๐ณ๐ฑ
homeshowdomain.nl
2026-06-15 21:59:43
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-14.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-15 09:29:15
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.180.58.20 (20.58.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.58.20 (20.58.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 05:29:10.199638 2026] [security2:error] [pid 9122:tid 9122] [client 34.180.58.20:51696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stucohen.com"] [uri "/v1/.git/config"] [unique_id "ai_F5uNxM3vjWsteqUgk8AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 09:11:14
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.180.58.20 (20.58.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.58.20 (20.58.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 05:11:07.525855 2026] [security2:error] [pid 10074:tid 10074] [client 34.180.58.20:44650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lemoulinavent.org"] [uri "/app/.git/config"] [unique_id "ai_Bq2VJA94cnKvErQPFBgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-15 08:10:11
(4 days ago)
Bot / seems abusive / Apache connections: 30
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 04:50:03
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.180.58.20 (20.58.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.58.20 (20.58.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 00:49:54.740776 2026] [security2:error] [pid 21350:tid 21350] [client 34.180.58.20:51394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "acatucson.com"] [uri "/src/.git/config"] [unique_id "ai-EctJzfhKw6EVLrVXi_AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-06-15 04:34:59
(4 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.180.58.20 (IN/India/Maharashtra/Mumb ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.180.58.20 (IN/India/Maharashtra/Mumbai/20.58.180.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-06-15 04:02:19
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.180.58.20 (20.58.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.58.20 (20.58.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 00:02:15.306212 2026] [security2:error] [pid 21370:tid 21370] [client 34.180.58.20:53752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.journ-e.sabri.es"] [uri "/build/.git/config"] [unique_id "ai95Rwjpxf1Z6aBgMGdsmwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
aranguren.org
2026-06-15 04:01:15
(4 days ago)
34.180.58.20 - - [15/Jun/2026:14:01:14 +1000] "GET /htdocs/.git/config HTTP/1.1" 302 - "-" "Mozilla/ ...
show more
34.180.58.20 - - [15/Jun/2026:14:01:14 +1000] "GET /htdocs/.git/config HTTP/1.1" 302 - "-" "Mozilla/5.0 (Linux; Android 7.1.2; Redmi 4X) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36"
34.180.58.20 - - [15/Jun/2026:14:01:14 +1000] "GET /shop/.git/config HTTP/1.1" 302 - "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Safari/537.36"
34.180.58.20 - - [15/Jun/2026:14:01:14 +1000] "GET /code/.git/config HTTP/1.1" 302 - "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/76.0.3809.100 Chrome/76.0.3809.100 Safari/537.36"
...
show less
Web App Attack
๐ง๐ช
cmbplf
2026-06-15 03:06:03
(4 days ago)
3.111 requests from abuseipdb.com blacklisted IP (1yr9mos2w)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-15 02:32:20
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.180.58.20 (20.58.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.58.20 (20.58.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 22:32:12.568356 2026] [security2:error] [pid 2865:tid 2872] [client 34.180.58.20:59704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "smarterproductions.teritemme.com"] [uri "/blog/.git/config"] [unique_id "ai9kLOHEmv2Fi2eMkGsPzgAAAMI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 01:30:09
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.180.58.20 (20.58.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.58.20 (20.58.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 21:29:57.847339 2026] [security2:error] [pid 11180:tid 11180] [client 34.180.58.20:34990] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.179vfs.com"] [uri "/.git/config"] [unique_id "ai9VlV2Y7G0YHGjePiGNYgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-15 00:18:50
(4 days ago)
Scanning/Probing (30)
Brute-Force
Web App Attack
๐ซ๐ฎ
inlink.ltd
2026-06-14 23:57:29
(4 days ago)
dot file probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 23:34:31
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.180.58.20 (20.58.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.58.20 (20.58.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 19:34:23.351009 2026] [security2:error] [pid 971:tid 971] [client 34.180.58.20:41562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dev.ottawacalligraphy.ca.artbyrt.com"] [uri "/wp-content/.git/config"] [unique_id "ai86f-PmNPezDK1QyRgwIAAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 22:02:20
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.180.58.20 (20.58.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.58.20 (20.58.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 18:02:16.515371 2026] [security2:error] [pid 652:tid 652] [client 34.180.58.20:42754] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radiantmessages.com"] [uri "/shop/.git/config"] [unique_id "ai8k6KxSI2LV2mrFOuzXxAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack