๐ณ๐ฑ
homeshowdomain.nl
2026-05-28 22:01:20
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-27.
show less
Web App Attack
SSH
Hacking
๐ง๐ท
SOC Blue Team
2026-05-28 21:25:47
(1 week ago)
IPs get by Hunting on SIEM
Phishing
Web Spam
Port Scan
Hacking
๐บ๐ธ
JustMeHere
2026-05-28 19:36:42
(1 week ago)
[Thu May 28 15:36:37.132380 2026] [security2:error] [pid 134846:tid 134983] [client 34.181.216.26:57 ...
show more
[Thu May 28 15:36:37.132380 2026] [security2:error] [pid 134846:tid 134983] [client 34.181.216.26:57352] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 8)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "73.88.79.72"] [uri "/.git/config"] [unique_id "ahiZRYCuc8URkn-8BoKl3AAAAM8"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-28 19:30:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.181.216.26 (26.216.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.216.26 (26.216.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 28 15:30:26.078222 2026] [security2:error] [pid 28388:tid 28388] [client 34.181.216.26:39362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.111"] [uri "/.git/config"] [unique_id "ahiX0jH5UWi94jLAUH1Y4AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
Detmach
2026-05-28 00:46:06
(1 week ago)
Security attack detected. Multiple failed attempts from 34.181.216.26. IP banned for 1440 minutes at ...
show more
Security attack detected. Multiple failed attempts from 34.181.216.26. IP banned for 1440 minutes at 28.05.2026 03:46:01. Failed attempts: 1
show less
Brute-Force
๐ฉ๐ช
IVski
2026-05-28 00:39:26
(1 week ago)
IVski WAF | Sensitive file probe detected - looking for .git
Port Scan
Brute-Force
Web App Attack
๐ซ๐ท
JPPO
2026-05-27 22:50:02
(1 week ago)
Port 443 : GET /.git or /.git/HEAD, /.git/config ... /.DS_store
Web App Attack
Anonymous
2026-05-27 08:05:20
(1 week ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 06:27:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.181.216.26 (26.216.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.216.26 (26.216.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 02:27:53.505268 2026] [security2:error] [pid 1316:tid 1316] [client 34.181.216.26:59828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pasamugo.com"] [uri "/.git/config"] [unique_id "ahaO6W6ZRcKHZtnwKyqpGwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 03:52:41
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.181.216.26 (26.216.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.216.26 (26.216.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 23:52:33.747277 2026] [security2:error] [pid 24964:tid 24964] [client 34.181.216.26:37084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stage-app-eu-west-2.feaverslane.com"] [uri "/.git/config"] [unique_id "ahZqgdnFyZGJjTENOLo6yAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 03:18:23
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.181.216.26 (26.216.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.216.26 (26.216.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 23:18:20.486042 2026] [security2:error] [pid 30854:tid 30854] [client 34.181.216.26:54696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.federallog.com"] [uri "/.git/config"] [unique_id "ahZifI8HsMZjYgbb8BrL4gAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-27 01:58:58
(1 week ago)
Attempted access to sensitive endpoint (/.git/config) detected. Automated scan or unauthorized probi ...
show more
Attempted access to sensitive endpoint (/.git/config) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 00:35:59
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.181.216.26 (26.216.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.216.26 (26.216.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 20:35:54.983601 2026] [security2:error] [pid 12909:tid 12909] [client 34.181.216.26:40390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kh6jim.com"] [uri "/.git/config"] [unique_id "ahY8agaesxqfo0K8pvyFrQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mashamal
2026-05-26 22:11:10
(1 week ago)
Vulnerability Probe
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 21:09:10
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.181.216.26 (26.216.181.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.181.216.26 (26.216.181.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 17:09:06.032415 2026] [security2:error] [pid 5782:tid 5782] [client 34.181.216.26:56136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.moonstonenightclub.com"] [uri "/.git/config"] [unique_id "ahYL8qpYnMybvn9tPdr7MgAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack