๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:02:24
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
FeG Deutschland
2026-06-09 14:03:52
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ซ๐ฎ
6kilowatti
2026-06-09 08:07:39
(1 week ago)
34.156.101.27 - - [09/Jun/2026:08:07:39 +0000] "GET /.git/config HTTP/1.1" 404 183 "-" "Mozilla/5.0 ...
show more
34.156.101.27 - - [09/Jun/2026:08:07:39 +0000] "GET /.git/config HTTP/1.1" 404 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
...
show less
Web App Attack
๐จ๐ฟ
sajmon0011
2026-06-09 07:38:11
(1 week ago)
34.156.101.27 - - [09/Jun/2026:09:38:10 +0200] "GET /.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 ...
show more
34.156.101.27 - - [09/Jun/2026:09:38:10 +0200] "GET /.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Linux; Android 8.0.0; F5321) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.89 Mobile Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 07:10:16
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.156.101.27 (27.101.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.101.27 (27.101.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 03:10:09.337258 2026] [security2:error] [pid 9981:tid 9997] [client 34.156.101.27:52956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kiehnefamily.us"] [uri "/.git/config"] [unique_id "aie8UfFXVgRp6K1Y9XU3PAAAAIo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MM-bot
2026-06-09 06:00:05
(1 week ago)
URL-probe: HTTP/1.1 GET request on /.git/config (2026-06-09 08:00:05 UTC+2)
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 05:32:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.156.101.27 (27.101.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.101.27 (27.101.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 01:32:23.131841 2026] [security2:error] [pid 28310:tid 28314] [client 34.156.101.27:37280] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "venezuelaguia.com"] [uri "/.git/config"] [unique_id "aielZ6cUIIpaJdUCE6WQ-AAAAQE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-09 05:06:11
(1 week ago)
[TueJun0907:06:07.4229532026][security2:error][pid2388211:tid2388374][client34.156.101.27:0]ModSecur ...
show more
[TueJun0907:06:07.4229532026][security2:error][pid2388211:tid2388374][client34.156.101.27:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"allegraravizza.it\"][uri\"/.git/config\"][unique_id\"aiefP3xcOX4IXtgqSBRitwAAAQ0\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 04:10:42
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.156.101.27 (27.101.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.101.27 (27.101.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 00:10:36.694713 2026] [security2:error] [pid 15184:tid 15184] [client 34.156.101.27:59384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.purebinary.cathrynn.com"] [uri "/.git/config"] [unique_id "aieSPDVZe78oWeDpXTn1ywAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
beon
2026-06-09 01:56:17
(1 week ago)
[DateTime=>2026-06-09T01:56:17Z (UTC)] , [HoneyPot_Hit=>once] , [HoneyPot=>/.git/config] , [total_Hi ...
show more
[DateTime=>2026-06-09T01:56:17Z (UTC)] , [HoneyPot_Hit=>once] , [HoneyPot=>/.git/config] , [total_Hit=>once]
show less
Bad Web Bot
Web App Attack
Hacking
๐ฌ๐ง
Oakley
2026-06-09 00:48:39
(1 week ago)
(confirmed_bot_sig) Confirmed bot
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-06-08 22:02:23
(1 week ago)
Auto-ban: >3000 req/min op 2026-06-08
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-08 21:10:13
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.156.101.27 (27.101.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.101.27 (27.101.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 17:10:06.390776 2026] [security2:error] [pid 12684:tid 12684] [client 34.156.101.27:53870] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "title30.com"] [uri "/.git/config"] [unique_id "aicvrn0NaJJAvKUdtrguNAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 20:41:07
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.156.101.27 (27.101.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.101.27 (27.101.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 16:41:01.524043 2026] [security2:error] [pid 28971:tid 28971] [client 34.156.101.27:52164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ramseysgalleryofstuff.com"] [uri "/.git/config"] [unique_id "aico3d2rGbA9n9G2NpXbbwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 19:36:53
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 34.156.101.27 (27.101.156.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.156.101.27 (27.101.156.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 15:36:48.641315 2026] [security2:error] [pid 12516:tid 12516] [client 34.156.101.27:33826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cleanbuildingservices.com"] [uri "/.git/config"] [unique_id "aicZ0JOuOzPW_bsELFkUYQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack