🇵🇱
miriks
2026-09-07 15:18:24
(12 minutes ago)
Automated scan detected: GET /.git/config — UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKi ...
show more
Automated scan detected: GET /.git/config — UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Port Scan
Web App Attack
🇦🇺
rubixstudios
2026-09-07 15:12:02
(18 minutes ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 14:01:09
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.158.195.129 (129.195.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.195.129 (129.195.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 10:01:01.406561 2026] [security2:error] [pid 23440:tid 23440] [client 34.158.195.129:50986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.therealseska.com"] [uri "/.git/config"] [unique_id "ap7DneHisd4nwz0SnYpmBQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Mehmet_The_Script_Kiddie
2026-09-07 12:17:54
(3 hours ago)
CloudFlare WAF REPORT: Disobey robots.txt. Suspicious web crawler.
Bad Web Bot
Web App Attack
🇩🇪
Blexyel
2026-09-07 09:30:53
(5 hours ago)
34.158.195.129 - - [07/Sep/2026:11:30:52 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 ...
show more
34.158.195.129 - - [07/Sep/2026:11:30:52 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 09:20:14
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.195.129 (129.195.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.195.129 (129.195.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:20:07.078585 2026] [security2:error] [pid 17222:tid 17222] [client 34.158.195.129:48434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.thebestac.com"] [uri "/.git/config"] [unique_id "ap6Bx1jqIXF8l8RaI9Z73wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 08:52:30
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.195.129 (129.195.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.195.129 (129.195.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:52:26.935201 2026] [security2:error] [pid 25262:tid 25262] [client 34.158.195.129:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.theabstractpress.com"] [uri "/.git/config"] [unique_id "ap57StyfCjae8tgC5jeUKAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 08:20:37
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.195.129 (129.195.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.195.129 (129.195.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:20:32.507686 2026] [security2:error] [pid 3360:tid 3360] [client 34.158.195.129:33262] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.softwarezz.net"] [uri "/.git/config"] [unique_id "ap5z0PSDIxeH4VHusM33KwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
phoenix1jl96
2026-09-07 07:15:20
(8 hours ago)
2026/09/07 09:15:19 [error] 3857369#3857369: *219149 open() "/home/user-data/www/default/mailer/.env ...
show more
2026/09/07 09:15:19 [error] 3857369#3857369: *219149 open() "/home/user-data/www/default/mailer/.env" failed (2: No such file or directory), client: 34.158.195.129, server: autodiscover.test.ledemon.us, request: "GET /mailer/.env HTTP/1.1", host: "autodiscover.test.ledemon.us"
2026/09/07 09:15:19 [error] 3857369#3857369: *219149 open() "/usr/local/lib/roundcubemail/.env" failed (2: No such file or directory), client: 34.158.195.129, server: autodiscover.test.ledemon.us, request: "GET /mail/.env HTTP/1.1", host: "autodiscover.test.ledemon.us"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 05:06:58
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.195.129 (129.195.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.195.129 (129.195.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 01:06:52.384567 2026] [security2:error] [pid 2718:tid 2718] [client 34.158.195.129:46832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.technologymoods.com"] [uri "/.git/config"] [unique_id "ap5GbM1r8hSULJdeAZLpTgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Catalin Negru
2026-09-07 02:39:19
(12 hours ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
🇺🇸
Rocky Mountain Bioengineering Symposium
2026-09-06 23:57:33
(15 hours ago)
[Sun Sep 06 17:57:24.788238 2026] [authz_core:error] [pid 57186:tid 139765684893248] [client 34.158. ...
show more
[Sun Sep 06 17:57:24.788238 2026] [authz_core:error] [pid 57186:tid 139765684893248] [client 34.158.195.129:35488] AH01630: client denied by server configuration: /var/www/horde/.env.bak
[Sun Sep 06 17:57:32.421760 2026] [authz_core:error] [pid 57186:tid 139763998778944] [client 34.158.195.129:35488] AH01630: client denied by server configuration: /var/www/horde/.env.dist
[Sun Sep 06 17:57:32.619689 2026] [authz_core:error] [pid 57186:tid 139763755390528] [client 34.158.195.129:35488] AH01630: client denied by server configuration: /var/www/horde/.env.swp
...
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 23:55:42
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.195.129 (129.195.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.195.129 (129.195.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 19:55:37.066067 2026] [security2:error] [pid 28855:tid 28855] [client 34.158.195.129:47542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.sympalais.com"] [uri "/.git/config"] [unique_id "ap39eZhkwIqpyGoCJVisSgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 22:44:15
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.195.129 (129.195.158.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.195.129 (129.195.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:44:11.988136 2026] [security2:error] [pid 16404:tid 16404] [client 34.158.195.129:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.swarnar.com"] [uri "/.git/config"] [unique_id "ap3su5Ob5emiqoDCNLanOgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
factor1
2026-09-06 21:20:43
(18 hours ago)
CrowdSec at apollo Reports Abuse
Web App Attack