"] [unique_id "aqSmQB2FOzRGAocDyI7yNAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 01:05:10
(52 minutes ago)
(caddyscan) Scanner path probe from 212.237.120.142 (IQ/Iraq/-): 5 in the last 3600 secs; Ports: *; ...
show more
(caddyscan) Scanner path probe from 212.237.120.142 (IQ/Iraq/-): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 212.237.120.142 - - [12/Sep/2026:01:05:02 +0000] "GET /.git/HEAD HTTP/1.1"
[REDACTED] 200 2627 212.237.120.142 - - [12/Sep/2026:01:05:03 +0000] "GET /.git/HEAD HTTP/1.1"
[REDACTED] 200 2627 212.237.120.142 - - [12/Sep/2026:01:05:04 +0000] "GET /.git/HEAD HTTP/1.1"
[REDACTED] 200 2627 212.237.120.142 - - [12/Sep/2026:01:05:08 +0000] "GET /.git/HEAD HTTP/1.1"
[REDACTED] 200 2627 212.237.120.142 - - [12/Sep/2026:01:05:08 +0000] "GET /app/.env HTTP/1.1"
show less
Port Scan
🇧🇪
cmbplf
2026-09-12 01:00:44
(57 minutes ago)
259 requests with url.path *.git/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-12 00:46:04
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 212.237.120.142 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 212.237.120.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 20:45:57.592272 2026] [security2:error] [pid 3770:tid 3792] [client 212.237.120.142:14351] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maestrosoler.com"] [uri "/.git/HEAD"] [unique_id "aqSgxfhleoDHIlhN6OeNpwAAARI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 00:25:24
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 212.237.120.142 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210492) triggered by 212.237.120.142 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 20:25:20.068166 2026] [security2:error] [pid 15750:tid 15750] [client 212.237.120.142:10031] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garyandthegroove.com"] [uri "/.git/HEAD"] [unique_id "aqSb8Pnl_Y3kw1QNXN-CnwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-12 00:12:57
(1 hour ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-12 00:12 UTC
show less
Bad Web Bot
🇫🇷
dynamix
2026-09-12 00:05:40
(1 hour ago)
Multiple WAF Violations
Web App Attack
🇩🇪
todix
2026-09-12 00:05:34
(1 hour ago)
Wordpress brute force or spam attempt from 212.237.120.142
Brute-Force
🇺🇸
IndigoRidge
2026-09-11 23:40:13
(2 hours ago)
212.237.120.142 - - [11/Sep/2026:19:40:13 -0400] "GET /app/.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 ( ...
show more
212.237.120.142 - - [11/Sep/2026:19:40:13 -0400] "GET /app/.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
212.237.120.142 - - [11/Sep/2026:19:40:13 -0400] "GET /.env HTTP/1.1" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
212.237.120.142 - - [11/Sep/2026:19:40:13 -0400] "GET /app/.env HTTP/1.1" 403 5530 "http://commercialpoolsvc.com/app/.env" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:121.0) Gecko/20100101 Firefox/121.0"
...
show less
Web App Attack
🇬🇧
consul.to
2026-09-11 23:18:41
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack