🇩🇪
iNetWorker
2026-09-12 15:02:41
(2 hours ago)
trolling for resource vulnerabilities
Web App Attack
🇩🇪
neckaralb-admin.de
2026-09-12 14:48:55
(2 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇩🇪
LRob
2026-09-12 13:36:57
(3 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-12 13:36 UTC
show less
Hacking
Web App Attack
🇦🇺
2000cn.com.au
2026-09-12 12:52:17
(4 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-12 12:51:52
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.155.175.232 (232.175.155.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.155.175.232 (232.175.155.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 08:51:47.503323 2026] [security2:error] [pid 3259:tid 3259] [client 34.155.175.232:60446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ballast-capital.com"] [uri "/.git/config"] [unique_id "aqVK4xrjtLsoMYF2HvDhTwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 11:09:15
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.155.175.232 (232.175.155.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.155.175.232 (232.175.155.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 07:09:07.186295 2026] [security2:error] [pid 18353:tid 18353] [client 34.155.175.232:49054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "balivisaservice.com"] [uri "/.git/config"] [unique_id "aqUy04ItzmAc_LYCf5-2nwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-12 10:41:45
(6 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.155.175.232 (FR/France/232.175.155.3 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.155.175.232 (FR/France/232.175.155.34.bc.googleusercontent.com)
show less
SQL Injection
🇳🇴
Abuse Buster
2026-09-12 07:18:25
(9 hours ago)
34.155.175.232 - - [12/Sep/2026:09:18:23 +0200] "GET /.git/config HTTP/1.1" 404 22 "-" "Mozilla/5.0 ...
show more
34.155.175.232 - - [12/Sep/2026:09:18:23 +0200] "GET /.git/config HTTP/1.1" 404 22 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.155.175.232 - - [12/Sep/2026:09:18:23 +0200] "GET /.env HTTP/1.1" 404 22 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.155.175.232 - - [12/Sep/2026:09:18:23 +0200] "GET /.env.local HTTP/1.1" 404 22 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇩🇪
paissangroup
2026-09-12 07:03:26
(10 hours ago)
Multiple WAF Violations
Web App Attack
🇮🇹
VHosting
2026-09-12 07:00:10
(10 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇫🇷
Stara
2026-09-12 06:55:04
(10 hours ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 06:51:10
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.155.175.232 (232.175.155.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.155.175.232 (232.175.155.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 02:51:06.504919 2026] [security2:error] [pid 2463:tid 2463] [client 34.155.175.232:59392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autumn-kennedy.com"] [uri "/.git/config"] [unique_id "aqT2WsAk2ttgGmh1GVyzJwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-12 06:49:23
(10 hours ago)
[Sat Sep 12 16:49:23.132595 2026] [security2:error] [pid 748184] [client 34.155.175.232:45814] [clie ...
show more
[Sat Sep 12 16:49:23.132595 2026] [security2:error] [pid 748184] [client 34.155.175.232:45814] [client 34.155.175.232] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "balcomberetreat.com.au"] [uri "/"] [unique_id "aqT184wTZr3FA6xc0qwPtgAAAAc"]
...
show less
Web App Attack
🇧🇷
dominioz
2026-09-12 06:29:25
(10 hours ago)
2026-09-12 06:28:23 GET /.env - - 34.155.175.232 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_ ...
show more
2026-09-12 06:28:23 GET /.env - - 34.155.175.232 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 5124
2026-09-12 06:28:24 GET /.env.local - - 34.155.175.232 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 5136
2026-09-12 06:28:25 GET /.env.production - - 34.155.175.232 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 5146
2026-09-12 06:28:26 GET /.env.staging - - 34.155.175.232 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 5140
2026-09-12 06:28:26 GET /.env.development - - 34.155.175.232 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 404 5148
2026-09-12 06:28:28 GET /.en
...
show less
Web App Attack
🇫🇷
Baking333
2026-09-12 06:10:54
(10 hours ago)
[redacted] 34.155.175.232 - - [12/Sep/2026:07:10:52 +0100] "GET /.git/config HTTP/1.1" 302 1534 0/58 ...
show more
[redacted] 34.155.175.232 - - [12/Sep/2026:07:10:52 +0100] "GET /.git/config HTTP/1.1" 302 1534 0/58155 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" [redacted] 34.155.175.232 - - [12/Sep/2026:07:10:53 +0100] "GET /.env HTTP/1.1" 302 1534 0/39671 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack