🇩🇪
DyhnenTv
2026-09-10 07:48:08
(40 minutes ago)
CrowdSec webserver: crowdsecurity/http-sensitive-files
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-10 05:41:53
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.176.156.4 (4.156.176.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.156.4 (4.156.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 01:41:46.299678 2026] [security2:error] [pid 11932:tid 11932] [client 34.176.156.4:55374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vpatech.com"] [uri "/.git/config"] [unique_id "aqJDGvC2Xi--D-iOfdA6PAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Savvii
2026-09-10 04:31:04
(3 hours ago)
20 attempts against mh-misbehave-ban on sea
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 03:58:22
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.176.156.4 (4.156.176.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.156.4 (4.156.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 23:58:18.512915 2026] [security2:error] [pid 8623:tid 8623] [client 34.176.156.4:53058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thenorwoods.name"] [uri "/.git/config"] [unique_id "aqIq2mpaw5jcuSIwbZssQgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
Anytech
2026-09-10 00:53:01
(7 hours ago)
Blocked by ConnMonitor
Web App Attack
🇳🇱
middelkoopcc
2026-09-10 00:45:13
(7 hours ago)
2026-09-10 02:40:23 GET /.git/config [404] && 2026-09-10 02:40:26 GET /.env [404] && 2026-09-10 02:4 ...
show more
2026-09-10 02:40:23 GET /.git/config [404] && 2026-09-10 02:40:26 GET /.env [404] && 2026-09-10 02:40:36 GET /.env.bak [404] && 121 more within 20 minutes
show less
Web App Attack
🇪🇸
pipeline.es
2026-09-09 19:49:43
(12 hours ago)
Web scanning / probing for vulnerable paths | URL: /mailer/.env | Evidence: altovolta.es 34.176.156. ...
show more
Web scanning / probing for vulnerable paths | URL: /mailer/.env | Evidence: altovolta.es 34.176.156.4 - - [09/Sep/2026:21:48:36 +0200] \"GET /mailer/.env HTTP/1.1\" 404 209 \"-\" \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=CL | ASN: GOOGLE-CLOUD-PLATFORM | Country: CL
show less
Port Scan
Web App Attack
🇧🇪
cmbplf
2026-09-09 18:51:20
(13 hours ago)
3.700 requests with url.path *.env
487 requests with url.path *phpinfo.php
Brute-Force
Bad Web Bot
Anonymous
2026-09-09 17:20:38
(15 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇫🇷
masterguru
2026-09-09 11:57:26
(20 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
Anonymous
2026-09-09 11:56:06
(20 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 11:51:00
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.176.156.4 (4.156.176.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.156.4 (4.156.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:50:53.239143 2026] [security2:error] [pid 4862:tid 4862] [client 34.176.156.4:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ndanetworks.com"] [uri "/.git/config"] [unique_id "aqFIHUdbHiuDwrT7XJEZxAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 11:24:37
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.176.156.4 (4.156.176.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.176.156.4 (4.156.176.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 07:24:29.783096 2026] [security2:error] [pid 6753:tid 6753] [client 34.176.156.4:56098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ndakno.com"] [uri "/.git/config"] [unique_id "aqFB7az5Uj9vND7E9SBemgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack