🇩🇪
Blexyel
2026-09-05 16:01:23
(1 day ago)
34.18.209.81 - - [05/Sep/2026:18:01:22 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 ( ...
show more
34.18.209.81 - - [05/Sep/2026:18:01:22 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
🇵🇱
Budyn
2026-09-05 14:20:58
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: mail.teddypot.cloud | URI: /.git/config | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 14:15:47
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇪🇸
alferez
2026-09-05 13:32:59
(1 day ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
Anonymous
2026-09-05 06:25:59
(1 day ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
🇫🇷
masterguru
2026-09-05 05:24:30
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
Anonymous
2026-09-05 03:40:00
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 02:10:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.18.209.81 (81.209.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.209.81 (81.209.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 22:10:01.341402 2026] [security2:error] [pid 5767:tid 5767] [client 34.18.209.81:44912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "harwoodmechanical.com"] [uri "/.git/config"] [unique_id "apt5-fGuxsdNdrkKhvJ1zQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 00:57:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.18.209.81 (81.209.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.209.81 (81.209.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 20:57:24.485002 2026] [security2:error] [pid 3410:tid 3410] [client 34.18.209.81:53274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "harvestfrc.com"] [uri "/.git/config"] [unique_id "apto9NDQqPm_S17isLWgRwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
john doe
2026-09-05 00:33:13
(1 day ago)
SentinelBot: Secret-path hunting (5 distinct paths): Env File Hunting (score: 67)
Bad Web Bot
🇳🇱
ConsulHosting
2026-09-04 22:35:33
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:09:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.18.209.81 (81.209.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.209.81 (81.209.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:08:55.530002 2026] [security2:error] [pid 1614362:tid 1614362] [client 34.18.209.81:53042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hartflicker.com"] [uri "/.git/config"] [unique_id "apszZ2rYA3arZjKh4F-aWwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Lee Daniel
2026-09-04 19:15:49
(2 days ago)
34.18.209.81 - - [04/Sep/2026:15:15:49 -0400] "GET /.env HTTP/1.1" 403 6287 "-" "Mozilla/5.0 (Macint ...
show more
34.18.209.81 - - [04/Sep/2026:15:15:49 -0400] "GET /.env HTTP/1.1" 403 6287 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 19:04:15
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.18.209.81 (81.209.18.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.18.209.81 (81.209.18.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 15:04:08.199160 2026] [security2:error] [pid 12425:tid 12425] [client 34.18.209.81:53592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "harrygant.com"] [uri "/.git/config"] [unique_id "apsWKGQpRReK6YgNcb1-2wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-04 19:01:00
(2 days ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack