๐ณ๐ฑ
homeshowdomain.nl
2026-06-15 22:02:06
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-14.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
chrisoej
2026-06-15 16:00:10
(1 day ago)
Automated scan detection: 30 requests, 30 failures
Probed 30 sensitive paths:
- /.git/config
- / ...
show more
Automated scan detection: 30 requests, 30 failures
Probed 30 sensitive paths:
- /.git/config
- /app/.git/config
- /src/.git/config
- /backend/.git/config
- /frontend/.git/config
Reported by chairlabs infrastructure monitoring
show less
Web App Attack
Hacking
๐บ๐ธ
chrisoej
2026-06-15 12:46:59
(1 day ago)
34.29.3.15 - - [15/Jun/2026:12:46:58 +0000] "GET /.git/config HTTP/1.1" 404 19 "-" "-" 3123554 "-" " ...
show more
34.29.3.15 - - [15/Jun/2026:12:46:58 +0000] "GET /.git/config HTTP/1.1" 404 19 "-" "-" 3123554 "-" "-" 0ms
34.29.3.15 - - [15/Jun/2026:12:46:58 +0000] "GET /app/.git/config HTTP/1.1" 404 19 "-" "-" 3123555 "-" "-" 0ms
34.29.3.15 - - [15/Jun/2026:12:46:58 +0000] "GET /src/.git/config HTTP/1.1" 404 19 "-" "-" 3123556 "-" "-" 0ms
34.29.3.15 - - [15/Jun/2026:12:46:58 +0000] "GET /backend/.git/config HTTP/1.1" 404 19 "-" "-" 3123557 "-" "-" 0ms
34.29.3.15 - - [15/Jun/2026:12:46:58 +0000] "GET /frontend/.git/config HTTP/1.1" 404 19 "-" "-" 3123558 "-" "-" 0ms
...
show less
Web App Attack
๐ฉ๐ช
getdk
2026-06-15 12:19:11
(1 day ago)
[15/Jun/2026:12:19:10 +0000] host.domain.tld:443 34.29.3.15 - - "GET /admin/.git/config HTTP/1.1" 40 ...
show more
[15/Jun/2026:12:19:10 +0000] host.domain.tld:443 34.29.3.15 - - "GET /admin/.git/config HTTP/1.1" 403 3821 "-" "NokiaN73-1/3.0649.0.0.1 Series60/3.0 Profile/MIDP2.0 Configuration/CLDC-1.1"
[15/Jun/2026:12:19:10 +0000] host.domain.tld:443 34.29.3.15 - - "GET /shop/.git/config HTTP/1.1" 403 3821 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.169 Safari/537.36"
show less
Brute-Force
Bad Web Bot
๐ช๐ธ
Francisco Vallejo
2026-06-15 11:33:32
(1 day ago)
[Mon Jun 15 13:33:31.664901 2026] [core:info] [pid 481576:tid 130565854459584] [client 34.29.3.15:39 ...
show more
[Mon Jun 15 13:33:31.664901 2026] [core:info] [pid 481576:tid 130565854459584] [client 34.29.3.15:39068] AH00128: File does not exist: /var/www/franvallejo/app/.git/config
[Mon Jun 15 13:33:31.673460 2026] [core:info] [pid 293330:tid 130567444092608] [client 34.29.3.15:39070] AH00128: File does not exist: /var/www/franvallejo/src/.git/config
[Mon Jun 15 13:33:31.685673 2026] [core:info] [pid 293330:tid 130567324554944] [client 34.29.3.15:39078] AH00128: File does not exist: /var/www/franvallejo/backend/.git/config
[Mon Jun 15 13:33:31.691826 2026] [core:info] [pid 293330:tid 130566527641280] [client 34.29.3.15:39090] AH00128: File does not exist: /var/www/franvallejo/frontend/.git/config
[Mon Jun 15 13:33:31.699606 2026] [core:info] [pid 293330:tid 130567290984128] [client 34.29.3.15:39106] AH00128: File does not exist: /var/www/franvallejo/api/.git/config
...
show less
Brute-Force
SSH
๐ณ๐ฑ
Savvii
2026-06-15 11:02:07
(1 day ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-06-15 10:01:51
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 34.29.3.15 (US/United States/15.3.29.34 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.29.3.15 (US/United States/15.3.29.34.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-06-15 09:32:30
(1 day ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ท๐บ
DZBOT
2026-06-15 07:21:44
(1 day ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 07:10:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.29.3.15 (15.3.29.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.29.3.15 (15.3.29.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 03:10:52.812182 2026] [security2:error] [pid 22271:tid 22271] [client 34.29.3.15:39152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tomflynn.smilingorc.com"] [uri "/.env.save"] [unique_id "ai-lfLuk-qa6k5OIUjS1FgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-15 05:40:02
(1 day ago)
34.29.3.15 - - [15/Jun/2026:07:39:58 +0200] "GET /backend/.env.bak HTTP/1.1" 403 7161 "-" "Mozilla/5 ...
show more
34.29.3.15 - - [15/Jun/2026:07:39:58 +0200] "GET /backend/.env.bak HTTP/1.1" 403 7161 "-" "Mozilla/5.0 (Windows NT 6.2; WOW64) AppleWebKit/537.36 (KHTML like Gecko) Chrome/28.0.1469.0 Safari/537.36"
34.29.3.15 - - [15/Jun/2026:07:39:58 +0200] "GET /backend/.env.old HTTP/1.1" 403 7161 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 12_3_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148 MicroMessenger/7.0.4(0x17000428) NetType/WIFI Language/zh_CN"
34.29.3.15 - - [15/Jun/2026:07:39:58 +0200] "GET /backend/api/.env HTTP/1.1" 403 7161 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows 98; PalmSource/hspr-H102; Blazer/4.0) 16;320x320"
34.29.3.15 - - [15/Jun/2026:07:39:58 +0200] "GET /services/.env.production HTTP/1.1" 403 7161 "-" "Lynx/2.8.7dev.4 libwww-FM/2.14 SSL-MM/1.4.1 OpenSSL/0.9.8d"
34.29.3.15 - - [15/Jun/2026:07:39:58 +0200] "GET /.env.dev.local HTTP/1.1" 403 7161 "-" "Mozilla/5.0 (Macintosh; U; PPC Mac OS X; fr-fr) AppleWebKit/312.5 (KHTML, like Gecko) Safari/312.3"
34.2
...
show less
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 03:30:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.29.3.15 (15.3.29.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.29.3.15 (15.3.29.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 23:30:00.956713 2026] [security2:error] [pid 17026:tid 17026] [client 34.29.3.15:56150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mfleetservice.com"] [uri "/.env.dev"] [unique_id "ai9xuOI5MMyYoCcFnv6togAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-06-15 00:31:04
(1 day ago)
Aggressive web search of vulnerable pages: /api/.env /api/v2/.env /development/.env /test/.env /api/ ...
show more
Aggressive web search of vulnerable pages: /api/.env /api/v2/.env /development/.env /test/.env /api/.env.local ...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 00:19:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.29.3.15 (15.3.29.34.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 34.29.3.15 (15.3.29.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 20:19:16.070374 2026] [security2:error] [pid 4125:tid 4125] [client 34.29.3.15:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.atlascoombs.com"] [uri "/.env.local"] [unique_id "ai9FBBPf9W00qe3woQ25NAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-15 00:17:01
(1 day ago)
Abuse Detected (10)
Brute-Force
Web App Attack