🇩🇪
sprobst76
2026-09-06 05:48:52
(1 hour ago)
Blocked by Traefik Dashboard. Reason: Auto-blocked: AbuseIPDB: 100% score, 38 reports
Web App Attack
Hacking
🇳🇱
Site.eu
2026-09-06 03:03:56
(4 hours ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
langenkamp-media
2026-09-06 02:47:43
(4 hours ago)
Fail2Ban: Banned from jail nginx-scan-critical on 3dausdu.de
Web App Attack
🇺🇸
ruusvuu
2026-09-05 22:18:34
(9 hours ago)
Automated abuse report: 25 attack/probe requests from Google LLC / JP.
Targeted paths: /.claude/.cre ...
show more
Automated abuse report: 25 attack/probe requests from Google LLC / JP.
Targeted paths: /.claude/.credentials.json, /.codeium/windsurf/mcp_config.json, /.cursor/config.json, /mcp_config.json, /claude_desktop_config.json.
Sample log lines:
[shots] 📊 9/5/2026, 15:18:33 34.104.160.19 GET /.continue/config.json 404 - 1.002 ms
[shots] 📊 9/5/2026, 15:18:33 34.104.160.19 GET /llm_config.json 404 - 1.029 ms
[shots] 📊 9/5/2026, 15:18:33 34.104.160.19 GET /ai_config.json 404 - 1.250 ms
Detected by an automated web-server log monitor.
show less
Web App Attack
🇺🇸
Neosmith20
2026-09-05 09:23:05
(22 hours ago)
Knock-Knock honeypot brute-force: proto8 (1 total hits)
Brute-Force
🇧🇾
lns.bz
2026-09-05 06:52:27
(1 day ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 01:13:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.160.19 (19.160.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.160.19 (19.160.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 21:12:56.640191 2026] [security2:error] [pid 22500:tid 22500] [client 34.104.160.19:42282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kwim.internet-brochures.com"] [uri "/src/.git/config"] [unique_id "aptsmG03KNVnsRljbzMnWgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 23:07:04
(1 day ago)
Automated web scanner. Requested suspicious paths: /app/.git/config | /src/.git/config | /site/.git/ ...
show more
Automated web scanner. Requested suspicious paths: /app/.git/config | /src/.git/config | /site/.git/config | /www/.git/config | /.git/config | /var/www/.git/config | /wordpress/.git/config | /htdocs/.git/config | /public/.git/config | /backend/.git/config | /api/.git/config | /html/.git/config. UTC: 2026-09-04 22:40:26.
show less
Web App Attack
🇫🇷
SpaceHost-Server
2026-09-04 22:19:19
(1 day ago)
Brute-Force
Web App Attack
Anonymous
2026-09-04 22:05:08
(1 day ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 22:00:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.160.19 (19.160.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.160.19 (19.160.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 18:00:48.730198 2026] [security2:error] [pid 3843084:tid 3843128] [client 34.104.160.19:45792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.joshuapaulweckesser.com"] [uri "/backend/.git/config"] [unique_id "aps_kMBoHke7nYY3vRm6cAAAAQA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 21:59:19
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-03.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 21:32:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.104.160.19 (19.160.104.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.104.160.19 (19.160.104.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:32:39.902338 2026] [security2:error] [pid 1642183:tid 1642183] [client 34.104.160.19:52448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.webuydinwiddiehouses.com"] [uri "/src/.git/config"] [unique_id "aps497eCuR2dxzFkWCuDMAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 21:26:00
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇩🇪
macrob
2026-09-04 19:51:30
(1 day ago)
2026/09/04 19:51:29 [error] 754819#754819: *557028559 access forbidden by rule, client: 34.104.160.1 ...
show more
2026/09/04 19:51:29 [error] 754819#754819: *557028559 access forbidden by rule, client: 34.104.160.19, server: vn.finami.ph, request: "GET /app/.git/config HTTP/2.0", host: "vn.finami.ph"
2026/09/04 19:51:29 [error] 754818#754818: *557028558 access forbidden by rule, client: 34.104.160.19, server: vn.finami.ph, request: "GET /site/.git/config HTTP/2.0", host: "vn.finami.ph"
2026/09/04 19:51:29 [error] 754819#754819: *557028561 access forbidden by rule, client: 34.104.160.19, server: vn.finami.ph, request: "GET /var/www/.git/config HTTP/2.0", host: "vn.finami.ph"
...
show less
Web App Attack