๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:01:41
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 13:28:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.151.70.229 (229.70.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.70.229 (229.70.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 09:28:46.767923 2026] [security2:error] [pid 3572:tid 3572] [client 34.151.70.229:43586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "billhoy.com"] [uri "/.git/config"] [unique_id "aigVDraUTJacznXlAK9Z4AAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
cleverest.eu
2026-06-09 11:24:30
(1 day ago)
MimirWAF has 1 incident from 1 distinct domain => {"bad_request_uri / vcs_probe"}
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 10:33:25
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 34.151.70.229 (229.70.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.151.70.229 (229.70.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 06:33:19.326030 2026] [security2:error] [pid 3188:tid 3188] [client 34.151.70.229:55180] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "qualiabookings.com"] [uri "/.git/config"] [unique_id "aifr7wVvOa3Vr4UsJ5R0WAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 10:06:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.151.70.229 (229.70.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.70.229 (229.70.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 06:06:44.098253 2026] [security2:error] [pid 10333:tid 10333] [client 34.151.70.229:59170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jazzycatty.com"] [uri "/.git/config"] [unique_id "aifltNAtzl1EvhwDaWiXWwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 08:18:04
(1 day ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 06:34:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.151.70.229 (229.70.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.70.229 (229.70.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 02:33:58.332747 2026] [security2:error] [pid 19633:tid 19633] [client 34.151.70.229:39532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.hcpoultry.com"] [uri "/.git/config"] [unique_id "aiez1motrx43-7XtjZPudgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 05:41:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.151.70.229 (229.70.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.70.229 (229.70.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 01:41:34.677505 2026] [security2:error] [pid 7178:tid 7178] [client 34.151.70.229:40556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wildemar.rcto.us"] [uri "/.git/config"] [unique_id "aienjoFAQ74AvkOYtZQa5wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-06-09 05:21:45
(1 day ago)
[TueJun0907:21:38.7458942026][security2:error][pid3747802:tid3748096][client34.151.70.229:0]ModSecur ...
show more
[TueJun0907:21:38.7458942026][security2:error][pid3747802:tid3748096][client34.151.70.229:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"webdisk.edilmarra.ch\"][uri\"/.git/config\"][unique_id\"aiei4jdhS6f2a4P5YeDhUgAAAE8\"]
show less
Hacking
Web App Attack
๐ญ๐บ
DumaNet
2026-06-09 05:05:00
(1 day ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Jun 08. 21:28:45
Source IP: 34.151 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Jun 08. 21:28:45
Source IP: 34.151.70.229
Portion of the log(s):
34.151.70.229 - [08/Jun/2026:21:28:43 +0200] "GET /.env.dev.local HTTP/1.1" 404 153 "-" "Mozilla/5.0 (Linux; U; Android 3.0; en-us; Xoom Build/HRI39) AppleWebKit/525.10 (KHTML, like Gecko) Version/3.0.4 Mobile Safari/523.12.2"
34.151.70.229 - [08/Jun/2026:21:28:43 +0200] "GET /.env.default HTTP/1.1" 404 153 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 10_0 like Mac OS X) AppleWebKit/600.1.4 (KHTML, like Gecko) GSA/18.0.130791545 Mobile/14A5345a Safari/600.1.4"
34.151.70.229 - [08/Jun/2026:21:28:43 +0200] "GET /.env.docker HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.99 Safari/537.36"
34.151.70.229 - [08/Jun/2026:21:28:43 +0200] "GET /.env.dist HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3850.0 Iron Safari/537.36" ....
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 04:52:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.151.70.229 (229.70.151.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.151.70.229 (229.70.151.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 00:52:24.696587 2026] [security2:error] [pid 25944:tid 25956] [client 34.151.70.229:33174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "proracersecrets.com"] [uri "/.git/config"] [unique_id "aiecCAWPhOHib9IsfKttRwAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-06-09 02:52:06
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.151.70.229 (AU/Australia/229.70. ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.151.70.229 (AU/Australia/229.70.151.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐ฌ๐ง
Axel
2026-06-09 02:42:01
(1 day ago)
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.git/config ...
show more
Blocked by ModSecurity. Rule ID: 210492 Message: None Phase: 1 Severity: CRITICAL URI: /.git/config Server: UK-01
show less
Web App Attack
Hacking
SQL Injection
๐ซ๐ท
masterguru
2026-06-09 01:02:00
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.151.70.229 (AU/Australia/229.70.15 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.151.70.229 (AU/Australia/229.70.151.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
mnsf
2026-06-09 00:18:01
(2 days ago)
Scanning/Probing (66)
Brute-Force
Web App Attack