🇳🇱
Eric
2026-09-06 08:02:44
(14 hours ago)
[Sun Sep 06 08:02:39.192826 2026] [security2:error] [pid 637204:tid 637204] [client 34.24.3.158:3940 ...
show more
[Sun Sep 06 08:02:39.192826 2026] [security2:error] [pid 637204:tid 637204] [client 34.24.3.158:39406] [client 34.24.3.158] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "94-209-38-171.cable.dynamic.v4.ziggo.nl"] [uri "/var/www/.git/config"] [unique_id "ap0eH5eQfY0YG3J6vrgQqAAAABg"]
[Sun Sep 06 08:02:39.198076 2026] [security2:error] [pid 637198:tid 637198] [client 34.24.3.158:39450] [client 34.24.3.158] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exc
...
show less
Hacking
Web App Attack
🇩🇪
Dennis
2026-09-06 07:17:00
(14 hours ago)
34.24.3.158 has been banned for triggering http-sensitive-files (5 events over 23.055579ms).
Brute-Force
Web App Attack
Anonymous
2026-09-06 06:51:37
(15 hours ago)
Multiple Git Repository Information Disclosure attempt.
Hacking
🇩🇪
big-cloud.nl
2026-09-05 22:24:37
(23 hours ago)
Try to access /src/.git/config
Web App Attack
🇹🇷
Detmach
2026-09-05 11:36:24
(1 day ago)
Security attack detected. Multiple failed attempts from 34.24.3.158. IP banned for 1440 minutes at 0 ...
show more
Security attack detected. Multiple failed attempts from 34.24.3.158. IP banned for 1440 minutes at 05.09.2026 14:36:24. Failed attempts: 1
show less
Brute-Force
🇩🇪
LRob
2026-09-04 22:57:29
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /www/.git/config (+11 more) | 2026-09-04 22:57 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:34:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.24.3.158 (158.3.24.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.3.158 (158.3.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:34:45.269147 2026] [security2:error] [pid 31036:tid 31036] [client 34.24.3.158:55896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.title37.com"] [uri "/htdocs/.git/config"] [unique_id "aps5dbRHwnf180hVzZHcuwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-04 19:33:31
(2 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇩🇪
NewGastroline
2026-09-04 19:00:11
(2 days ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 18:10:50
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.24.3.158 (158.3.24.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.3.158 (158.3.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 14:10:42.867419 2026] [security2:error] [pid 1105:tid 1105] [client 34.24.3.158:60740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "troop698.org.nilestree.com"] [uri "/app/.git/config"] [unique_id "apsJojvqAnsrLgS0ks1V-AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 17:43:48
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.24.3.158 (158.3.24.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.3.158 (158.3.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 13:43:45.004354 2026] [security2:error] [pid 30511:tid 30511] [client 34.24.3.158:39070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brbcash.com.bamedica.com"] [uri "/backend/.git/config"] [unique_id "apsDUfOi38uRnFkW_oi46AAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 15:56:23
(2 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇫🇷
Stara
2026-09-04 14:31:46
(2 days ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:34:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.24.3.158 (158.3.24.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.3.158 (158.3.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:34:47.084228 2026] [security2:error] [pid 28164:tid 28164] [client 34.24.3.158:55126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bentonflybox.com"] [uri "/www/.git/config"] [unique_id "aprI9x6BSTMugdBHfDpqDwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:01:30
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.24.3.158 (158.3.24.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.24.3.158 (158.3.24.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:01:24.726136 2026] [security2:error] [pid 1021:tid 1021] [client 34.24.3.158:45718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "quizzersform.cmabiblequizzing.org"] [uri "/site/.git/config"] [unique_id "apqzFPnW1ZpBSqraumctlQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack