π³π±
homeshowdomain.nl
2026-06-15 22:01:15
(17 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-14.
show less
Web App Attack
SSH
Hacking
π©πͺ
Kotuhan
2026-06-15 10:56:38
(1 day ago)
Honeypot: this IP sent web exploit attempts (RCE/SQLi/traversal/CVE probes) against a decoy host wit ...
show more
Honeypot: this IP sent web exploit attempts (RCE/SQLi/traversal/CVE probes) against a decoy host with no real service.
show less
Web App Attack
Hacking
π«π·
LiloBzH
2026-06-15 04:12:13
(1 day ago)
34.106.91.40 - - [15/Jun/2026:06:12:12 +0200] "GET /wp-content/.git/config HTTP/1.1" 403 180 "-" "Mo ...
show more
34.106.91.40 - - [15/Jun/2026:06:12:12 +0200] "GET /wp-content/.git/config HTTP/1.1" 403 180 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.103 Safari/537.36"
34.106.91.40 - - [15/Jun/2026:06:12:12 +0200] "GET /shop/.git/config HTTP/1.1" 403 180 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/33.0.1750.166 Safari/537.36 OPR/20.0.1396.73172"
34.106.91.40 - - [15/Jun/2026:06:12:12 +0200] "GET /portal/.git/config HTTP/1.1" 403 118 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_9_3) AppleWebKit/537.75.14 (KHTML, like Gecko) Version/7.0.3 Safari/7046A194A"
show less
Web App Attack
π³π±
e.fierstra
2026-06-15 03:11:45
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 02:21:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.91.40 (40.91.106.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.91.40 (40.91.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 22:21:50.040817 2026] [security2:error] [pid 26824:tid 26824] [client 34.106.91.40:38558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oldnvn.tonynvn.me"] [uri "/frontend/.git/config"] [unique_id "ai9hvkiJ9uit1_eXraXGtAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-06-15 00:55:09
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
π³π±
Savvii
2026-06-15 00:34:33
(1 day ago)
20 attempts against mh_ha-misbehave-ban on sedna
Brute-Force
Bad Web Bot
Web App Attack
π±π»
garmtech.com
2026-06-15 00:30:15
(1 day ago)
Attempted access to sensitive endpoint (/.git/config) detected. Automated scan or unauthorized probi ...
show more
Attempted access to sensitive endpoint (/.git/config) detected. Automated scan or unauthorized probing.
show less
Web App Attack
π¨π
backslash
2026-06-15 00:21:00
(1 day ago)
block ruleset bad bot: github scan 052A73F305734A39936C6BD919E2C0BF536B62AC
Bad Web Bot
πΊπΈ
mnsf
2026-06-15 00:19:32
(1 day ago)
Scanning/Probing (58)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-14 22:49:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.91.40 (40.91.106.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.91.40 (40.91.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 18:49:53.099004 2026] [security2:error] [pid 5590:tid 5590] [client 34.106.91.40:52472] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3n1ent.com"] [uri "/v3/.git/config"] [unique_id "ai8wEci60cB-qzdB9LzSAgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
paissangroup
2026-06-14 22:48:52
(1 day ago)
Multiple WAF Violations
Web App Attack
π°π·
MW
2026-06-14 22:48:51
(1 day ago)
34.106.91.40 - - [15/Jun/2026:07:48:50 +0900] "GET /frontend/.git/config HTTP/1.1" 404 4251 "-" "Moz ...
show more
34.106.91.40 - - [15/Jun/2026:07:48:50 +0900] "GET /frontend/.git/config HTTP/1.1" 404 4251 "-" "Mozilla/5.0 (Linux; Android 9; CPH1859) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.143 Mobile Safari/537.36"
34.106.91.40 - - [15/Jun/2026:07:48:50 +0900] "GET /web/.git/config HTTP/1.1" 404 4251 "-" "Links (2.1pre15; FreeBSD 5.3-RELEASE i386; 196x84)"
34.106.91.40 - - [15/Jun/2026:07:48:50 +0900] "GET /v3/.git/config HTTP/1.1" 404 4251 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_7_2; rv:10.0.1) Gecko/20100101 Firefox/10.0.1"
show less
Bad Web Bot
Web App Attack
π¨π
ca
2026-06-14 21:29:03
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-06-14 15:49:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.106.91.40 (40.91.106.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.91.40 (40.91.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 11:49:24.129646 2026] [security2:error] [pid 21157:tid 21157] [client 34.106.91.40:48060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trafficstopper.com"] [uri "/frontend/.git/config"] [unique_id "ai7NhBSprR3tKxjGrEiPxAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack