๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:01:52
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-06-09 15:21:30
(2 days ago)
34.140.216.39 - - [09/Jun/2026:12:21:29 -0300] "GET /.git/config HTTP/1.1" 403 548 "-" "Mozilla/5.0 ...
show more
34.140.216.39 - - [09/Jun/2026:12:21:29 -0300] "GET /.git/config HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_12_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.100 Safari/537.36"
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-06-09 15:19:16
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 34.140.216.39 (39.216.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.140.216.39 (39.216.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 11:19:12.755819 2026] [security2:error] [pid 25344:tid 25344] [client 34.140.216.39:42454] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "ritualistik.com"] [uri "/.git/config"] [unique_id "aigu8LqKdzCGRxUuMV_1AQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 14:46:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.216.39 (39.216.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.216.39 (39.216.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 10:46:10.703179 2026] [security2:error] [pid 25133:tid 25133] [client 34.140.216.39:59726] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.patrick.grimone.com"] [uri "/.git/config"] [unique_id "aignMjsGX5WrL_pFCOPxEwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
joharikop
2026-06-09 14:38:53
(2 days ago)
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-cred ...
show more
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-credential-probes jail.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 13:36:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.216.39 (39.216.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.216.39 (39.216.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 09:36:12.279815 2026] [security2:error] [pid 14326:tid 14330] [client 34.140.216.39:33222] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "koalacogs.com"] [uri "/.git/config"] [unique_id "aigWzNl-gtKpK_MPLyv0wQAAAUI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 13:19:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.216.39 (39.216.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.216.39 (39.216.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 09:19:38.204042 2026] [security2:error] [pid 17499:tid 17499] [client 34.140.216.39:49010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cultiplant.com.menagri.com"] [uri "/.git/config"] [unique_id "aigS6qLWtCrk-etNrnfDTQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 13:00:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.216.39 (39.216.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.216.39 (39.216.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 09:00:39.800564 2026] [security2:error] [pid 13153:tid 13153] [client 34.140.216.39:44686] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "burningdownthevillger.com.tremulant.com"] [uri "/.git/config"] [unique_id "aigOd9ByItu4D_EAur-JFQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-06-09 12:45:42
(2 days ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 11:38:36
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.216.39 (39.216.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.216.39 (39.216.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 07:38:33.105864 2026] [security2:error] [pid 22431:tid 22431] [client 34.140.216.39:59042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.messengersforchrist.charity"] [uri "/.git/config"] [unique_id "aif7OSSrjbchWh8Ut7r7eAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 11:17:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.216.39 (39.216.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.216.39 (39.216.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 07:16:59.618237 2026] [security2:error] [pid 16688:tid 16688] [client 34.140.216.39:37912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.hiscreativedesign.com"] [uri "/.git/config"] [unique_id "aif2K4WvV8-7lOpkY-6eLAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 09:08:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.216.39 (39.216.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.216.39 (39.216.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 05:08:24.722054 2026] [security2:error] [pid 24385:tid 24385] [client 34.140.216.39:42376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "consolidatedoperationsgroup.com"] [uri "/.git/config"] [unique_id "aifYCOdC2sILn3LRgCmfdQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Smish
2026-06-09 07:28:18
(3 days ago)
HONEYPOT HIT --> Fail2ban time=1780990096 log=2026-06-09T08:28:16+01:00 ip=34.140.216.39 host=router ...
show more
HONEYPOT HIT --> Fail2ban time=1780990096 log=2026-06-09T08:28:16+01:00 ip=34.140.216.39 host=router.ham.as210667.net method=GET uri="/.git/config" status=404 ua="Mozilla/5.0 (compatible; Yahoo! Slurp China; http://misc.yahoo.com.cn/help.html)" ref="-" rid=3017697e3b5272c25c38e5125bbed462
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 06:59:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.216.39 (39.216.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.216.39 (39.216.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 02:59:11.880661 2026] [security2:error] [pid 3580:tid 3580] [client 34.140.216.39:50300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "afdfurniture.com"] [uri "/.git/config"] [unique_id "aie5v3JsE6bMPXYx0LqI7gAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 05:52:30
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.140.216.39 (39.216.140.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.140.216.39 (39.216.140.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 01:52:23.982034 2026] [security2:error] [pid 2277:tid 2277] [client 34.140.216.39:51438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stinsonbeachsurfandkayak.com"] [uri "/.git/config"] [unique_id "aieqF_8juE71BB9OgIjpDAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack