๐ณ๐ฑ
homeshowdomain.nl
2026-06-15 21:59:51
(6 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-14.
show less
Web App Attack
SSH
Hacking
๐จ๐ญ
copestack
2026-06-15 10:00:09
(6 days ago)
Automated detection: HTTP environment file enumeration (.env credential harvesting). 1 decisions on ...
show more
Automated detection: HTTP environment file enumeration (.env credential harvesting). 1 decisions on ov-4e5936.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 03:16:10
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.106.199.228 (228.199.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.199.228 (228.199.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 23:16:05.481903 2026] [security2:error] [pid 15428:tid 15428] [client 34.106.199.228:47336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hr-base-camp.com.smartstylehair.com"] [uri "/src/.git/config"] [unique_id "ai9udVXoXzLK5BLLrRCdrgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 00:07:53
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.106.199.228 (228.199.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.199.228 (228.199.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 20:07:46.907521 2026] [security2:error] [pid 27589:tid 27589] [client 34.106.199.228:53572] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "disenowebprofesional.com"] [uri "/backend/.git/config"] [unique_id "ai9CUkLALt34oYkYJCEjqQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-15 00:00:58
(1 week ago)
34.106.199.228 - - [15/Jun/2026:08:00:52 +0800] "GET /src/.git/config HTTP/1.1" 200 19012 "-" "Mozil ...
show more
34.106.199.228 - - [15/Jun/2026:08:00:52 +0800] "GET /src/.git/config HTTP/1.1" 200 19012 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.1.2 Safari/605.1.15"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 23:01:08
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.106.199.228 (228.199.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.199.228 (228.199.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 19:01:02.808258 2026] [security2:error] [pid 15015:tid 15015] [client 34.106.199.228:43420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.qed-consulting.co"] [uri "/src/.git/config"] [unique_id "ai8yrnSR-dH5nPCTYoIiogAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-14 22:39:06
(1 week ago)
Try to access /app/.git/config
Web App Attack
๐บ๐ธ
CBJ
2026-06-14 22:19:43
(1 week ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 22:12:34
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.106.199.228 (228.199.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.199.228 (228.199.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 18:12:27.556016 2026] [security2:error] [pid 17304:tid 17304] [client 34.106.199.228:44364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "srsrestoration.net"] [uri "/dist/.git/config"] [unique_id "ai8nS9vYcag9Se8q-UjI7wAAAFU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-06-14 22:06:45
(1 week ago)
AutoBlock: โ๏ธ Configuration File Access (Non Decay-Based)
Hacking
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-14 21:57:06
(1 week ago)
30 attempts against mh_ha-misbehave-ban on tin
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
clamehost.it
2026-06-14 21:50:26
(1 week ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
๐ณ๐ฑ
Savvii
2026-06-14 21:13:55
(1 week ago)
20 attempts against mh-misbehave-ban on jammytest
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 21:09:03
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.106.199.228 (228.199.106.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.199.228 (228.199.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 17:08:58.892258 2026] [security2:error] [pid 20106:tid 20106] [client 34.106.199.228:41064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cartoondelivery.com"] [uri "/src/.git/config"] [unique_id "ai8YansUazT1Ei1u4vtjhAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-06-14 15:54:05
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking