π³π±
homeshowdomain.nl
2026-06-15 22:03:23
(3 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-14.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-06-15 05:30:02
(3 months ago)
suspicious request in access.log
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 05:13:27
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 34.124.114.54 (54.114.124.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.114.54 (54.114.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 01:13:22.825692 2026] [security2:error] [pid 12569:tid 12569] [client 34.124.114.54:55970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dosfordogs.ca.modeltdr.com"] [uri "/v3/.git/config"] [unique_id "ai-J8pOdKtgwJmugQlIQIQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
4server
2026-06-15 05:01:42
(3 months ago)
[MonJun1507:01:36.3314402026][security2:error][pid1574007:tid1574410][client34.124.114.54:0]ModSecur ...
show more
[MonJun1507:01:36.3314402026][security2:error][pid1574007:tid1574410][client34.124.114.54:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"365\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"supporto-ticino.ch\"][uri\"/.git/config\"][unique_id\"ai-HMJm3pAlELDoyVD26WwAAAQo\"]
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 03:52:34
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 34.124.114.54 (54.114.124.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.114.54 (54.114.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 23:52:26.787532 2026] [security2:error] [pid 25716:tid 25716] [client 34.124.114.54:50898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.lexie.org"] [uri "/src/.git/config"] [unique_id "ai92-hXpsMbwdJdQd9iJOAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
strxmpp
2026-06-15 03:12:15
(3 months ago)
34.124.114.54 - - [15/Jun/2026:05:12:13 +0200] "GET /.git/config HTTP/1.1" 404 4554 "-" "Mozilla/5.0 ...
show more
34.124.114.54 - - [15/Jun/2026:05:12:13 +0200] "GET /.git/config HTTP/1.1" 404 4554 "-" "Mozilla/5.0 (Linux; Android 7.0; HUAWEI VNS-L31) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36"
...
show less
Bad Web Bot
πΊπΈ
mnsf
2026-06-15 03:06:54
(3 months ago)
Scanning/Probing (60)
Brute-Force
Web App Attack
π©πͺ
SwinT
2026-06-15 03:00:06
(3 months ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
π³π±
kbkb
2026-06-15 02:55:53
(3 months ago)
CrowdSec detection: crowdsecurity/http-sensitive-files
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2026-06-15 02:18:03
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 34.124.114.54 (54.114.124.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.114.54 (54.114.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 22:17:57.756358 2026] [security2:error] [pid 21785:tid 21808] [client 34.124.114.54:57344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.whitecrosslibrary.aafm.us"] [uri "/app/.git/config"] [unique_id "ai9g1XTHA19gh09tBXHO0gAAAZM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
ISPLtd
2026-06-15 01:46:20
(3 months ago)
Jun 14 22:46:19 34.124.114.54 TCP SPT=37186 DPT=443 SYN
Jun 14 22:46:19 34.124.114.54 TCP SPT=37176 ...
show more
Jun 14 22:46:19 34.124.114.54 TCP SPT=37186 DPT=443 SYN
Jun 14 22:46:19 34.124.114.54 TCP SPT=37176 DPT=443 SYN
Jun 14 22:46:19 34.124.114.54 TCP SPT=37158 DPT=443 SYN
...
show less
DDoS Attack
πΊπΈ
TPI-Abuse
2026-06-15 00:28:03
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 34.124.114.54 (54.114.124.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.124.114.54 (54.114.124.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 20:27:56.433554 2026] [security2:error] [pid 11663:tid 11672] [client 34.124.114.54:50880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "7sons.net"] [uri "/app/.git/config"] [unique_id "ai9HDB7sgw36GlceXvC7aQAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
wteiken
2026-06-15 00:26:01
(3 months ago)
2026-06-14T20:26:00.112818-04:00 rocinante.teiken.net kernel: [1412715.031371] syn_limit:IN=ens5 OUT ...
show more
2026-06-14T20:26:00.112818-04:00 rocinante.teiken.net kernel: [1412715.031371] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=34.124.114.54 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x00 TTL=55 ID=16946 DF PROTO=TCP SPT=54492 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-06-14T20:26:00.113033-04:00 rocinante.teiken.net kernel: [1412715.035282] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=34.124.114.54 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=14346 DF PROTO=TCP SPT=54504 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-06-14T20:26:00.122293-04:00 rocinante.teiken.net kernel: [1412715.041037] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:0a:f3:ae:05:2f:b7:08:00 SRC=34.124.114.54 DST=192.168.16.119 LEN=60 TOS=0x00 PREC=0x00 TTL=57 ID=60464 DF PROTO=TCP SPT=54520 DPT=443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-06-14T20:26:00.128861-04:00 rocinante.teiken.net kernel: [1412715.051383] syn_limit:IN=ens5 OUT= MAC=0a:ff:cf:a1:a5:bb:
...
show less
Port Scan
π¬π§
consul.to
2026-06-15 00:01:43
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
π³π±
Mangelot Hosting
2026-06-14 23:22:39
(3 months ago)
(modsecurity) srv101 ModSecurity 34.124.114.54 (CA/Canada/54.114.124.34.bc.googleusercontent.com): 1 ...
show more
(modsecurity) srv101 ModSecurity 34.124.114.54 (CA/Canada/54.114.124.34.bc.googleusercontent.com): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack