๐จ๐ญ
TheCoon
2026-06-09 23:45:01
(13 hours ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:00:00
(15 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 15:18:48
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.40.45.226 (226.45.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.45.226 (226.45.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 11:18:41.490961 2026] [security2:error] [pid 14326:tid 14334] [client 34.40.45.226:34982] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mouserart.com"] [uri "/.git/config"] [unique_id "aigu0dl-gtKpK_MPLyv9BgAAAUY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 14:47:14
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.40.45.226 (226.45.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.45.226 (226.45.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 10:47:10.258068 2026] [security2:error] [pid 20500:tid 20500] [client 34.40.45.226:55736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kraftrealestate.kraftrentals.com"] [uri "/.git/config"] [unique_id "aignblB-q-3Rbf468bzwfgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 14:29:18
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.40.45.226 (226.45.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.45.226 (226.45.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 10:29:13.686373 2026] [security2:error] [pid 23664:tid 23664] [client 34.40.45.226:52194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cynosureservices.net"] [uri "/.git/config"] [unique_id "aigjOdiB-RMqcoN6ZcibkAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-06-09 13:12:16
(1 day ago)
[TueJun0915:12:09.6983012026][security2:error][pid1206352:tid1207075][client34.40.45.226:0]ModSecuri ...
show more
[TueJun0915:12:09.6983012026][security2:error][pid1206352:tid1207075][client34.40.45.226:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.aid-web.ch.81-17-25-250.cpanel.site\"][uri\"/.git/config\"][unique_id\"aigRKd1F0uJnIgXwrWYUfgAAAEA\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 11:11:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.45.226 (226.45.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.45.226 (226.45.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 07:11:13.636528 2026] [security2:error] [pid 15816:tid 15816] [client 34.40.45.226:52710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.carpentriesoffline.org"] [uri "/.git/config"] [unique_id "aif00XHkYp6i2zO_pQ6vxQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
beon
2026-06-09 09:49:01
(1 day ago)
[DateTime=>2026-06-09T09:49:01Z (UTC)] , [HoneyPot_Hit=>once] , [HoneyPot=>/.git/config] , [total_Hi ...
show more
[DateTime=>2026-06-09T09:49:01Z (UTC)] , [HoneyPot_Hit=>once] , [HoneyPot=>/.git/config] , [total_Hit=>once]
show less
Bad Web Bot
Web App Attack
Hacking
Anonymous
2026-06-09 09:45:22
(1 day ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-09 09:34:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.45.226 (226.45.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.45.226 (226.45.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 05:34:08.807423 2026] [security2:error] [pid 20052:tid 20052] [client 34.40.45.226:58846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.skintormint.com"] [uri "/.git/config"] [unique_id "aifeEOxAbbo6bN06xEIj-QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-09 09:31:03
(1 day ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ซ๐ท
masterguru
2026-06-09 09:22:11
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.40.45.226 (DE/Germany/226.45.40.34 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.40.45.226 (DE/Germany/226.45.40.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 08:55:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.45.226 (226.45.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.45.226 (226.45.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 04:55:07.036945 2026] [security2:error] [pid 30451:tid 30451] [client 34.40.45.226:51608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jamestaylorart.com"] [uri "/.git/config"] [unique_id "aifU6zrXI89O1kzlyQXq0gAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Lino Project
2026-06-09 07:01:58
(1 day ago)
34.40.45.226 - - [09/Jun/2026:09:01:54 +0200] "GET /.git/config HTTP/1.1" 403 3821 "-" "Mozilla/5.0 ...
show more
34.40.45.226 - - [09/Jun/2026:09:01:54 +0200] "GET /.git/config HTTP/1.1" 403 3821 "-" "Mozilla/5.0 (Linux; Android 9; SAMSUNG SM-G973F Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/9.4 Chrome/67.0.3396.87 Mobile Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 04:17:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.40.45.226 (226.45.40.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.45.226 (226.45.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 00:17:26.427670 2026] [security2:error] [pid 22270:tid 22270] [client 34.40.45.226:45612] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oceanrich.biz"] [uri "/.git/config"] [unique_id "aieT1ly4YPmAAFDvpiwx8gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack