๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:02:47
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
xxkodedxx
2026-06-09 14:00:17
(3 days ago)
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 2ร edge-block in 10 ...
show more
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 2ร edge-block in 10m window.
Origin: US / AS396982 Google LLC
Active: 14:00:04โ14:00:06 UTC
Volume: 2 HTTP req
Probed: /.git/config
Status mix: 444ร2
Vhost fishing: teachme.ztx-lab.com
UA: "Mozilla/5.0 (X11; CrOS x86_64 12105.100.0) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.144 Safari/537.36"
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 11:08:16
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.29.54.230 (230.54.29.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.29.54.230 (230.54.29.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 07:08:08.665642 2026] [security2:error] [pid 24000:tid 24000] [client 34.29.54.230:43118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.texassportsmansassociation.org.cajunfriedturkey.com"] [uri "/.git/config"] [unique_id "aif0GK8ZmXFYspp5kK5xbgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 09:46:28
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.29.54.230 (230.54.29.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.29.54.230 (230.54.29.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 05:46:21.507093 2026] [security2:error] [pid 9746:tid 9746] [client 34.29.54.230:56654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ouzcorp.com"] [uri "/.git/config"] [unique_id "aifg7QuKR29V6INGjttPeQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 07:00:50
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.29.54.230 (230.54.29.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.29.54.230 (230.54.29.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 03:00:45.258057 2026] [security2:error] [pid 14596:tid 14596] [client 34.29.54.230:41562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "feiz.church"] [uri "/.git/config"] [unique_id "aie6HS3FW_-zKLRiBB44cwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-06-09 06:30:24
(3 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/http-honeypath-sniper-crit.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 04:58:17
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.29.54.230 (230.54.29.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.29.54.230 (230.54.29.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 00:58:11.105011 2026] [security2:error] [pid 11473:tid 11473] [client 34.29.54.230:50874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.flugstadnet.xn--lyngr-yua.net"] [uri "/.git/config"] [unique_id "aiedYxrzDKuz0RUIXMRBSwAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-06-09 04:50:52
(3 days ago)
[ISILIA Protection v2.1] Tentative d'accรจs: /.git/config | Pays: US | UA: Opera/9.80 (Windows NT 6.1 ...
show more
[ISILIA Protection v2.1] Tentative d'accรจs: /.git/config | Pays: US | UA: Opera/9.80 (Windows NT 6.1; U; es-ES) Presto/2.9.181 Version/12.00
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 04:24:33
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.29.54.230 (230.54.29.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.29.54.230 (230.54.29.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 00:24:28.297457 2026] [security2:error] [pid 14875:tid 14875] [client 34.29.54.230:40196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "narrowacresbees.com"] [uri "/.git/config"] [unique_id "aieVfGqCc-MT4pZXZOhhGAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 03:04:08
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.29.54.230 (230.54.29.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.29.54.230 (230.54.29.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 23:04:00.596556 2026] [security2:error] [pid 25854:tid 25854] [client 34.29.54.230:43802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thenolangroup.llc"] [uri "/.git/config"] [unique_id "aieCoOwRb1GCJHsOJhkbuwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-09 02:23:10
(3 days ago)
[TueJun0904:23:05.2313762026][security2:error][pid2194814:tid2194880][client34.29.54.230:0]ModSecuri ...
show more
[TueJun0904:23:05.2313762026][security2:error][pid2194814:tid2194880][client34.29.54.230:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"pietroviviani.ch\"][uri\"/.git/config\"][unique_id\"aid5CUEEgE7W9cBbwvkE_AAAAE8\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 02:11:24
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.29.54.230 (230.54.29.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.29.54.230 (230.54.29.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 22:11:17.701706 2026] [security2:error] [pid 7276:tid 7280] [client 34.29.54.230:47304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lex.nederbragt.net"] [uri "/.git/config"] [unique_id "aid2RYxdjp2NQDXFnbm4AwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-06-09 02:11:17
(3 days ago)
Accessed trap at '/.git/config'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 00:31:52
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.29.54.230 (230.54.29.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.29.54.230 (230.54.29.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 20:31:45.640405 2026] [security2:error] [pid 4300:tid 4300] [client 34.29.54.230:42832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ruizpuche.com"] [uri "/.git/config"] [unique_id "aide8b2U8KxqnwEV2QKNqAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-08 22:09:06
(3 days ago)
Auto-ban: >3000 req/min op 2026-06-08
Web App Attack
SSH
Hacking