๐ฉ๐ช
iNetWorker
2026-09-16 14:00:00
(20 minutes ago)
trolling for resource vulnerabilities
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-16 13:42:47
(37 minutes ago)
Try to access /.git/config
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-09-16 13:42:03
(38 minutes ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
dot.mg
2026-09-16 12:42:13
(1 hour ago)
Bad behaviour
Web Spam
Anonymous
2026-09-16 12:13:50
(2 hours ago)
34.156.176.173 - - [16/Sep/2026:14:13:40 +0200] "GET /.git/config HTTP/1.1" 403 614 "-" "Mozilla/5.0 ...
show more
34.156.176.173 - - [16/Sep/2026:14:13:40 +0200] "GET /.git/config HTTP/1.1" 403 614 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.156.176.173 - - [16/Sep/2026:14:13:40 +0200] "GET /.env HTTP/1.1" 403 614 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.156.176.173 - - [16/Sep/2026:14:13:40 +0200] "GET /.env.local HTTP/1.1" 403 614 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.156.176.173 - - [16/Sep/2026:14:13:40 +0200] "GET /.env.production HTTP/1.1" 403 614 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.156.176.173 - - [16/Sep/2026:14:13:40 +0200] "GET /.env.staging HTTP/1.1" 403 614 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Ge
...
show less
DDoS Attack
๐ฆ๐บ
2000cn.com.au
2026-09-16 11:23:26
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-16 11:22:59
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.176.173 (173.176.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.176.173 (173.176.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 07:22:53.104555 2026] [security2:error] [pid 24465:tid 24465] [client 34.156.176.173:34782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ballast-capital.com"] [uri "/.git/config"] [unique_id "aqp8DcRlO6VpRuOLKbGB6wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 09:25:20
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.176.173 (173.176.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.176.173 (173.176.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 05:25:16.260830 2026] [security2:error] [pid 30592:tid 30592] [client 34.156.176.173:54954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "balivisaservice.com"] [uri "/.git/config"] [unique_id "aqpgfDtIrqZiF1ZUsh-QWwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-09-16 08:55:43
(5 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.156.176.173 (BE/Belgium/173.176.156. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.156.176.173 (BE/Belgium/173.176.156.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-16 05:43:18
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.156.176.173 (173.176.156.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.176.173 (173.176.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 01:43:12.666883 2026] [security2:error] [pid 15830:tid 15830] [client 34.156.176.173:56624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "baldventure.com.tomthomasplumbing.com"] [uri "/.git/config"] [unique_id "aqoscLQo-V0QldrdJh5QxgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-16 05:21:46
(8 hours ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ด
Abuse Buster
2026-09-16 05:13:08
(9 hours ago)
34.156.176.173 - - [16/Sep/2026:07:13:06 +0200] "GET /.git/config HTTP/1.1" 404 22 "-" "Mozilla/5.0 ...
show more
34.156.176.173 - - [16/Sep/2026:07:13:06 +0200] "GET /.git/config HTTP/1.1" 404 22 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.156.176.173 - - [16/Sep/2026:07:13:06 +0200] "GET /.env HTTP/1.1" 404 22 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-16 04:59:43
(9 hours ago)
Multiple WAF Violations
Web App Attack
๐ซ๐ท
Stara
2026-09-16 04:52:56
(9 hours ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-09-16 04:48:32
(9 hours ago)
[Wed Sep 16 14:48:30.993943 2026] [security2:error] [pid 341831] [client 34.156.176.173:41538] [clie ...
show more
[Wed Sep 16 14:48:30.993943 2026] [security2:error] [pid 341831] [client 34.156.176.173:41538] [client 34.156.176.173] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "balcomberetreat.com.au"] [uri "/"] [unique_id "aqofnmXocTijcET5kSO2eQAAAAE"]
...
show less
Web App Attack