๐ณ๐ฑ
homeshowdomain.nl
2026-07-24 22:02:11
(7 hours ago)
Auto-ban: >3000 req/min op 2026-07-24
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-07-24 15:11:14
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.76.81.12 (ec2-3-76-81-12.eu-central-1.compute ...
show more
(mod_security) mod_security (id:210492) triggered by 3.76.81.12 (ec2-3-76-81-12.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 11:11:06.835936 2026] [security2:error] [pid 2652037:tid 2652037] [client 3.76.81.12:60752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hppagewideflorida.com.computersraleigh.com"] [uri "/.git/config"] [unique_id "amOAikdU0sXPl0ywkH72SAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 14:18:49
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.76.81.12 (ec2-3-76-81-12.eu-central-1.compute ...
show more
(mod_security) mod_security (id:210492) triggered by 3.76.81.12 (ec2-3-76-81-12.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 10:18:42.650325 2026] [security2:error] [pid 30704:tid 30704] [client 3.76.81.12:56674] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.howtokeepgoodemployeescom.indie100.com"] [uri "/.git/config"] [unique_id "amN0QtY00b4E240nYf2x9gAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 13:55:33
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.76.81.12 (ec2-3-76-81-12.eu-central-1.compute ...
show more
(mod_security) mod_security (id:210492) triggered by 3.76.81.12 (ec2-3-76-81-12.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 09:55:27.656390 2026] [security2:error] [pid 1118927:tid 1118948] [client 3.76.81.12:39144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.howlerrock.workconfident.com"] [uri "/.git/config"] [unique_id "amNuz1vDZpbNNbnMcxv6aQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-07-24 13:35:02
(15 hours ago)
crowdsecurity/http-crawl-non_statics
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 13:18:56
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.76.81.12 (ec2-3-76-81-12.eu-central-1.compute ...
show more
(mod_security) mod_security (id:210492) triggered by 3.76.81.12 (ec2-3-76-81-12.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 09:18:52.073063 2026] [security2:error] [pid 3733040:tid 3733040] [client 3.76.81.12:58134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.houstontenemosunproblema.verdadesreales.com"] [uri "/.git/config"] [unique_id "amNmPFfIumehmT_X9CxebgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-07-24 10:59:24
(18 hours ago)
Too many 404 requests [BY]
Web App Attack
๐ซ๐ท
masterguru
2026-07-24 08:05:00
(21 hours ago)
Remote Command Execution: Unix Shell Expression Found. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\ ...
show more
Remote Command Execution: Unix Shell Expression Found. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})| (932130-131)
show less
Hacking
๐จ๐ญ
4server
2026-07-24 07:43:58
(21 hours ago)
[FriJul2409:43:54.7151012026][security2:error][pid2453130:tid2453395][client3.76.81.12:0]ModSecurity ...
show more
[FriJul2409:43:54.7151012026][security2:error][pid2453130:tid2453395][client3.76.81.12:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:\\\\\\\\\$\(\?:\\\\\\\\\(\(\?:\\\\\\\\\(.\*\\\\\\\\\)\|.\*\)\\\\\\\\\)\|\\\\\\\\{.\*\\\\\\\\}\)\|[\<\>]\\\\\\\\\(.\*\\\\\\\\\)\)\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"396\"][id\"393655\"][rev\"17\"][msg\"Atomicorp.comWAFRules:PossibleRemoteCommandExecution:UnixShellExpressionFound\"][data\"MatchedData:\$\(\(41\*271\)\)foundwithinARGS:0:{then:\$1:__proto__:thenstatus:resolved_modelreason:-1value:{then:\$b1337}_response:{_prefix:varres=process.mainmodule.require\(child_process\).execsync\(echo\$\(\(41\*271\)\)\|base64-w0\).tostring\(\).trim\(\)throwobject.assign\(newerror\(next_redirect\){digest:\`next_redirectpush/login\?a=\${res}307\`}\)_chunks:\$q2_formdata:{get:\$1:constructor:constructor}}}\"][tag\"attack-rce\"][hostname\"www.hosting-domain-swiss-com.ticino-hosting.ch\"][uri\"/\"][unique_id\"amMXummyrZEsylbE3duOgQAAA
show less
Hacking
Web App Attack
๐ฌ๐ท
setupgr
2026-07-24 07:11:22
(22 hours ago)
(mod_security) mod_security (id:1000001) triggered by 3.76.81.12 (DE/Germany/Hesse/Frankfurt am Main ...
show more
(mod_security) mod_security (id:1000001) triggered by 3.76.81.12 (DE/Germany/Hesse/Frankfurt am Main/-/[AS16509 AMAZON-02]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Fri Jul 24 10:11:22.075234 2026] [security2:error] [pid 16828:tid 16936] [client 3.76.81.12:58324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/p.php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "103"] [id "1000001"] [msg "Bad file blocked: /p.php"] [severity "CRITICAL"] [tag "security"] [hostname "www.host.setworldup365.com"] [uri "/p.php"] [unique_id "amMQGgr_4qCwnoCj0qmtTwAABI0"]
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-07-24 06:05:18
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 3.76.81.12 (ec2-3-76-81-12.eu-central-1.compute ...
show more
(mod_security) mod_security (id:210492) triggered by 3.76.81.12 (ec2-3-76-81-12.eu-central-1.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:05:10.442146 2026] [security2:error] [pid 4076344:tid 4076344] [client 3.76.81.12:52504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.horseillustration.com"] [uri "/.git/config"] [unique_id "amMAlmkMun4M01gJrFcW8QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure
2026-07-24 05:27:30
(23 hours ago)
csagent: score 20.2: secrets grab x2, 404 noise floor x1; 1 domain(s) in 0s
Web App Attack
Anonymous
2026-07-24 04:01:48
(1 day ago)
Multiple web server 400 error codes from same source ip
Web App Attack