π³π±
homeshowdomain.nl
2026-06-15 21:59:48
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-14.
show less
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-06-15 09:18:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.151.209.132 (132.209.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.209.132 (132.209.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 05:18:10.848176 2026] [security2:error] [pid 5258:tid 5258] [client 34.151.209.132:60880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "allisonokon.com.pseudo.space"] [uri "/static/.git/config"] [unique_id "ai_DUhOz5HLG0qOToNoKbwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
dtorrer
2026-06-15 08:31:56
(2 days ago)
General vulnerability scan.
Port Scan
π©πͺ
Lino Project
2026-06-15 07:34:36
(2 days ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-sensitive-files
Hacking
Anonymous
2026-06-15 06:57:34
(2 days ago)
34.151.209.132 - - [15/Jun/2026:14:57:34 +0800] "GET /html/.git/config HTTP/1.1" 404 196 "-" "Mozill ...
show more
34.151.209.132 - - [15/Jun/2026:14:57:34 +0800] "GET /html/.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_3) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.80 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 06:42:28
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.151.209.132 (132.209.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.209.132 (132.209.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 02:42:23.712951 2026] [security2:error] [pid 13836:tid 13836] [client 34.151.209.132:33798] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.myaward.michaelward.com"] [uri "/html/.git/config"] [unique_id "ai-ezw7qjIimzmMN8Gw3wgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-06-15 06:30:36
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 05:21:34
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.151.209.132 (132.209.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.209.132 (132.209.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 01:21:29.415031 2026] [security2:error] [pid 31843:tid 31843] [client 34.151.209.132:37344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "matterofbritain.com"] [uri "/app/.git/config"] [unique_id "ai-L2UpGgVCJ9S_GbVr3JQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
Ribeye375
2026-06-15 05:10:45
(2 days ago)
HIPS nginx-access-errors - Block tcp/http,https
Brute-Force
πΊπΈ
TPI-Abuse
2026-06-15 04:01:48
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.151.209.132 (132.209.151.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.209.132 (132.209.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 00:01:45.158033 2026] [security2:error] [pid 18975:tid 18988] [client 34.151.209.132:37740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.charteredeconomist.aafm.us"] [uri "/dist/.git/config"] [unique_id "ai95Ka4O3Z75KZgPGmBlIAAAAYk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
e.fierstra
2026-06-15 04:01:06
(3 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
π¦πΉ
services.org.pl
2026-06-15 03:39:36
(3 days ago)
connect() failed (111: Connection refused) while connecting to upstream, client: 34.151.209.132, ser ...
show more
connect() failed (111: Connection refused) while connecting to upstream, client: 34.151.209.132, server: keycloak.services.org.pl, request: "GET /.git/config HTTP/1.1", upstream: "https://127.0.0.1:8443/.git/config", host: "keycloak.services.org.pl"
show less
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2026-06-15 03:35:13
(3 days ago)
1.222 requests with url.path */.git/config
Brute-Force
Bad Web Bot
π«π·
Baking333
2026-06-15 03:29:13
(3 days ago)
[redacted] 34.151.209.132 - - [15/Jun/2026:04:29:12 +0100] "GET /src/.git/config HTTP/1.1" 302 5288 ...
show more
[redacted] 34.151.209.132 - - [15/Jun/2026:04:29:12 +0100] "GET /src/.git/config HTTP/1.1" 302 5288 0/55050 "-" "Mozilla/5.0 (iPad; CPU OS 8_4_1 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) Version/8.0 Mobile/12H321 Safari/600.1.4" [redacted] 34.151.209.132 - - [15/Jun/2026:04:29:12 +0100] "GET /v1/.git/config HTTP/1.1" 302 5288 0/44970 "-" "SearchExpress"
show less
Bad Web Bot
Web App Attack
π³π±
Mangelot Hosting
2026-06-15 03:19:00
(3 days ago)
(modsecurity) srv104 ModSecurity 34.151.209.132 (BR/Brazil/132.209.151.34.bc.googleusercontent.com): ...
show more
(modsecurity) srv104 ModSecurity 34.151.209.132 (BR/Brazil/132.209.151.34.bc.googleusercontent.com): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack