🇺🇸
jcbriar
2026-09-04 07:59:10
(16 minutes ago)
Searching for vulnerable scripts
Hacking
Web App Attack
🇫🇷
Baking333
2026-09-04 07:39:25
(35 minutes ago)
[redacted] 34.24.121.141 - - [04/Sep/2026:08:39:23 +0100] "GET /.git/config HTTP/1.1" 302 6714 0/406 ...
show more
[redacted] 34.24.121.141 - - [04/Sep/2026:08:39:23 +0100] "GET /.git/config HTTP/1.1" 302 6714 0/40643 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36" [redacted] 34.24.121.141 - - [04/Sep/2026:08:39:24 +0100] "GET /.git/config HTTP/1.1" 301 559 0/172 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
🇺🇸
JustMeHere
2026-09-04 07:31:50
(43 minutes ago)
[Fri Sep 04 03:31:45.567934 2026] [security2:error] [pid 1342:tid 1373] [client 34.24.121.141:40430] ...
show more
[Fri Sep 04 03:31:45.567934 2026] [security2:error] [pid 1342:tid 1373] [client 34.24.121.141:40430] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "yorknation.com"] [uri "/.git/config"] [unique_id "appz4WN-eyWaC7MkSi3CnQAAAMM"]
...
show less
Web App Attack
🇮🇩
Burayot
2026-09-04 04:53:08
(3 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.24.121.141 (US/United States/141 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.24.121.141 (US/United States/141.121.24.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:51:00
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.121.141 (141.121.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.121.141 (141.121.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:50:54.423371 2026] [security2:error] [pid 30538:tid 30538] [client 34.24.121.141:7552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sonoranwaterworks.com"] [uri "/.git/config"] [unique_id "appOLrgqQqQXXcr6NBmvogAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-04 03:03:35
(5 hours ago)
[Fri Sep 04 13:03:34.259497 2026] [security2:error] [pid 607741] [client 34.24.121.141:11916] [clien ...
show more
[Fri Sep 04 13:03:34.259497 2026] [security2:error] [pid 607741] [client 34.24.121.141:11916] [client 34.24.121.141] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "valueaddedpromotions.com.au"] [uri "/.git/config"] [unique_id "apo1BvyF72na_sP9TZO2_gAAAAU"]
...
show less
Web App Attack
🇺🇸
etu brutus
2026-09-04 01:07:46
(7 hours ago)
34.24.121.141 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host
🇩🇪
BlueWire Hosting
2026-09-04 01:05:31
(7 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
Anonymous
2026-09-04 00:48:52
(7 hours ago)
34.24.121.141 - - [03/Sep/2026:21:48:51 -0300] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (W ...
show more
34.24.121.141 - - [03/Sep/2026:21:48:51 -0300] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
🇺🇸
Mundo Bueno
2026-09-04 00:26:35
(7 hours ago)
[ISILIA Protection v2.1] Tentative d'accès: /.git/config | Pays: US | UA: Mozilla/5.0 (Windows NT 10 ...
show more
[ISILIA Protection v2.1] Tentative d'accès: /.git/config | Pays: US | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Sa
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 23:22:14
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.24.121.141 (141.121.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.121.141 (141.121.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:22:08.048510 2026] [security2:error] [pid 8331:tid 8331] [client 34.24.121.141:21636] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jasconius.org"] [uri "/.git/config"] [unique_id "apoBIB4iU1Cu7idvPlOEwQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
AvonleaConsulting
2026-09-03 22:59:17
(9 hours ago)
Attempts to probe web pages for vulnerable PHP or other applications
Web App Attack
🇭🇳
soporte
2026-09-03 22:27:37
(9 hours ago)
Probe for vulnerabilities. Path attempted: /.git/config
Web App Attack
🇬🇧
AvonleaConsulting
2026-09-03 22:20:55
(9 hours ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 22:01:17
(10 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.24.121.141 (141.121.24.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.24.121.141 (141.121.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:01:11.458591 2026] [security2:error] [pid 14917:tid 14917] [client 34.24.121.141:11610] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "spmbookings.com"] [uri "/.git/config"] [unique_id "apnuJ_gBdX3SbdLylvDnOgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack