๐ณ๐ฑ
homeshowdomain.nl
2026-09-22 22:00:55
(9 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-21.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-09-22 01:25:59
(1 day ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:24:34
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.180.77.52 (52.77.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.77.52 (52.77.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:24:26.496859 2026] [security2:error] [pid 659:tid 659] [client 34.180.77.52:40418] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.disdis.net.greenlight.us"] [uri "/.git/config"] [unique_id "arGumvnmvTj5DnOZM9ANoQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-21 21:55:02
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:20:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.180.77.52 (52.77.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.77.52 (52.77.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:20:19.153518 2026] [security2:error] [pid 2722:tid 2722] [client 34.180.77.52:42728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.desoucey.com.monmouthbottleshop.com"] [uri "/.git/config"] [unique_id "arGfkypd-b227Tmd6LG_owAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Alpiskris
2026-09-21 18:52:36
(1 day ago)
34.180.77.52 - - [21/Sep/2026:18:52:18 +0000] "GET /.git/config HTTP/1.1" 403 548 "-" "Mozilla/5.0 ( ...
show more
34.180.77.52 - - [21/Sep/2026:18:52:18 +0000] "GET /.git/config HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.180.77.52 - - [21/Sep/2026:18:52:21 +0000] "GET /.env HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.180.77.52 - - [21/Sep/2026:18:52:21 +0000] "GET /.env.local HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.180.77.52 - - [21/Sep/2026:18:52:21 +0000] "GET /.env.production HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.180.77.52 - - [21/Sep/2026:18:52:22 +0000] "GET /.env.staging HTTP/1.1" 403 548 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
34.
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 11:30:15
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-21 11:14:41
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ฎ๐น
VHosting
2026-09-21 06:35:04
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-20 20:03:43
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 18:33:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.180.77.52 (52.77.180.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.180.77.52 (52.77.180.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 14:33:08.324896 2026] [security2:error] [pid 23298:tid 23298] [client 34.180.77.52:42326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hmdinc.harintonmechanical.com"] [uri "/.git/config"] [unique_id "arAm5L_CZO1rR6fA1njxMQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-09-20 17:44:57
(2 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ณ๐ฑ
Cloud86 B.V.
2026-06-26 23:00:02
(2 months ago)
categories: Email Spam
Email Spam