Anonymous
2026-06-17 11:10:38
(1 day ago)
Trying to access config files
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-15 22:01:22
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-14.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-06-15 15:08:07
(3 days ago)
Trying to access config files
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-06-15 10:13:53
(3 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-06-15 02:40:02
(3 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
Matthew Ping
2026-06-15 02:30:10
(3 days ago)
ModSecurity rule 949110 triggered on dedicated4785. Web application attack blocked by CSF/LFD.
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-15 02:11:57
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.131.9.76 (76.9.131.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.9.76 (76.9.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 22:11:51.779447 2026] [security2:error] [pid 2266:tid 2266] [client 34.131.9.76:52164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pagewideprinting.computersraleigh.com"] [uri "/dashboard/.git/config"] [unique_id "ai9fZw8NvRc3y0CkTtuVLAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
paulo.apoloni
2026-06-15 02:09:48
(3 days ago)
34.131.9.76 - - [14/Jun/2026:23:09:48 -0300] "GET /code/.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 ...
show more
34.131.9.76 - - [14/Jun/2026:23:09:48 -0300] "GET /code/.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.170 Safari/537.36"
34.131.9.76 - - [14/Jun/2026:23:09:48 -0300] "GET /static/.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:68.0) Gecko/20100101 Firefox/68.0"
34.131.9.76 - - [14/Jun/2026:23:09:48 -0300] "GET /project/.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Linux; Android 5.0; SM-G900F Build/LRX21T; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/45.0.2454.95 Mobile Safari/537.36"
34.131.9.76 - - [14/Jun/2026:23:09:48 -0300] "GET /wordpress/.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_8_2) AppleWebKit/537.4 (KHTML like Gecko) Chrome/22.0.1229.79 Safari/537.4"
34.131.9.76 - - [14/Jun/2026:23:09:48 -0300] "GET /v2/.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 6.2; Win64; x64; rv:16.0) Gecko/16.0 Firefox/16.0"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
EGP Abuse Dept
2026-06-15 01:47:42
(3 days ago)
Scanning for web/db/file exploits on www.izicontent.nl
SQL Injection
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-06-15 01:04:56
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-06-15 01:04:22
(3 days ago)
Blocked by CSF 13 firewall - Rule: US/United States/76.9.131.34.bc.googleusercontent.com
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 23:15:37
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.131.9.76 (76.9.131.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.9.76 (76.9.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 19:15:31.367278 2026] [security2:error] [pid 27102:tid 27102] [client 34.131.9.76:51234] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.itimetable21.com"] [uri "/v1/.git/config"] [unique_id "ai82E30pwwXpJ-Dykd0K9wAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 22:57:33
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.131.9.76 (76.9.131.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.9.76 (76.9.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 18:57:25.179855 2026] [security2:error] [pid 16773:tid 16773] [client 34.131.9.76:51532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.thomaschemical.com"] [uri "/wordpress/.git/config"] [unique_id "ai8x1SyN03A7ExjrNLhNTwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
doarg
2026-06-14 22:07:52
(3 days ago)
[Mon Jun 15 00:07:51.826333 2026] [authz_core:error] [pid 143387] [client 34.131.9.76:47428] AH01630 ...
show more
[Mon Jun 15 00:07:51.826333 2026] [authz_core:error] [pid 143387] [client 34.131.9.76:47428] AH01630: client denied by server configuration: /var/www/doarg.com/symfony
[Mon Jun 15 00:07:51.829986 2026] [authz_core:error] [pid 143388] [client 34.131.9.76:47372] AH01630: client denied by server configuration: /var/www/doarg.com/frontend
[Mon Jun 15 00:07:51.835555 2026] [authz_core:error] [pid 143389] [client 34.131.9.76:47382] AH01630: client denied by server configuration: /var/www/doarg.com/.git/config
[Mon Jun 15 00:07:51.836738 2026] [authz_core:error] [pid 143385] [client 34.131.9.76:47406] AH01630: client denied by server configuration: /var/www/doarg.com/htdocs
[Mon Jun 15 00:07:51.838948 2026] [authz_core:error] [pid 143384] [client 34.131.9.76:47410] AH01630: client denied by server configuration: /var/www/doarg.com/api
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-14 21:12:21
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.131.9.76 (76.9.131.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.131.9.76 (76.9.131.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 17:12:17.090931 2026] [security2:error] [pid 1319:tid 1319] [client 34.131.9.76:37068] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arborterra.org"] [uri "/assets/.git/config"] [unique_id "ai8ZMeOVSwEyDD2wrPNjTQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack