๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:00:29
(25 minutes ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-06-08 22:01:30
(1 day ago)
Auto-ban: >3000 req/min op 2026-06-08
Web App Attack
SSH
Hacking
๐จ๐ญ
4server
2026-06-08 21:18:20
(1 day ago)
[MonJun0823:18:15.1878402026][security2:error][pid1860995:tid1862166][client34.141.2.49:0]ModSecurit ...
show more
[MonJun0823:18:15.1878402026][security2:error][pid1860995:tid1862166][client34.141.2.49:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"webdisk.inserzioniticino.ch\"][uri\"/.git/config\"][unique_id\"aicxlwYfhz-KO86bbu5zOQAAARc\"]
show less
Hacking
Web App Attack
๐ฌ๐ง
gurnip
2026-06-08 19:23:18
(1 day ago)
Vulnerability probe of page /.git/config, not found on server.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 18:15:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.141.2.49 (49.2.141.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.2.49 (49.2.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 14:15:33.611247 2026] [security2:error] [pid 3874:tid 3874] [client 34.141.2.49:51760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gisur.com"] [uri "/.git/config"] [unique_id "aicGxfk8VzP4126hJJq2tgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 17:55:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.141.2.49 (49.2.141.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.2.49 (49.2.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 13:55:43.097738 2026] [security2:error] [pid 20796:tid 20796] [client 34.141.2.49:34076] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "depololaw.com"] [uri "/.git/config"] [unique_id "aicCHzTNjMpZF5i1AyFjlgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 16:03:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.141.2.49 (49.2.141.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.2.49 (49.2.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 12:03:49.622710 2026] [security2:error] [pid 27381:tid 27381] [client 34.141.2.49:60796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kawkacevents.com"] [uri "/.git/config"] [unique_id "aibn5QBIImbOGqf3onXMxwAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 15:45:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.141.2.49 (49.2.141.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.2.49 (49.2.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 11:45:43.032429 2026] [security2:error] [pid 18381:tid 18381] [client 34.141.2.49:45612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.pamplonaserviciotecnico.com"] [uri "/.git/config"] [unique_id "aibjpwkN1U7hyhQnVXX59gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 14:37:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.141.2.49 (49.2.141.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.2.49 (49.2.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 10:37:53.686297 2026] [security2:error] [pid 24261:tid 24261] [client 34.141.2.49:34860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nhglassmakers.org"] [uri "/.git/config"] [unique_id "aibTwYaX793DD65ZcriWFwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 14:16:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.141.2.49 (49.2.141.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.2.49 (49.2.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 10:15:55.878834 2026] [security2:error] [pid 31796:tid 31796] [client 34.141.2.49:52368] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alkymera.ahijado.org"] [uri "/.git/config"] [unique_id "aibOm33skq4iXSJFYsGRtgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 13:15:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.141.2.49 (49.2.141.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.2.49 (49.2.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 09:15:04.437218 2026] [security2:error] [pid 24913:tid 24925] [client 34.141.2.49:38512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.transiit.org"] [uri "/.git/config"] [unique_id "aibAWJz46ALCLFL9FO98ogAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-08 11:35:50
(1 day ago)
Try to access /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 10:41:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.141.2.49 (49.2.141.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.141.2.49 (49.2.141.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 06:41:36.949931 2026] [security2:error] [pid 5230:tid 5230] [client 34.141.2.49:55484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "transparentforest.com"] [uri "/.git/config"] [unique_id "aiacYF6lfJ__BEu40h2oHAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-06-08 09:55:14
(1 day ago)
[Mon Jun 08 19:55:14.150544 2026] [security2:error] [pid 96889] [client 34.141.2.49:40102] [client 3 ...
show more
[Mon Jun 08 19:55:14.150544 2026] [security2:error] [pid 96889] [client 34.141.2.49:40102] [client 34.141.2.49] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "paulshipley.info"] [uri "/.git/config"] [unique_id "aiaRguB4xBzda2wYNwAxjQAAAEg"]
...
show less
Web App Attack
Anonymous
2026-06-08 08:55:02
(1 day ago)
suspicious request in access.log
Web App Attack