🇵🇱
miriks
2026-09-12 10:42:26
(3 minutes ago)
Automated scan detected: GET /.git-credentials — UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537 ...
show more
Automated scan detected: GET /.git-credentials — UA: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36
show less
Port Scan
Web App Attack
🇩🇪
palla89
2026-09-12 10:40:29
(5 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 45.138.12.16 (LT/Lithuania/-)
SQL Injection
Anonymous
2026-09-12 10:38:14
(7 minutes ago)
IP matched detection query many 3xx errors.
Brute-Force
🇬🇧
Apache
2026-09-12 10:29:34
(16 minutes ago)
(mod_security) mod_security (id:210492) triggered by 45.138.12.16 (LT/Lithuania/-): 5 in the last 30 ...
show more
(mod_security) mod_security (id:210492) triggered by 45.138.12.16 (LT/Lithuania/-): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇫🇷
phoenix1jl96
2026-09-12 10:28:33
(17 minutes ago)
2026/09/12 12:28:29 [error] 4744#4744: *64251 open() "/home/user-data/www/default/cgi-bin/printenv" ...
show more
2026/09/12 12:28:29 [error] 4744#4744: *64251 open() "/home/user-data/www/default/cgi-bin/printenv" failed (2: No such file or directory), client: 45.138.12.16, server: dsatec.info, request: "GET /cgi-bin/printenv HTTP/1.1", host: "dsatec.info"
2026/09/12 12:28:33 [error] 4744#4744: *64251 open() "/home/user-data/www/default/cgi-bin/printenv.pl" failed (2: No such file or directory), client: 45.138.12.16, server: dsatec.info, request: "GET /cgi-bin/printenv.pl HTTP/1.1", host: "dsatec.info"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 10:26:09
(19 minutes ago)
(mod_security) mod_security (id:210492) triggered by 45.138.12.16 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.138.12.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 06:26:03.814893 2026] [security2:error] [pid 24265:tid 24265] [client 45.138.12.16:42910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crossfiregold.com"] [uri "/.git/"] [unique_id "aqUou80eK_5_FfNDHc0sWQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 10:06:38
(38 minutes ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇩🇪
AetherFox
2026-09-12 10:05:44
(39 minutes ago)
AetherFox VoidGuard detected: [Sat Sep 12 10:05:05.520050 2026] [authz_core:error] [pid 1930588:tid ...
show more
AetherFox VoidGuard detected: [Sat Sep 12 10:05:05.520050 2026] [authz_core:error] [pid 1930588:tid 1930637] [client 45.138.12.16:56862] AH01630: client denied by server configuration: proxy:https://[MASKED]/.git-credentials, referer: http://draconigen.de/.git-credentials
[Sat Sep 12 10:05:10.019966 2026] [authz_core:error] [pid 1930588:tid 1930641] [client 45.138.12.16:56862] AH01630: client denied by server configuration: proxy:https://[MASKED]/.git/, referer: http://draconigen.de/.git/
[Sat Sep 12 10:05:27.201100 2026] [authz_core:error] [pid 1930588:tid 1930601] [client 45.138.12.16:57148] AH01630: client denied by server configuration: proxy:https://[MASKED]/.git/logs/HEAD, referer: http://draconigen.de/.git/logs/HEAD
[Sat Sep 12 10:05:37.598387 2026] [authz_core:error] [pid 1930588:tid 1930603] [client 45.138.12.16:57294] AH01630: client denied by server configuration: proxy:https://[MASKED]/.github/workflows/CI.yml, referer: http://draconigen.de/.
...
show less
Bad Web Bot
Web App Attack
🇩🇪
tentwentyfour
2026-09-12 10:05:01
(40 minutes ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack
🇩🇪
Nixwig
2026-09-12 09:57:02
(48 minutes ago)
45.138.12.16 - - [12/Sep/2026:09:53:02 +0000] "GET /.git/ HTTP/1.1" 404 749 "http://mattiaferrara.de ...
show more
45.138.12.16 - - [12/Sep/2026:09:53:02 +0000] "GET /.git/ HTTP/1.1" 404 749 "http://mattiaferrara.dev/.git/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
45.138.12.16 - - [12/Sep/2026:09:53:08 +0000] "GET /.git/config HTTP/1.1" 404 749 "http://mattiaferrara.dev/.git/config" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
45.138.12.16 - - [12/Sep/2026:09:57:01 +0000] "GET /.env HTTP/1.1" 404 748 "http://mattiaferrara.dev/.env" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
...
show less
Web App Attack
🇺🇸
mibbsdevs
2026-09-12 09:53:25
(52 minutes ago)
CoffeePot Web: Automated bad bot directory fuzzing and high-rate 404 probing.
Port Scan
Bad Web Bot
🇫🇷
Baking333
2026-09-12 09:52:13
(53 minutes ago)
[redacted] 45.138.12.16 - - [12/Sep/2026:10:52:09 +0100] "GET /.git/ HTTP/1.1" 301 5811 0/727 "http: ...
show more
[redacted] 45.138.12.16 - - [12/Sep/2026:10:52:09 +0100] "GET /.git/ HTTP/1.1" 301 5811 0/727 "http://[redacted]/.git/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36" [redacted] 45.138.12.16 - - [12/Sep/2026:10:52:11 +0100] "GET /.git HTTP/1.1" 302 6753 0/48755 "https://[redacted]/.git/" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 09:47:19
(58 minutes ago)
(mod_security) mod_security (id:210492) triggered by 45.138.12.16 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 45.138.12.16 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 05:47:15.862539 2026] [security2:error] [pid 15181:tid 15181] [client 45.138.12.16:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vidacellenlaweb.com"] [uri "/.git/"] [unique_id "aqUfo9iAYUPCz5WdIFrBlgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Starburst SysOp Team
2026-09-12 09:36:39
(1 hour ago)
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 16.12.138.45.rbl.malwar ...
show more
Malware host (X-Forwarded-For) detected by rbl.malware.expert. RBL lookup of 16.12.138.45.rbl.malware.expert succeeded at REQUEST_HEADERS:X-Forwarded-For. (1001000-nue6-2)
show less
Hacking
🇳🇱
Alt255
2026-09-12 09:34:03
(1 hour ago)
45.138.12.16 - - [12/Sep/2026:11:34:03 +0200] "GET /.git/ HTTP/1.1" 503 1883 "-" "Mozilla/5.0 (X11; ...
show more
45.138.12.16 - - [12/Sep/2026:11:34:03 +0200] "GET /.git/ HTTP/1.1" 503 1883 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack