๐ณ๐ฑ
homeshowdomain.nl
2026-09-18 22:01:42
(8 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-17.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-09-17 10:26:03
(1 day ago)
Bot / scanning and/or hacking attempts: GET /apps/.env HTTP/1.1, GET /server/.env HTTP/1.1, GET /.en ...
show more
Bot / scanning and/or hacking attempts: GET /apps/.env HTTP/1.1, GET /server/.env HTTP/1.1, GET /.env.example HTTP/1.1, GET /web/.env HTTP/1.1, GET /.env.yml HTTP/1.1, GET /frontend/.env HTTP/1.1, GET /admin/.env HTTP/1.1, GET /backend/.env HTTP/1.1, GET /app/.env HTTP/1.1, GET /public/.env HTTP/1.1, GET /api/.env HTTP/1.1, GET /.env.txt HTTP/1.1, GET /src/.env HTTP/1.1, GET /.env.json HTTP/1.1, GET /.env.yaml HTTP/1.1, GET /site/.env HTTP/1.1, GET /core/.env HTTP/1.1
show less
Hacking
Web App Attack
๐ฌ๐ท
setupgr
2026-09-17 10:25:07
(1 day ago)
(mod_security) mod_security (id:11000011) triggered by 34.178.51.208 (NL/The Netherlands/Groningen/G ...
show more
(mod_security) mod_security (id:11000011) triggered by 34.178.51.208 (NL/The Netherlands/Groningen/Groningen/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Thu Sep 17 13:25:04.742739 2026] [security2:error] [pid 151283:tid 151412] [client 34.178.51.208:50920] ModSecurity: Access denied with code 406 (phase 1). Matched phrase "googleusercontent.com" at REMOTE_HOST. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "141"] [id "11000011"] [msg "BLOCKED BAD DOMAIN: 208.51.178.34.bc.googleusercontent.com"] [severity "CRITICAL"] [hostname "gyrosplace.gr"] [uri "/"] [unique_id "aqvAANjUopyh6wx7Xouj2wAAAwU"]
show less
Port Scan
๐ซ๐ท
dynamix
2026-09-17 10:16:14
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
Epimetheus
2026-09-17 09:31:07
(1 day ago)
Unauthorized access attempts:
[GET] /sa.json
[GET] /phpinfo
[GET] /server-status.php
[GET] /_phpinf ...
show more
Unauthorized access attempts:
[GET] /sa.json
[GET] /phpinfo
[GET] /server-status.php
[GET] /_phpinfo.php
[GET] /google-key.json
[GET] /www/phpinfo.php
[GET] /ansible/.env
[GET] /mongodb/.env
[GET] /var/www/html/.env
[GET] /prod/.env
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-17 08:14:47
(1 day ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-17 05:15:16
(2 days ago)
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-17 04:56:36
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-17 04:55:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.178.51.208 (208.51.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.51.208 (208.51.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 00:55:44.778648 2026] [security2:error] [pid 13423:tid 13423] [client 34.178.51.208:45174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.titicacacatamarans.com"] [uri "/.git/config"] [unique_id "aqty0Npn9J8qJaGxUPVOFwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 03:15:27
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.178.51.208 (208.51.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.51.208 (208.51.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 23:15:22.471163 2026] [security2:error] [pid 14155:tid 14160] [client 34.178.51.208:51854] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.theextraordinaryoffice.com"] [uri "/.git/config"] [unique_id "aqtbSpkkkDULSgyf-4GqPgAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Blexyel
2026-09-17 03:00:18
(2 days ago)
34.178.51.208 - - [17/Sep/2026:05:00:18 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 ...
show more
34.178.51.208 - - [17/Sep/2026:05:00:18 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 02:58:23
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.178.51.208 (208.51.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.51.208 (208.51.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:58:17.215783 2026] [security2:error] [pid 11580:tid 11580] [client 34.178.51.208:40022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.thebestac.com"] [uri "/.git/config"] [unique_id "aqtXSdO_CBPokZHevWxpNQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-17 02:54:07
(2 days ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 1s
Web App Attack
๐บ๐ธ
dot.mg
2026-09-17 02:46:02
(2 days ago)
Bad behaviour
Web Spam
๐บ๐ธ
TPI-Abuse
2026-09-16 17:40:21
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.178.51.208 (208.51.178.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.178.51.208 (208.51.178.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 13:40:14.489658 2026] [security2:error] [pid 25801:tid 25801] [client 34.178.51.208:33842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "growtowork.com"] [uri "/.git/config"] [unique_id "aqrUfgepMi4y2jKO1ieXnAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack