๐ณ๐ฑ
homeshowdomain.nl
2025-12-11 23:00:19
(9 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2025-12-10.
show less
Hacking
Web App Attack
SSH
๐ณ๐ฑ
jjnxpct
2025-12-11 04:50:55
(9 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.git/config (Rule ID: 930130) - Restricted File Access Attempt [Suspicious: .git/ found within REQUEST_FILENAME: /.git/config]
show less
Hacking
Web App Attack
Anonymous
2025-12-11 04:31:05
(9 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ณ๐ฑ
homeshowdomain.nl
2025-12-10 22:59:19
(9 months ago)
Auto-ban: >3000 req/min op 2025-12-10
Hacking
Web App Attack
SSH
๐ณ๐ฟ
Antinson
2025-12-10 22:25:10
(9 months ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
๐ง๐ฌ
Filipe Dรกvila
2025-12-10 22:14:04
(9 months ago)
[Wed Dec 10 17:14:02.150952 2025] [:error] [pid 523889:tid 140666582136576] [client 34.139.58.103:33 ...
show more
[Wed Dec 10 17:14:02.150952 2025] [:error] [pid 523889:tid 140666582136576] [client 34.139.58.103:33280] [client 34.139.58.103] [redacted]: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "[redacted][redacted]"] [[redacted] "233"] [id "[redacted]"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "[redacted]/4.7.0-dev"] [tag "[redacted]"] [tag "[redacted]"] [hostname "training.[redacted]"] [uri "/.git/config"] [unique_id "aTnwqhfZ84ZopgL60WTueAAAAMQ"]
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-10 22:04:39
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 34.139.58.103 (103.58.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.58.103 (103.58.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 17:04:32.895730 2025] [security2:error] [pid 4623:tid 4623] [client 34.139.58.103:49278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trafficstopper.com"] [uri "/.git/config"] [unique_id "aTnucCcgGOSl68BDWz5MBAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
COMPLEX
2025-12-10 22:01:38
(9 months ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (GOOGLE-CLOUD-PLA ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (GOOGLE-CLOUD-PLATFORM)
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-12-10 21:42:41
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 34.139.58.103 (103.58.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.58.103 (103.58.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 16:42:34.575037 2025] [security2:error] [pid 8694:tid 8694] [client 34.139.58.103:38822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trade.dodojuice.com"] [uri "/.git/config"] [unique_id "aTnpSsTh7yts6Z9yuu-msgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
kumiko
2025-12-10 21:34:12
(9 months ago)
[2025-12-10 23:34:11] Probing for dotfiles
"GET /.git/config HTTP/1.1" 403
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-10 21:26:52
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 34.139.58.103 (103.58.139.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.139.58.103 (103.58.139.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 10 16:26:46.945193 2025] [security2:error] [pid 15011:tid 15011] [client 34.139.58.103:44028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tracdynamics.com"] [uri "/.git/config"] [unique_id "aTnlluP9CIwWSfp55_-veAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-12-10 21:20:01
(9 months ago)
suspicious request in access.log
Web App Attack
Anonymous
2025-12-10 21:18:20
(9 months ago)
Try to connect to Port_Scan_443_stealth
Port Scan
๐ธ๐ช
EmK530
2025-12-10 21:14:57
(9 months ago)
URL flagged by RegEx: /.git/config
Web App Attack
๐ฉ๐ช
Bedios GmbH
2025-12-10 20:56:50
(9 months ago)
Login credentials theft attempt
Hacking