Anonymous
2026-09-05 21:30:02
(2 hours ago)
suspicious request in access.log
Web App Attack
🇩🇪
Uwe Sarpe
2026-09-05 09:59:00
(14 hours ago)
[Sat Sep 05 11:59:00.226122 2026] [access_compat:error] [pid 2128:tid 2128] [client 34.156.125.183:4 ...
show more
[Sat Sep 05 11:59:00.226122 2026] [access_compat:error] [pid 2128:tid 2128] [client 34.156.125.183:49720] AH01797: client denied by server configuration: /var/www/app
[Sat Sep 05 11:59:00.230521 2026] [access_compat:error] [pid 2123:tid 2123] [client 34.156.125.183:49680] AH01797: client denied by server configuration: /var/www/.git
[Sat Sep 05 11:59:00.230593 2026] [access_compat:error] [pid 2127:tid 2127] [client 34.156.125.183:49648] AH01797: client denied by server configuration: /var/www/var
[Sat Sep 05 11:59:00.231184 2026] [access_compat:error] [pid 2122:tid 2122] [client 34.156.125.183:49632] AH01797: client denied by server configuration: /var/www/src
[Sat Sep 05 11:59:00.234748 2026] [access_compat:error] [pid 2125:tid 2125] [client 34.156.125.183:49710] AH01797: client denied by server configuration: /var/www/backend
...
show less
Brute-Force
Web App Attack
🇻🇳
trung.fun
2026-09-05 09:07:09
(14 hours ago)
DDoS, Hack, Brute Force, Web Attack
...
DDoS Attack
Web Spam
Hacking
Brute-Force
Web App Attack
🇧🇪
sid3windr
2026-09-05 08:33:52
(15 hours ago)
GET /.git/config (Tarpitted for 2m12s, wasted 7.85kB)
Web App Attack
🇺🇸
VanKoh
2026-09-05 07:47:17
(16 hours ago)
34.156.125.183 - - [05/Sep/2026:01:47:16 -0600] "GET /www/.git/config HTTP/1.1" 404 58187 "-" "crusa ...
show more
34.156.125.183 - - [05/Sep/2026:01:47:16 -0600] "GET /www/.git/config HTTP/1.1" 404 58187 "-" "crusader-worker/1.0"
34.156.125.183 - - [05/Sep/2026:01:47:16 -0600] "GET /site/.git/config HTTP/1.1" 404 58187 "-" "crusader-worker/1.0"
34.156.125.183 - - [05/Sep/2026:01:47:16 -0600] "GET /.git/config HTTP/1.1" 404 58187 "-" "crusader-worker/1.0"
...
show less
Port Scan
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 21:59:42
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-03.
show less
Web App Attack
SSH
Hacking
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 21:57:33
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 21:21:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.125.183 (183.125.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.125.183 (183.125.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:21:02.502727 2026] [security2:error] [pid 6711:tid 6711] [client 34.156.125.183:39230] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.globalmonitoringinc.com"] [uri "/www/.git/config"] [unique_id "aps2Pv3ws7i6eE1qcjr7xQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-09-04 20:54:56
(1 day ago)
Repeated exploit attempts, for example: /.git/config /.git/config (HTTP/1.1 port 443)
Web App Attack
Anonymous
2026-09-04 20:03:00
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇳🇱
e.fierstra
2026-09-04 16:11:23
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:51:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.125.183 (183.125.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.125.183 (183.125.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:51:01.688995 2026] [security2:error] [pid 22246:tid 22263] [client 34.156.125.183:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.peluqueriabuhos.com"] [uri "/site/.git/config"] [unique_id "apro5YzTykwJ83eSX2T55QAAAU8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-04 14:38:40
(1 day ago)
34.156.125.183 - - [04/Sep/2026:10:38:40 -0400] "GET /site/.git/config HTTP/1.1" 404 5554 "-" "crusa ...
show more
34.156.125.183 - - [04/Sep/2026:10:38:40 -0400] "GET /site/.git/config HTTP/1.1" 404 5554 "-" "crusader-worker/1.0"
34.156.125.183 - - [04/Sep/2026:10:38:40 -0400] "GET /app/.git/config HTTP/1.1" 404 5554 "-" "crusader-worker/1.0"
34.156.125.183 - - [04/Sep/2026:10:38:40 -0400] "GET /.git/config HTTP/1.1" 404 5554 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:26:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.125.183 (183.125.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.125.183 (183.125.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:26:23.668945 2026] [security2:error] [pid 2962:tid 2962] [client 34.156.125.183:60644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "railfanfromseo.com"] [uri "/src/.git/config"] [unique_id "apq47wzJaxsqkW8ZUqfCTQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:46:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.156.125.183 (183.125.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.125.183 (183.125.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:46:06.782837 2026] [security2:error] [pid 1327:tid 1327] [client 34.156.125.183:55238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ultratec.com.mx.activethinkers.net"] [uri "/site/.git/config"] [unique_id "apqTXvjF8E8pekGSXHSx7gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack