๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:00:55
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
ut-addicted.com
2026-06-09 11:16:17
(2 weeks ago)
\[Tue Jun 09 13:16:15.536547 2026\] \[:error\] \[pid 20646:tid 139785967077120\] \[client 34.101.188 ...
show more
\[Tue Jun 09 13:16:15.536547 2026\] \[:error\] \[pid 20646:tid 139785967077120\] \[client 34.101.188.13:56962\] \[client 34.101.188.13\] ModSecurity: Access denied with code 403 \(phase 2\). Operator GE matched 5 at TX:anomaly_score. \[file "/usr/local/apache/modsecurity-owasp-latest/rules/REQUEST-949-BLOCKING-EVALUATION.conf"\] \[line "57"\] \[id "949110"\] \[msg "Inbound Anomaly Score Exceeded \(Total Score: 5\)"\] \[severity "CRITICAL"\] \[tag "application-multi"\] \[tag "language-multi"\] \[tag "platform-multi"\] \[tag "attack-generic"\] \[hostname "www.ut-addicted.com"\] \[uri "/.git/config"\] \[unique_id "aif1-18P1GhGAMSE8pGHIgAAAQE"\]
show less
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-06-09 09:52:23
(2 weeks ago)
[TueJun0911:52:21.4484922026][security2:error][pid2713741:tid2713906][client34.101.188.13:0]ModSecur ...
show more
[TueJun0911:52:21.4484922026][security2:error][pid2713741:tid2713906][client34.101.188.13:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"mail.welcomeintrentino.it\"][uri\"/.git/config\"][unique_id\"aifiVbx_vzxBABNSDK2afAAAAQc\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 08:49:30
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.101.188.13 (13.188.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.188.13 (13.188.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 04:49:23.810796 2026] [security2:error] [pid 20206:tid 20206] [client 34.101.188.13:50940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.siedersoft.com.ar.sieder.com"] [uri "/.git/config"] [unique_id "aifTk_KdG9tcGpSZyZPioQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 08:10:24
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.101.188.13 (13.188.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.188.13 (13.188.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 04:10:17.348653 2026] [security2:error] [pid 5864:tid 5864] [client 34.101.188.13:57912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.kleens-uk.com"] [uri "/.git/config"] [unique_id "aifKaZtveuPlvD3IbuLk5QAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 06:02:17
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.101.188.13 (13.188.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.188.13 (13.188.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 02:02:10.920134 2026] [security2:error] [pid 17593:tid 17593] [client 34.101.188.13:44420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.forensicwater.waterarchitecture.com"] [uri "/.git/config"] [unique_id "aiesYu_QUK_rbpVQMAofNwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-06-09 05:26:57
(2 weeks ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 02:38:56
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.101.188.13 (13.188.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.188.13 (13.188.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 22:38:49.150656 2026] [security2:error] [pid 5335:tid 5335] [client 34.101.188.13:58322] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "austinbiblestudents.org"] [uri "/.git/config"] [unique_id "aid8uS9mY5lBTLvxSgKLAgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 01:42:59
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.101.188.13 (13.188.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.188.13 (13.188.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 21:42:53.827616 2026] [security2:error] [pid 27528:tid 27528] [client 34.101.188.13:56342] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cherryblossomplayers.royal-barbershop.com"] [uri "/.git/config"] [unique_id "aidvnazRXer_VjqfojlcpwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
WinnieHoneypots
2026-06-09 01:42:54
(2 weeks ago)
Crappy bot probing nonexistent /.git/config
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
pixelboost.kr
2026-06-09 00:31:37
(2 weeks ago)
34.101.188.13 - - [09/Jun/2026:09:31:37 +0900] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (L ...
show more
34.101.188.13 - - [09/Jun/2026:09:31:37 +0900] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Linux; Android 9; VTR-L09) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 20:25:05
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.101.188.13 (13.188.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.188.13 (13.188.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 16:24:54.238651 2026] [security2:error] [pid 27675:tid 27675] [client 34.101.188.13:34294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xhumanlikerobots.com.bamedica.com"] [uri "/.git/config"] [unique_id "aiclFnHEHSdE2noEOYdfJwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 19:10:52
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.101.188.13 (13.188.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.188.13 (13.188.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 15:10:46.406453 2026] [security2:error] [pid 14562:tid 14562] [client 34.101.188.13:59128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.michael.michaelward.com"] [uri "/.git/config"] [unique_id "aicTtk46odyUInEB5gelXAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Kreapptivo
2026-06-08 18:07:58
(2 weeks ago)
[08/Jun/2026:20:07:55 +0200] Web-Request: "GET /.git/config", User-Agent: "Mozilla/5.0 (X11; Linux x ...
show more
[08/Jun/2026:20:07:55 +0200] Web-Request: "GET /.git/config", User-Agent: "Mozilla/5.0 (X11; Linux x86_64; rv:38.0) Gecko/20100101 Firefox/38.0 Iceweasel/38.2.1"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 15:11:01
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.101.188.13 (13.188.101.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.101.188.13 (13.188.101.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 11:10:57.508316 2026] [security2:error] [pid 24637:tid 24637] [client 34.101.188.13:36012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gayebrown.tulsatvmemories.com"] [uri "/.git/config"] [unique_id "aibbgTwT6Tc4BF4C1Ggf5gAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack