π³π±
homeshowdomain.nl
2026-06-09 22:01:54
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
π§πͺ
cmbplf
2026-06-09 15:41:14
(1 week ago)
18.630 requests with url.path *.git/*
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-06-09 11:35:01
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.40.86.72 (72.86.40.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.86.72 (72.86.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 07:34:53.889929 2026] [security2:error] [pid 4956:tid 4956] [client 34.40.86.72:52256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tribalmystic.okwellbeing.com"] [uri "/.git/config"] [unique_id "aif6XWhC25om8dXV2YsmYAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 10:38:28
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.40.86.72 (72.86.40.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.86.72 (72.86.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 06:38:21.606427 2026] [security2:error] [pid 4533:tid 4533] [client 34.40.86.72:41466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "moorenextdoor.com"] [uri "/.git/config"] [unique_id "aiftHXjwWP8XpgWJOLve5wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 10:13:23
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.40.86.72 (72.86.40.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.86.72 (72.86.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 06:13:17.840278 2026] [security2:error] [pid 22031:tid 22031] [client 34.40.86.72:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.dentguyvt.com"] [uri "/.git/config"] [unique_id "aifnPb39OnscSbf8_et0dwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅π±
sefinek.net
2026-06-09 09:33:05
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from DE.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from DE.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.git/config | UA: Mozilla/5.0 (Linux; Android 8.1.0; ZB602KL) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.89 Mobile Safari/537.36 β’ Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
π¨π
4server
2026-06-09 09:24:48
(1 week ago)
[TueJun0911:24:43.7744332026][security2:error][pid428972:tid429236][client34.40.86.72:0]ModSecurity: ...
show more
[TueJun0911:24:43.7744332026][security2:error][pid428972:tid429236][client34.40.86.72:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"rd-gaming.net\"][uri\"/.git/config\"][unique_id\"aifb21aXLzwmDVUamazdcQAAAJI\"]
show less
Hacking
Web App Attack
πΊπΈ
sandap1
2026-06-09 08:50:01
(1 week ago)
Blocked by os-abuseipdb; 12 hits, proto=tcp, ports=443,80,src_ip=34.40.86.72
Port Scan
Hacking
πΊπΈ
TPI-Abuse
2026-06-09 08:15:19
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.40.86.72 (72.86.40.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.86.72 (72.86.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 04:15:13.165800 2026] [security2:error] [pid 4087:tid 4087] [client 34.40.86.72:52746] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.securityzonepr.com"] [uri "/.git/config"] [unique_id "aifLkY83-W6YMPQFuY5UxQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 06:44:36
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.40.86.72 (72.86.40.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.86.72 (72.86.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 02:44:29.046607 2026] [security2:error] [pid 20705:tid 20705] [client 34.40.86.72:57766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.toybud.danged.com"] [uri "/.git/config"] [unique_id "aie2TRdfJA6OVQqN2DyHYgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
big-cloud.nl
2026-06-09 04:54:33
(1 week ago)
Try to access /.git/config
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 02:03:29
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.40.86.72 (72.86.40.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.86.72 (72.86.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 22:03:26.391606 2026] [security2:error] [pid 12241:tid 12241] [client 34.40.86.72:44648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mywhy.endriss.info"] [uri "/.git/config"] [unique_id "aid0brn-vGVNix3UCfiBogAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-06-08 22:05:55
(1 week ago)
Auto-ban: >3000 req/min op 2026-06-08
Web App Attack
SSH
Hacking
π¬π§
Oakley
2026-06-08 20:13:30
(1 week ago)
(confirmed_bot_sig) Confirmed bot
Hacking
πΊπΈ
TPI-Abuse
2026-06-08 19:43:57
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.40.86.72 (72.86.40.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.40.86.72 (72.86.40.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 15:43:51.372873 2026] [security2:error] [pid 18392:tid 18392] [client 34.40.86.72:34474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jasonpolland.com"] [uri "/.git/config"] [unique_id "aicbdzPkYLdM9g91nqDZwAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack