๐ณ๐ฑ
homeshowdomain.nl
2026-06-15 22:00:07
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-14.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-15 04:28:25
(4 days ago)
(mod_security) mod_security (id:949110) triggered by 34.130.246.109 (109.246.130.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 34.130.246.109 (109.246.130.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 00:28:21.311368 2026] [security2:error] [pid 4637:tid 4637] [client 34.130.246.109:34208] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pleasejustfixit.org.cescfoundation.org"] [uri "/backend/.git/config"] [unique_id "ai9_ZS6ZRqaSer6FaiY3pQAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-15 04:27:04
(4 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 03:37:19
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.130.246.109 (109.246.130.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.130.246.109 (109.246.130.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 23:37:14.775232 2026] [security2:error] [pid 11443:tid 11443] [client 34.130.246.109:39506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ditchthediaper.com"] [uri "/.git/config"] [unique_id "ai9zaqkqPozp74qVsSQ2uAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 02:27:03
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.130.246.109 (109.246.130.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.130.246.109 (109.246.130.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 22:26:55.378903 2026] [security2:error] [pid 22348:tid 22348] [client 34.130.246.109:59550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.johnedwardsconsulting.com.danged.com"] [uri "/web/.git/config"] [unique_id "ai9i78r8fKHD3X6aTBkgFgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 01:49:27
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.130.246.109 (109.246.130.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.130.246.109 (109.246.130.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 21:49:21.048805 2026] [security2:error] [pid 24521:tid 24521] [client 34.130.246.109:45900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "majersigns.com"] [uri "/app/.git/config"] [unique_id "ai9aIdI39ptWARtrSLKQ9QAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 01:09:18
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.130.246.109 (109.246.130.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.130.246.109 (109.246.130.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 21:09:11.740117 2026] [security2:error] [pid 3399:tid 3399] [client 34.130.246.109:36408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "noel-designs.com.stormwlf.com"] [uri "/app/.git/config"] [unique_id "ai9Qt6Fbr87ppm-XU3OH-AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Origon
2026-06-15 00:47:10
(4 days ago)
http-sensitive-files - IP: 34.130.246.109 - time="2026-06-15T02:47:09+02:00" level=info msg="(555f6 ...
show more
http-sensitive-files - IP: 34.130.246.109 - time="2026-06-15T02:47:09+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 34.130.246.109 (CA/396982) : 4h ban on Ip 34.130.246.109" module=db
show less
Web App Attack
๐ซ๐ท
masterguru
2026-06-15 00:10:12
(4 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 23:43:29
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.130.246.109 (109.246.130.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.130.246.109 (109.246.130.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 19:43:23.175428 2026] [security2:error] [pid 27847:tid 27847] [client 34.130.246.109:42114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brianbrock.horsesaw.com"] [uri "/app/.git/config"] [unique_id "ai88m0D0zlyrKN7WSU3ouAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-06-14 23:42:19
(4 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-06-14 23:35:02
(4 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 23:22:50
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.130.246.109 (109.246.130.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.130.246.109 (109.246.130.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 19:22:47.867177 2026] [security2:error] [pid 31877:tid 31877] [client 34.130.246.109:48868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnhansonmemorial.org"] [uri "/app/.git/config"] [unique_id "ai83xzLkLPGX0sWhkjQv9wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-06-14 23:08:53
(4 days ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.130.246.109 (CA/Canada/-): 2 in ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.130.246.109 (CA/Canada/-): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 22:51:15
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.130.246.109 (109.246.130.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.130.246.109 (109.246.130.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 18:51:08.404376 2026] [security2:error] [pid 29268:tid 29268] [client 34.130.246.109:42618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.phalanxemail.axiomemail.net"] [uri "/frontend/.git/config"] [unique_id "ai8wXAdpX2eyE_JnwB4KLAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack