๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:02:14
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
4server
2026-06-09 15:24:25
(1 week ago)
[TueJun0917:24:20.2129692026][security2:error][pid3129758:tid3129866][client34.181.216.253:0]ModSecu ...
show more
[TueJun0917:24:20.2129692026][security2:error][pid3129758:tid3129866][client34.181.216.253:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"brunocampagna.com\"][uri\"/.git/config\"][unique_id\"aigwJAy2Cu_V3DIE3yjqRAAAAM0\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 15:18:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.181.216.253 (253.216.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.216.253 (253.216.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 11:18:17.242360 2026] [security2:error] [pid 10454:tid 10454] [client 34.181.216.253:43884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oldnvn.tonynvn.me"] [uri "/.git/config"] [unique_id "aiguufxYw6HqIcYVCbG2KQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 13:59:04
(1 week ago)
Bot / scanning and/or hacking attempts: GET /.git/config HTTP/1.1
Hacking
Web App Attack
๐ณ๐ฑ
debestelapp
2026-06-09 13:57:02
(1 week ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 12:43:31
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.181.216.253 (253.216.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.216.253 (253.216.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 08:43:23.159371 2026] [security2:error] [pid 26861:tid 26888] [client 34.181.216.253:54048] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "switchbl8.nl"] [uri "/.git/config"] [unique_id "aigKaytr9lIys2oTLsvlsAAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-09 12:35:27
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 11:36:33
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.181.216.253 (253.216.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.216.253 (253.216.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 07:36:30.566729 2026] [security2:error] [pid 4325:tid 4325] [client 34.181.216.253:55366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "buenasfrecuencias.com"] [uri "/.git/config"] [unique_id "aif6vsLLKtpuenClSHzd7wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-06-09 09:10:27
(1 week ago)
34.181.216.253 - - [09/Jun/2026:11:10:25 +0200] "GET /.git/config HTTP/1.1" 404 53962 "-" "Mozilla/5 ...
show more
34.181.216.253 - - [09/Jun/2026:11:10:25 +0200] "GET /.git/config HTTP/1.1" 404 53962 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.142 Safari/537.36 OPR/62.0.3331.116"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 09:09:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.181.216.253 (253.216.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.216.253 (253.216.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 05:09:24.729358 2026] [security2:error] [pid 19397:tid 19397] [client 34.181.216.253:42684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.secureinitiatives.com.alanmariotti.com"] [uri "/.git/config"] [unique_id "aifYREy4Y_deJicxnltrJgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 08:37:42
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.181.216.253 (253.216.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.216.253 (253.216.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 04:37:35.983181 2026] [security2:error] [pid 10191:tid 10191] [client 34.181.216.253:39766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.circlehealthcaregroup.com"] [uri "/.git/config"] [unique_id "aifQzwCQOyrMb9cGYtr2zwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 06:24:08
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.181.216.253 (253.216.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.216.253 (253.216.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 02:24:01.541694 2026] [security2:error] [pid 28532:tid 28532] [client 34.181.216.253:45032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "allmyartprojects.com"] [uri "/.git/config"] [unique_id "aiexgfxQKViX2BhDeN0D3wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-06-09 04:24:21
(1 week ago)
Accessed trap at '/.git/config'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 03:17:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.181.216.253 (253.216.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.216.253 (253.216.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 23:17:32.642863 2026] [security2:error] [pid 30844:tid 30844] [client 34.181.216.253:55764] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pr-professional.com"] [uri "/.git/config"] [unique_id "aieFzD0ln3v-bYRTqt6TtwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 02:26:02
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 34.181.216.253 (253.216.181.34.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 34.181.216.253 (253.216.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 22:25:58.885095 2026] [security2:error] [pid 554:tid 554] [client 34.181.216.253:38028] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "cpectec.com"] [uri "/.git/config"] [unique_id "aid5tirMmoDO6TxYULcE7wAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack