๐ณ๐ฑ
homeshowdomain.nl
2026-06-15 21:59:27
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-14.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-15 04:56:50
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.106.93.59 (59.93.106.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.93.59 (59.93.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 00:56:46.441197 2026] [security2:error] [pid 10635:tid 10635] [client 34.106.93.59:41962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.moldmaker.com.hk"] [uri "/src/.git/config"] [unique_id "ai-GDn7-oKsdv4OhjeqLfAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
patrisei
2026-06-15 02:22:55
(2 days ago)
You are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-sensitive-fil ...
show more
You are now banned for 10 years by Schiffdorf-West Patrol. Trigger: crowdsecurity/http-sensitive-files
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 02:05:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.106.93.59 (59.93.106.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.93.59 (59.93.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 22:05:30.395796 2026] [security2:error] [pid 8438:tid 8438] [client 34.106.93.59:60792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "robertmcatee.com"] [uri "/blog/.git/config"] [unique_id "ai9d6jYmvb2DY97lGpMW8wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Origon
2026-06-15 01:50:03
(2 days ago)
http-sensitive-files - IP: 34.106.93.59 - time="2026-06-15T03:50:02+02:00" level=info msg="(555f66b ...
show more
http-sensitive-files - IP: 34.106.93.59 - time="2026-06-15T03:50:02+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 34.106.93.59 (US/396982) : 4h ban on Ip 34.106.93.59" module=db
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 01:48:28
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.106.93.59 (59.93.106.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.93.59 (59.93.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 21:48:21.920766 2026] [security2:error] [pid 15579:tid 15579] [client 34.106.93.59:49800] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gamepart.com"] [uri "/assets/.git/config"] [unique_id "ai9Z5Yni44vHeYaQkNF_MgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-14 23:38:56
(3 days ago)
Scenarios: http-probing, http-sensitive-files
Total requests: 30
[14/Jun/2026:23:38:54 +0000] [Clien ...
show more
Scenarios: http-probing, http-sensitive-files
Total requests: 30
[14/Jun/2026:23:38:54 +0000] [Client: 34.106.93.59] GET [403] "/portal/.git/config" User-Agent: "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; PalmSource/hspr-H102; Blazer/4.0) 16;320x320"
[14/Jun/2026:23:38:54 +0000] [Client: 34.106.93.59] GET [403] "/v2/.git/config" User-Agent: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_6) AppleWebKit/603.3.8 (KHTML, like Gecko) Version/10.1.2 Safari/603.3.8"
[14/Jun/2026:23:38:54 +0000] [Client: 34.106.93.59] GET [403] "/project/.git/config" User-Agent: "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Safari/537.36"
[14/Jun/2026:23:38:54 +0000] [Client: 34.106.93.59] GET [403] "/laravel/.git/config" User-Agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/73.0.3683.103 Safari/537.36 OPR/60.0.3255.70"
show less
Web App Attack
๐ฉ๐ช
IVski
2026-06-14 22:57:20
(3 days ago)
IVski WAF | Sensitive file probe detected - looking for .git
Port Scan
Brute-Force
Web App Attack
๐จ๐ญ
4server
2026-06-14 22:38:41
(3 days ago)
[MonJun1500:38:36.6858852026][security2:error][pid56293:tid56449][client34.106.93.59:0]ModSecurity:A ...
show more
[MonJun1500:38:36.6858852026][security2:error][pid56293:tid56449][client34.106.93.59:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"aid-consultancy.ch\"][uri\"/v1/.git/config\"][unique_id\"ai8tbDxeRJFlXC71N8X0agAAAAg\"]
show less
Hacking
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-06-14 22:19:50
(3 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 22:02:57
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.106.93.59 (59.93.106.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.106.93.59 (59.93.106.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 18:02:54.061484 2026] [security2:error] [pid 22403:tid 22403] [client 34.106.93.59:58492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.virlouiserecords.virlouise.com"] [uri "/api/.git/config"] [unique_id "ai8lDgLZTtSl00ZM3ljtzAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-14 11:23:56
(3 days ago)
20 attempts against mh-misbehave-ban on argon
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐น
AlienBase
2026-06-14 10:49:00
(3 days ago)
Unauthorized Path traversal
GNU nano 7.2 ...
show more
Unauthorized Path traversal
GNU nano 7.2 /var/log/nginx/access.log
34.175.157.29 - - [14/Jun/2026:00:30:13 +0000] "GET / HTTP/2.0" 403 548 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.106.93.59 - - [14/Jun/2026:00:40:32 +0000] "GET /.git/config HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Linux; Android 4.4.2; GT-I9190) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.89 Mobile Safari/537.36"
34.106.93.59 - - [14/Jun/2026:00:40:32 +0000] "GET /app/.git/config HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.19 Safari/537.36"
show less
Bad Web Bot
Exploited Host
Anonymous
2026-06-14 07:40:01
(3 days ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
EGP Abuse Dept
2026-06-14 07:11:34
(3 days ago)
Scanning for web/db/file exploits on www.riensoptiek.nl
SQL Injection
Bad Web Bot
Web App Attack