๐ณ๐ฑ
homeshowdomain.nl
2026-06-15 22:03:41
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-14.
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
ITSNF
2026-06-15 05:35:05
(2 days ago)
Blocked by os-abuseipdb; 360 hits, proto=tcp, ports=443,80
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-15 05:23:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.245.229 (229.245.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.245.229 (229.245.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 01:23:26.780247 2026] [security2:error] [pid 24496:tid 24496] [client 34.125.245.229:38554] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zost.net"] [uri "/api/.git/config"] [unique_id "ai-MTsFSIJXWyKnA34IeWQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 05:03:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.245.229 (229.245.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.245.229 (229.245.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 01:03:46.085606 2026] [security2:error] [pid 7819:tid 7819] [client 34.125.245.229:50808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thingstodonude.com"] [uri "/app/.git/config"] [unique_id "ai-Hsg4zU3Absb5PYjpv6QAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 04:26:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.245.229 (229.245.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.245.229 (229.245.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 00:26:01.860347 2026] [security2:error] [pid 27232:tid 27235] [client 34.125.245.229:37510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ejspizzeriahudson.com"] [uri "/.git/config"] [unique_id "ai9-2XBLRyGw4RvzHdTUvgAAAQE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Origon
2026-06-15 03:39:16
(2 days ago)
http-sensitive-files - IP: 34.125.245.229 - time="2026-06-15T05:39:15+02:00" level=info msg="(555f6 ...
show more
http-sensitive-files - IP: 34.125.245.229 - time="2026-06-15T05:39:15+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 34.125.245.229 (US/396982) : 4h ban on Ip 34.125.245.229" module=db
show less
Web App Attack
๐ช๐ธ
gnom4ik
2026-06-15 03:21:33
(2 days ago)
ban-reviewer auto report; ip=34.125.245.229; scenario=crowdsecurity/http-probing; scenario_context=c ...
show more
ban-reviewer auto report; ip=34.125.245.229; scenario=crowdsecurity/http-probing; scenario_context=crowdsecurity/http-probing,crowdsecurity/http-sensitive-files; verdict=valid_ban; confidence=0.92; categories=21; active_decisions=2; lookback_decisions=2; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=ip_decision_count_high
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 02:50:15
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.245.229 (229.245.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.245.229 (229.245.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 22:50:11.818622 2026] [security2:error] [pid 14884:tid 14884] [client 34.125.245.229:43220] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lumberwizard.com.wizind.com"] [uri "/api/.git/config"] [unique_id "ai9oY_xA9UvS-_vmnL9uIwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-15 01:41:53
(2 days ago)
Try to access /src/.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 01:31:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.245.229 (229.245.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.245.229 (229.245.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 21:31:32.256962 2026] [security2:error] [pid 26141:tid 26141] [client 34.125.245.229:57026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aam-artists.com"] [uri "/.git/config"] [unique_id "ai9V9DV_dJHAqzOp9CPRqgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-06-15 01:01:37
(2 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-15 00:47:02
(2 days ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 00:20:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.125.245.229 (229.245.125.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.125.245.229 (229.245.125.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 20:20:31.369197 2026] [security2:error] [pid 3576:tid 3576] [client 34.125.245.229:39060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thegreatleapforward.com.herecometheplanes.com"] [uri "/.git/config"] [unique_id "ai9FT1df0k_jDyRLEw-8fAAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-15 00:14:52
(2 days ago)
[MonJun1502:14:49.5223262026][security2:error][pid3433961:tid3433977][client34.125.245.229:0]ModSecu ...
show more
[MonJun1502:14:49.5223262026][security2:error][pid3433961:tid3433977][client34.125.245.229:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.formet.ch.136-243-54-122.cpanel.site\"][uri\"/dist/.git/config\"][unique_id\"ai9D-fVHKKAbdH2Vu-gRIQAAAAw\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-06-15 00:08:12
(2 days ago)
Abuse Detected (30)
Brute-Force
Web App Attack