๐ณ๐ฑ
homeshowdomain.nl
2026-06-10 22:00:23
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-09.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:03:56
(3 days ago)
Auto-ban: >3000 req/min op 2026-06-09
Web App Attack
SSH
Hacking
๐ฉ๐ช
FeG Deutschland
2026-06-09 13:11:54
(3 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 10:35:29
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.151.120.112 (112.120.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.120.112 (112.120.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 06:35:23.724818 2026] [security2:error] [pid 31479:tid 31590] [client 34.151.120.112:38866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.rammep.digital4z.com"] [uri "/.git/config"] [unique_id "aifsa-w5pqLpaWXhdGDJMAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-09 10:11:16
(3 days ago)
Try to access /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 09:13:05
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.151.120.112 (112.120.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.120.112 (112.120.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 05:12:59.045207 2026] [security2:error] [pid 10588:tid 10588] [client 34.151.120.112:51696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cameronsol.com"] [uri "/.git/config"] [unique_id "aifZGxupfIJ-Din4R02k8gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 06:34:20
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.151.120.112 (112.120.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.120.112 (112.120.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 02:34:15.219406 2026] [security2:error] [pid 3882:tid 3882] [client 34.151.120.112:39170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.chinese.jbaydeliveries.com"] [uri "/.git/config"] [unique_id "aiez5_b_VDQ1-pMlq15DBwAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 03:46:59
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.151.120.112 (112.120.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.120.112 (112.120.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 23:46:56.568337 2026] [security2:error] [pid 21418:tid 21418] [client 34.151.120.112:36374] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kraftrealestate.kraftrentals.com"] [uri "/.git/config"] [unique_id "aieMsHYvDLGVy74PZjqhlwAAACs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 01:04:09
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.151.120.112 (112.120.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.120.112 (112.120.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 21:04:03.098934 2026] [security2:error] [pid 1382:tid 1382] [client 34.151.120.112:56630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sionayra.tracybur.net"] [uri "/.git/config"] [unique_id "aidmgx7b7TYK0TSY1UZzogAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
dcnet
2026-06-08 22:00:23
(4 days ago)
FortiGate detected DOS attack from IPv4 address 34.151.120.112
DDoS Attack
Anonymous
2026-06-08 21:46:30
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.151.120.112 (AU/Australia/112.120.15 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.151.120.112 (AU/Australia/112.120.151.34.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-06-08 21:42:45
(4 days ago)
(caddyscan) Scanner path probe from 34.151.120.112 (AU/Australia/112.120.151.34.bc.googleusercontent ...
show more
(caddyscan) Scanner path probe from 34.151.120.112 (AU/Australia/112.120.151.34.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 34.151.120.112 - - [08/Jun/2026:21:42:43 +0000] "GET /.env.development.local HTTP/1.1"
[REDACTED] 200 2627 34.151.120.112 - - [08/Jun/2026:21:42:43 +0000] "GET /.env.dev.local HTTP/1.1"
[REDACTED] 200 2627 34.151.120.112 - - [08/Jun/2026:21:42:43 +0000] "GET /.env.orig HTTP/1.1"
[REDACTED] 200 2627 34.151.120.112 - - [08/Jun/2026:21:42:43 +0000] "GET /.env.production.local HTTP/1.1"
[REDACTED] 200 2627 34.151.120.112 - - [08/Jun/2026:21:42:43 +0000] "GET /api/.env.local HTTP/1.1"
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-06-08 20:31:46
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.151.120.112 (112.120.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.120.112 (112.120.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 16:31:41.186196 2026] [security2:error] [pid 10603:tid 10603] [client 34.151.120.112:36524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aguaflot.aguasolar.com"] [uri "/api/.env.old"] [unique_id "aicmrdooLNlheEOYkC8KrwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-08 19:47:04
(4 days ago)
34.151.120.112 - - [08/Jun/2026:21:46:57 +0200] "GET /backend/.env.bak HTTP/1.1" 403 7161 "-" "Mozil ...
show more
34.151.120.112 - - [08/Jun/2026:21:46:57 +0200] "GET /backend/.env.bak HTTP/1.1" 403 7161 "-" "Mozilla/5.0 (Linux; Android 9; motorola one vision) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36"
34.151.120.112 - - [08/Jun/2026:21:46:57 +0200] "GET /app/.env.old HTTP/1.1" 403 7161 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_5) AppleWebKit/602.1.50 (KHTML, like Gecko) Version/10.0 Safari/602.1.50"
34.151.120.112 - - [08/Jun/2026:21:46:57 +0200] "GET /backend/.env.old HTTP/1.1" 403 7161 "-" "Mozilla/5.0 (Linux; Android 5.1.1; KYOCERA-C6742) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36"
34.151.120.112 - - [08/Jun/2026:21:46:57 +0200] "GET /app/.env.staging HTTP/1.1" 403 7161 "-" "W3C_Validator/1.305.2.12 libwww-perl/5.64"
34.151.120.112 - - [08/Jun/2026:21:46:57 +0200] "GET /frontend/.env.local HTTP/1.1" 403 7161 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/68.0.3440.75 Safari/
...
show less
DDoS Attack
๐ณ๐ฑ
debestelapp
2026-06-08 19:40:06
(4 days ago)
Web App Attack