๐ณ๐ฑ
homeshowdomain.nl
2026-06-10 22:01:16
(6 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-09.
show less
Web App Attack
SSH
Hacking
๐ฌ๐ง
AvonleaConsulting
2026-06-09 22:59:42
(1 week ago)
Attempts to probe web pages for vulnerable PHP or other applications
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:01:39
(1 week ago)
Auto-ban: >3000 req/min op 2026-06-09
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 16:13:04
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.143.207.197 (197.207.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.207.197 (197.207.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 12:12:57.120704 2026] [security2:error] [pid 2485:tid 2485] [client 34.143.207.197:42512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.files.cmabiblequizzing.org"] [uri "/.git/config"] [unique_id "aig7iQP20QrPFWlEIxdCdwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-06-09 16:12:58
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 15:33:22
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.143.207.197 (197.207.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.207.197 (197.207.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 11:33:16.828928 2026] [security2:error] [pid 14700:tid 14700] [client 34.143.207.197:48658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dceabronwilliams.com"] [uri "/.git/config"] [unique_id "aigyPA9Y8-o50Mv5W4UWJAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 15:16:05
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.143.207.197 (197.207.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.207.197 (197.207.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 11:15:58.534923 2026] [security2:error] [pid 6743:tid 6743] [client 34.143.207.197:50632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "alianzafreight.com"] [uri "/.git/config"] [unique_id "aiguLvbtlH9VUbGP0iZosgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 14:44:37
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.143.207.197 (197.207.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.207.197 (197.207.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 10:44:31.316378 2026] [security2:error] [pid 30413:tid 30413] [client 34.143.207.197:48818] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.arklatexds.wisk.org"] [uri "/.git/config"] [unique_id "aigmz08IDcmwXILIonQRAwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
AvonleaConsulting
2026-06-09 14:02:41
(1 week ago)
Scanning unused Default website or suspicious access to valid sites from IP marked as abusive
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-06-09 13:16:22
(1 week ago)
[TueJun0915:16:18.3460932026][security2:error][pid1206360:tid1207155][client34.143.207.197:0]ModSecu ...
show more
[TueJun0915:16:18.3460932026][security2:error][pid1206360:tid1207155][client34.143.207.197:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.aeapcl.ch.81-17-25-250.cpanel.site\"][uri\"/.git/config\"][unique_id\"aigSIlyu_pBBgTouWnK9ZAAAARE\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 12:23:11
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.143.207.197 (197.207.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.207.197 (197.207.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 08:23:05.611035 2026] [security2:error] [pid 6170:tid 6170] [client 34.143.207.197:47976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tonydelov.net"] [uri "/.git/config"] [unique_id "aigFqSAoun_WeP6Du5o2TwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 10:47:04
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.143.207.197 (197.207.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.207.197 (197.207.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 06:46:56.493523 2026] [security2:error] [pid 1146:tid 1146] [client 34.143.207.197:33828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ichi51e.net"] [uri "/.git/config"] [unique_id "aifvIKx8cEeBGm3DLDj8HwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
kumiko
2026-06-09 08:19:44
(1 week ago)
[2026-06-09 11:19:44] Probing for dotfiles
"GET /.git/config HTTP/1.1" 403
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 07:25:49
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.143.207.197 (197.207.143.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.143.207.197 (197.207.143.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 03:25:43.223348 2026] [security2:error] [pid 14396:tid 14396] [client 34.143.207.197:58618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.chatgptfrance.net"] [uri "/.git/config"] [unique_id "aie_9yOKqvpUoTc-zRZlsQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-09 07:23:38
(1 week ago)
[TueJun0909:23:34.7554692026][security2:error][pid2555667:tid2555703][client34.143.207.197:0]ModSecu ...
show more
[TueJun0909:23:34.7554692026][security2:error][pid2555667:tid2555703][client34.143.207.197:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"studio-portale.ch.136-243-54-122.cpanel.site\"][uri\"/.git/config\"][unique_id\"aie_dmIrWNlNu0JCIPmDBwAAABc\"]
show less
Port Scan
Brute-Force
Web App Attack