🇳🇱
Eric
2026-09-05 12:37:28
(6 hours ago)
[Sat Sep 05 12:37:27.346681 2026] [security2:error] [pid 4061604:tid 4061604] [client 34.173.33.63:5 ...
show more
[Sat Sep 05 12:37:27.346681 2026] [security2:error] [pid 4061604:tid 4061604] [client 34.173.33.63:55722] [client 34.173.33.63] ModSecurity: Warning. Pattern match "^[\\\\d.:]+$" at REQUEST_HEADERS:host. [file "/usr/share/modsecurity-crs/rules/REQUEST-920-PROTOCOL-ENFORCEMENT.conf"] [line "736"] [id "920350"] [msg "Host header is a numeric IP address"] [data "94.209.38.171"] [severity "WARNING"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-protocol"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/210/272"] [tag "PCI/6.5.10"] [hostname "94.209.38.171"] [uri "/.git/config"] [unique_id "apwNB7VeN7jgAYwapaS8WwAAACE"]
[Sat Sep 05 12:37:27.347165 2026] [security2:error] [pid 4061604:tid 4061604] [client 34.173.33.63:55722] [client 34.173.33.63] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"]
...
show less
Hacking
Web App Attack
🇳🇱
i-turnradio.nl
2026-09-05 10:33:46
(8 hours ago)
2026-09-05 @ 12:33:45 (CET) ~ Blocked for trying to access: /public/.git/config
Web App Attack
🇧🇾
lns.bz
2026-09-05 10:07:29
(8 hours ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 02:01:18
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.173.33.63 (63.33.173.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.33.63 (63.33.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 22:01:14.485364 2026] [security2:error] [pid 28032:tid 28032] [client 34.173.33.63:58760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jimrussell2010.russellforcongress.com"] [uri "/site/.git/config"] [unique_id "apt36sSg_Swr59q4NzHbuwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-09-04 23:04:23
(19 hours ago)
AutoBlock: ⚙️ Configuration File Access (Non Decay-Based)
Hacking
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 22:03:23
(20 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-03.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 21:05:59
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.173.33.63 (63.33.173.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.33.63 (63.33.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:05:53.788344 2026] [security2:error] [pid 8299:tid 8400] [client 34.173.33.63:37452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail3.absurdotron.com"] [uri "/src/.git/config"] [unique_id "apsysdAyp08f1StTk2YHRAAAAQ8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 09:35:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.173.33.63 (63.33.173.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.33.63 (63.33.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 05:35:25.943640 2026] [security2:error] [pid 20715:tid 20998] [client 34.173.33.63:48132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.stonyp.com"] [uri "/.git/config"] [unique_id "apqQ3RKoCyJEX5z1mHPRwwAAANI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:19:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.173.33.63 (63.33.173.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.33.63 (63.33.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:18:59.997893 2026] [security2:error] [pid 10901:tid 10901] [client 34.173.33.63:56174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.businesscongratulationscards.com"] [uri "/site/.git/config"] [unique_id "appi0_8jDPY3sVSBu2MaXgAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
YF
2026-09-04 01:30:39
(1 day ago)
Git config exposure probe
Web App Attack
🇫🇷
masterguru
2026-09-04 00:08:54
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 23:38:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.173.33.63 (63.33.173.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.33.63 (63.33.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:38:22.399349 2026] [security2:error] [pid 29078:tid 29078] [client 34.173.33.63:52288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "solidthought.com"] [uri "/html/.git/config"] [unique_id "apoE7rSxKcPLyXNWn69HjAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 20:07:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.173.33.63 (63.33.173.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.33.63 (63.33.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:07:28.151778 2026] [security2:error] [pid 23069:tid 23069] [client 34.173.33.63:45436] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shelbynash.com"] [uri "/.git/config"] [unique_id "apnTgGGVNCKc49jICR9OxwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 16:42:19
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.173.33.63 (63.33.173.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.173.33.63 (63.33.173.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 12:42:10.107861 2026] [security2:error] [pid 27743:tid 27743] [client 34.173.33.63:47536] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.ahsigns.com"] [uri "/src/.git/config"] [unique_id "apmjYl_59lB54lVk24_3gAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-03 16:29:12
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 34.173.33.63 (US/United States/63.33.173.34.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 34.173.33.63 (US/United States/63.33.173.34.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack