๐ฉ๐ช
macrob
2026-09-19 10:44:03
(7 hours ago)
2026/09/19 10:44:01 [error] 31034#31034: *14653831 access forbidden by rule, client: 34.158.20.109, ...
show more
2026/09/19 10:44:01 [error] 31034#31034: *14653831 access forbidden by rule, client: 34.158.20.109, server: bin.partners, request: "GET /.git/config HTTP/2.0", host: "bin.partners"
2026/09/19 10:44:01 [error] 31032#31032: *14653773 access forbidden by rule, client: 34.158.20.109, server: bin.partners, request: "GET /.env HTTP/2.0", host: "bin.partners"
2026/09/19 10:44:01 [error] 31032#31032: *14653773 access forbidden by rule, client: 34.158.20.109, server: bin.partners, request: "GET /.env.local HTTP/2.0", host: "bin.partners"
...
show less
Web App Attack
๐ฉ๐ช
macrob
2026-09-19 07:30:54
(10 hours ago)
2026/09/19 07:30:53 [error] 31031#31031: *14132003 access forbidden by rule, client: 34.158.20.109, ...
show more
2026/09/19 07:30:53 [error] 31031#31031: *14132003 access forbidden by rule, client: 34.158.20.109, server: bin-spin.com, request: "GET /.git/config HTTP/1.1", host: "bin-spin.com"
2026/09/19 07:30:53 [error] 31031#31031: *14132015 access forbidden by rule, client: 34.158.20.109, server: bin-spin.com, request: "GET /.env HTTP/1.1", host: "bin-spin.com"
2026/09/19 07:30:53 [error] 31031#31031: *14131966 access forbidden by rule, client: 34.158.20.109, server: bin-spin.com, request: "GET /.env.local HTTP/1.1", host: "bin-spin.com"
...
show less
Web App Attack
๐บ๐ธ
infra-monitor
2026-09-19 06:00:04
(12 hours ago)
Automated ban via infra-monitor: suspicious-probe
Port Scan
๐ฉ๐ช
kkw
2026-09-19 05:45:24
(12 hours ago)
[REDACTED] 34.158.20.109 - - [19/Sep/2026:07:45:24 +0200] "GET /.git/config HTTP/1.1" 404 557 "-" "M ...
show more
[REDACTED] 34.158.20.109 - - [19/Sep/2026:07:45:24 +0200] "GET /.git/config HTTP/1.1" 404 557 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
enjoyably
2026-09-19 05:36:26
(12 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
๐ฉ๐ช
macrob
2026-09-19 05:22:31
(13 hours ago)
2026/09/19 05:22:29 [error] 4160202#4160202: *13819356 access forbidden by rule, client: 34.158.20.1 ...
show more
2026/09/19 05:22:29 [error] 4160202#4160202: *13819356 access forbidden by rule, client: 34.158.20.109, server: bin-spin.com, request: "GET /.git/config HTTP/1.1", host: "bin-spin.com"
2026/09/19 05:22:29 [error] 4160202#4160202: *13819359 access forbidden by rule, client: 34.158.20.109, server: bin-spin.com, request: "GET /.env HTTP/1.1", host: "bin-spin.com"
2026/09/19 05:22:29 [error] 4160202#4160202: *13819367 access forbidden by rule, client: 34.158.20.109, server: bin-spin.com, request: "GET /.env.local HTTP/1.1", host: "bin-spin.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 05:15:16
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.20.109 (109.20.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.20.109 (109.20.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 01:15:10.832376 2026] [security2:error] [pid 22305:tid 22305] [client 34.158.20.109:39910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bimzi.net.darkcodedesign.net"] [uri "/.git/config"] [unique_id "aq4aXtqYEuFQShDA_CAAkAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
marten_o
2026-09-19 05:08:36
(13 hours ago)
34.158.20.109 - - [19/Sep/2026:07:08:35 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 404 236 "-" "Mozilla/ ...
show more
34.158.20.109 - - [19/Sep/2026:07:08:35 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 305 458
...
show less
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-19 01:35:01
(16 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-19 01:29:28
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.20.109 (109.20.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.20.109 (109.20.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 21:29:23.382689 2026] [security2:error] [pid 2169:tid 2169] [client 34.158.20.109:54418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bilund.com"] [uri "/.git/config"] [unique_id "aq3lcy83DRhvvayoGCSW8AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-09-19 01:04:48
(17 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 34.158.20.109 (CH/Switzerland/109.20.15 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.158.20.109 (CH/Switzerland/109.20.158.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-19 00:19:57
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.20.109 (109.20.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.20.109 (109.20.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 20:19:53.256686 2026] [security2:error] [pid 18174:tid 18174] [client 34.158.20.109:55116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "billystuff.net"] [uri "/.git/config"] [unique_id "aq3VKSoMZkxo78pxMDbWGQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-18 23:12:24
(19 hours ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-18 23:05:42
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.20.109 (109.20.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.20.109 (109.20.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 19:05:34.952918 2026] [security2:error] [pid 22765:tid 22765] [client 34.158.20.109:37972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "billwegener.net"] [uri "/.git/config"] [unique_id "aq3DvrNpG8bgdrCecpEMRAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 22:50:11
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.158.20.109 (109.20.158.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.158.20.109 (109.20.158.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 18:50:04.786288 2026] [security2:error] [pid 7868:tid 7868] [client 34.158.20.109:37136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "billswilliams.com"] [uri "/.git/config"] [unique_id "aq3AHAkKHiEha22dqeA2pwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack