๐ณ๐ฑ
homeshowdomain.nl
2026-09-02 22:01:35
(2 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-01.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-02 19:01:49
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.159.174 (174.159.34.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.159.174 (174.159.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 15:01:45.166413 2026] [security2:error] [pid 9645:tid 9645] [client 34.34.159.174:60260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hakanararat.com"] [uri "/www/.git/config"] [unique_id "aphymTSIau7LRH7LJVGHhQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
Starburst SysOp Team
2026-09-02 15:28:04
(9 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-syd2-4)
Hacking
Web App Attack
๐ซ๐ท
pm33
2026-09-02 10:15:20
(14 hours ago)
Unauthorized connections HTTP 403
Web App Attack
๐ฐ๐ท
doll.gl
2026-09-02 07:41:12
(17 hours ago)
CrowdSec: Ip 34.34.159.174 performed 'crowdsecurity/http-sensitive-files' (5 events over 6.185762ms) ...
show more
CrowdSec: Ip 34.34.159.174 performed 'crowdsecurity/http-sensitive-files' (5 events over 6.185762ms) at 2026-09-02 07:41:11.573069144 +0000 UTC (scenario: crowdsecurity/http-sensitive-files)
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 06:19:26
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.159.174 (174.159.34.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.159.174 (174.159.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 02:19:21.005981 2026] [security2:error] [pid 10312:tid 10312] [client 34.34.159.174:45382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.lynetteharris.net"] [uri "/src/.git/config"] [unique_id "ape_6SHuPYjLDUjZpoEW2gAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-09-02 06:12:36
(18 hours ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-02 06:00:03
(18 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-02 05:59:50
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.159.174 (174.159.34.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.159.174 (174.159.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 01:59:44.026954 2026] [security2:error] [pid 11982:tid 11982] [client 34.34.159.174:58046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.vmbinc.com"] [uri "/.git/config"] [unique_id "ape7UEGa3UaggrVO555m4QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-02 05:53:36
(18 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 05:26:52
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.159.174 (174.159.34.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.159.174 (174.159.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 01:26:47.602169 2026] [security2:error] [pid 17689:tid 17689] [client 34.34.159.174:38780] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.woodington.com"] [uri "/api/.git/config"] [unique_id "apezl0aIwjdIzARdWHOY9wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
gadix
2026-09-02 05:16:58
(19 hours ago)
[02/Sep/2026:07:16:57.704668 +0200] apexSQB74zu2FtEcBPENkgAAAAA 34.34.159.174 58126 127.0.0.1 7081
[ ...
show more
[02/Sep/2026:07:16:57.704668 +0200] apexSQB74zu2FtEcBPENkgAAAAA 34.34.159.174 58126 127.0.0.1 7081
[02/Sep/2026:07:16:57.710443 +0200] apexSY9MOAiKj7S46yKmtAAAAAc 34.34.159.174 58176 127.0.0.1 7081
[02/Sep/2026:07:16:57.712333 +0200] apexSQF6drznIpyPWm6gqwAAAAY 34.34.159.174 58160 127.0.0.1 7081
...
show less
Web App Attack
Anonymous
2026-09-02 05:12:22
(19 hours ago)
{"reqId":"p22HQejwxmEmRj1BgjIF","level":1,"time":"2026-09-02T07:12:20+02:00","remoteAddr":"34.34.159 ...
show more
{"reqId":"p22HQejwxmEmRj1BgjIF","level":1,"time":"2026-09-02T07:12:20+02:00","remoteAddr":"34.34.159.174","user":"--","app":"core","method":"GET","url":"/app/.git/config","scriptName":"/index.php","message":"Trusted domain error. \"34.34.159.174\" tried to access using \"mail.khomri.com\" as host.","userAgent":"crusader-worker/1.0","version":"34.0.3.2","data":{"app":"core"}}
{"reqId":"8gTJv6QDnfCA5f7y5oig","level":1,"time":"2026-09-02T07:12:20+02:00","remoteAddr":"34.34.159.174","user":"--","app":"core","method":"GET","url":"/wordpress/.git/config","scriptName":"/index.php","message":"Trusted domain error. \"34.34.159.174\" tried to access using \"mail.khomri.com\" as host.","userAgent":"crusader-worker/1.0","version":"34.0.3.2","data":{"app":"core"}}
{"reqId":"sT6FLCE1rpxlG0rqMzxl","level":1,"time":"2026-09-02T07:12:20+02:00","remoteAddr":"34.34.159.174","user":"--","app":"core","method":"GET","url":"/public/.git/config","scriptName":"/index.php","message":"Trusted domain error. \"34.
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 04:34:23
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.159.174 (174.159.34.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.159.174 (174.159.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 00:34:15.786769 2026] [security2:error] [pid 24327:tid 24327] [client 34.34.159.174:53960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.kirt.us"] [uri "/www/.git/config"] [unique_id "apenR6swfnL-kdXwRuGengAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 03:38:51
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.34.159.174 (174.159.34.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.34.159.174 (174.159.34.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 23:38:46.904000 2026] [security2:error] [pid 30089:tid 30097] [client 34.34.159.174:60526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "duplexgoldmine.com"] [uri "/wordpress/.git/config"] [unique_id "apeaRuWSISHrcEkBtQk3jAAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack