🇫🇷
Baking333
2026-09-14 12:23:13
(3 hours ago)
[redacted] 34.87.156.111 - - [14/Sep/2026:13:23:11 +0100] "GET /.git/config HTTP/1.1" 302 1538 0/378 ...
show more
[redacted] 34.87.156.111 - - [14/Sep/2026:13:23:11 +0100] "GET /.git/config HTTP/1.1" 302 1538 0/37826 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" [redacted] 34.87.156.111 - - [14/Sep/2026:13:23:12 +0100] "GET /.env HTTP/1.1" 302 1537 0/40684 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 09:16:36
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.156.111 (111.156.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.156.111 (111.156.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 05:16:29.107829 2026] [security2:error] [pid 29350:tid 29350] [client 34.87.156.111:38804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trendingnowsales.com.wholesalelivelobsters.com"] [uri "/.git/config"] [unique_id "aqe7bXpaBUjjcE-8p4tpYgAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
nzhost.co.nz
2026-09-14 08:56:35
(6 hours ago)
$f2bV_matches
Hacking
Brute-Force
Anonymous
2026-09-14 06:07:05
(9 hours ago)
Automated web scanner. Requested suspicious paths: /.git/config. UTC: 2026-09-14 06:00:10.
Web App Attack
Anonymous
2026-09-14 04:34:04
(11 hours ago)
34.87.156.111 - - [14/Sep/2026:06:33:58 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows N ...
show more
34.87.156.111 - - [14/Sep/2026:06:33:58 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.87.156.111 - - [14/Sep/2026:06:33:58 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.87.156.111 - - [14/Sep/2026:06:33:58 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.87.156.111 - - [14/Sep/2026:06:33:59 +0200] "GET /.git/config HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.87.156.111 - - [14/Sep/2026:06:33:59 +0200] "GET /.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.87.156.111 - - [14/Sep/2026:0
...
show less
Bad Web Bot
Web App Attack
🇺🇸
JonathanYoung2161
2026-09-14 03:51:37
(11 hours ago)
trekgalactic.org 34.87.156.111 - - [13/Sep/2026:22:51:34 -0500] "GET /.git/config HTTP/2.0" 403 3330 ...
show more
trekgalactic.org 34.87.156.111 - - [13/Sep/2026:22:51:34 -0500] "GET /.git/config HTTP/2.0" 403 3330 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
trekgalactic.org 34.87.156.111 - - [13/Sep/2026:22:51:35 -0500] "GET /.env HTTP/2.0" 403 3330 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
trekgalactic.org 34.87.156.111 - - [13/Sep/2026:22:51:35 -0500] "GET /.env.local HTTP/2.0" 403 3330 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
🇨🇭
leo1305
2026-09-14 03:30:11
(12 hours ago)
CrowdSec detection | scenario: http-sensitive-files
Web App Attack
Exploited Host
🇳🇱
middelkoopcc
2026-09-14 03:01:01
(12 hours ago)
2026-09-14 04:59:15 GET /.git/config [301] && 2026-09-14 04:59:16 GET /.env [301] && 2026-09-14 04:5 ...
show more
2026-09-14 04:59:15 GET /.git/config [301] && 2026-09-14 04:59:16 GET /.env [301] && 2026-09-14 04:59:16 GET /.git/config [301] && 375 more within 20 minutes
show less
Web App Attack
🇳🇱
debestelapp
2026-09-13 20:10:11
(19 hours ago)
Web App Attack
🇳🇱
Site.eu
2026-09-13 19:59:27
(19 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-13 17:09:31
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.156.111 (111.156.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.156.111 (111.156.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 13:09:24.491345 2026] [security2:error] [pid 9369:tid 9369] [client 34.87.156.111:52298] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "treadbox.net"] [uri "/.git/config"] [unique_id "aqbYxLPi2NFMRelvgshpTgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 16:08:12
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.87.156.111 (111.156.87.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.156.111 (111.156.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 12:08:08.429667 2026] [security2:error] [pid 807:tid 807] [client 34.87.156.111:51090] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trclegacyholdings.org.ryanc.net"] [uri "/.git/config"] [unique_id "aqbKaDnBQi-d1gq2P92OOQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 14:54:54
(2 days ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
Anonymous
2026-09-12 09:08:08
(2 days ago)
[ns3.backorder.gr] httpd-config-scan: sites=www.update.medisto.gr; logs=/var/log/httpd/domains/updat ...
show more
[ns3.backorder.gr] httpd-config-scan: sites=www.update.medisto.gr; logs=/var/log/httpd/domains/update.medisto.gr.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
🇩🇪
konseptit
2026-09-12 05:55:12
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.87.156.111 (SG/Singapore/111.156.87. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.87.156.111 (SG/Singapore/111.156.87.34.bc.googleusercontent.com)
show less
SQL Injection