🇩🇪
kivitendo.de
2026-09-05 09:43:33
(4 hours ago)
{"reqId":"QdljwIcdKuecCpYIDeOf","level":1,"time":"2026-09-05T09:43:32+00:00","remoteAddr":"34.74.75. ...
show more
{"reqId":"QdljwIcdKuecCpYIDeOf","level":1,"time":"2026-09-05T09:43:32+00:00","remoteAddr":"34.74.75.123","user":"--","app":"core","method":"GET","url":"/www/.git/config","scriptName":"/index.php","message":"Trusted domain error. \"34.74.75.123\" tried to access using \"mail.novoclon.com\" as host.","userAgent":"crusader-worker/1.0","version":"32.0.14.1","data":{"app":"core"}}
{"reqId":"OIlP3mjubgt4jByuMFUA","level":1,"time":"2026-09-05T09:43:32+00:00","remoteAddr":"34.74.75.123","user":"--","app":"core","method":"GET","url":"/var/www/.git/config","scriptName":"/index.php","message":"Trusted domain error. \"34.74.75.123\" tried to access using \"mail.novoclon.com\" as host.","userAgent":"crusader-worker/1.0","version":"32.0.14.1","data":{"app":"core"}}
{"reqId":"KFRZnZUjIcuEnbBj9uLC","level":1,"time":"2026-09-05T09:43:32+00:00","remoteAddr":"34.74.75.123","user":"--","app":"core","method":"GET","url":"/api/.git/config","scriptName":"/index.php","message":"Trusted domain error. \"34.74.7
...
show less
Brute-Force
Web App Attack
🇧🇾
lns.bz
2026-09-05 06:46:16
(7 hours ago)
Too many 404 requests [BY]
Web App Attack
🇬🇧
consul.to
2026-09-05 01:30:32
(12 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 01:18:10
(13 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.74.75.123 (123.75.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.74.75.123 (123.75.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 21:18:07.185884 2026] [security2:error] [pid 7211:tid 7211] [client 34.74.75.123:45692] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "leseberg.com"] [uri "/public/.git/config"] [unique_id "apttz59_j49hn13Su3458gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇵🇱
Budyn
2026-09-04 23:58:46
(14 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: teddypot.space | URI: /src/.git/config | UA: crusader-worker/1.0 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
Anonymous
2026-09-04 22:40:01
(15 hours ago)
suspicious request in access.log
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 21:57:03
(16 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.74.75.123 (US/United States/123.75.74.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.74.75.123 (US/United States/123.75.74.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:09:07
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.75.123 (123.75.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.75.123 (123.75.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:09:00.593648 2026] [security2:error] [pid 30986:tid 30986] [client 34.74.75.123:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.azdevco.com"] [uri "/public/.git/config"] [unique_id "apszbI377zJkU3xF7AxCfAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 19:58:09
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.75.123 (123.75.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.75.123 (123.75.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 15:58:01.605653 2026] [security2:error] [pid 32737:tid 32737] [client 34.74.75.123:52572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vientodelevante.es"] [uri "/api/.git/config"] [unique_id "apsiyVTVhDiUEwaWn6rK_AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 18:59:05
(19 hours ago)
Sensitive file access attempt
Hacking
🇺🇸
TPI-Abuse
2026-09-04 16:11:20
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.74.75.123 (123.75.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.75.123 (123.75.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 12:11:13.969100 2026] [security2:error] [pid 31502:tid 31502] [client 34.74.75.123:59840] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nancybarrera.com"] [uri "/var/www/.git/config"] [unique_id "aprtoecXu8rwOtLosfNVUgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:42:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.74.75.123 (123.75.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.75.123 (123.75.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:42:13.446865 2026] [security2:error] [pid 11498:tid 11498] [client 34.74.75.123:37794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boatpeople.org"] [uri "/wordpress/.git/config"] [unique_id "aprKtUFKTNQ0h1vfLeTSKgAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:03:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.74.75.123 (123.75.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.75.123 (123.75.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:03:03.917522 2026] [security2:error] [pid 27629:tid 27629] [client 34.74.75.123:54590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hillygames.com"] [uri "/site/.git/config"] [unique_id "aprBhzzwnveTqT9AWOFVlwAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:26:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.74.75.123 (123.75.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.75.123 (123.75.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:26:45.068260 2026] [security2:error] [pid 31466:tid 31466] [client 34.74.75.123:40362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seeingblue.com"] [uri "/.git/config"] [unique_id "apqq9WcUQt4r7weNvlyOOgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:28:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.74.75.123 (123.75.74.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.74.75.123 (123.75.74.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:28:39.774795 2026] [security2:error] [pid 23430:tid 23430] [client 34.74.75.123:49782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.duhcathlon.com"] [uri "/htdocs/.git/config"] [unique_id "appXB4vTEx3UW2KK9kPD9QAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack