๐ฌ๐ง
AvonleaConsulting
2026-06-09 22:58:11
(5 days ago)
Attempts to probe web pages for vulnerable PHP or other applications
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:02:16
(5 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 14:43:36
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.44.164.166 (166.164.44.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.164.166 (166.164.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 10:43:28.772114 2026] [security2:error] [pid 18124:tid 18124] [client 34.44.164.166:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.abdulhameeds.art"] [uri "/.git/config"] [unique_id "aigmkHgl878aScrmmhMZrAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 14:28:20
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.44.164.166 (166.164.44.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.164.166 (166.164.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 10:28:13.499968 2026] [security2:error] [pid 19491:tid 19491] [client 34.44.164.166:47014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pattymoorearmstrong.com"] [uri "/.git/config"] [unique_id "aigi_fpsEgjcNBnfpVZuiQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-09 13:31:29
(6 days ago)
[TueJun0915:31:24.9710252026][security2:error][pid2989137:tid2989296][client34.44.164.166:0]ModSecur ...
show more
[TueJun0915:31:24.9710252026][security2:error][pid2989137:tid2989296][client34.44.164.166:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"artisteer-italia.org\"][uri\"/.git/config\"][unique_id\"aigVrGPhRyO8VYvjNQibiAAAAQU\"]
show less
Port Scan
Brute-Force
Web App Attack
๐จ๐ญ
๐จ๐ญ Hosting
2026-06-09 11:40:02
(6 days ago)
Automated security scanning detected: Git Repository Config Exposure. Systematic reconnaissance usin ...
show more
Automated security scanning detected: Git Repository Config Exposure. Systematic reconnaissance using automated tools.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 11:19:58
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.44.164.166 (166.164.44.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.164.166 (166.164.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 07:19:50.982890 2026] [security2:error] [pid 24756:tid 24756] [client 34.44.164.166:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.dentguyvt.com"] [uri "/.git/config"] [unique_id "aif21reyFgF7gX81Y0HSLwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-06-09 11:18:55
(6 days ago)
[TueJun0913:18:48.7958652026][security2:error][pid797219:tid797265][client34.44.164.166:0]ModSecurit ...
show more
[TueJun0913:18:48.7958652026][security2:error][pid797219:tid797265][client34.44.164.166:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.walter-worndli.ch.xn--walter-wrndli-pmb.ch\"][uri\"/.git/config\"][unique_id\"aif2mEKzulbfEo4auHuu4gAAAVg\"]
show less
Hacking
Web App Attack
๐บ๐ธ
interbiznw.com
2026-06-09 10:36:46
(6 days ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 10:19:11
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.44.164.166 (166.164.44.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.164.166 (166.164.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 06:19:05.067767 2026] [security2:error] [pid 4278:tid 4278] [client 34.44.164.166:58456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brinkworthmodels.com"] [uri "/.git/config"] [unique_id "aifomQ_uzTqfNQd0B9gytwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 08:44:49
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.44.164.166 (166.164.44.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.164.166 (166.164.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 04:44:41.431721 2026] [security2:error] [pid 31314:tid 31314] [client 34.44.164.166:49264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kwieser.com"] [uri "/.git/config"] [unique_id "aifSeW6_zBbJVx_AeWp7ZgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 08:16:54
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.44.164.166 (166.164.44.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.164.166 (166.164.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 04:16:49.452342 2026] [security2:error] [pid 2769:tid 2769] [client 34.44.164.166:58750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kangen-agua.com.player-care.com"] [uri "/.git/config"] [unique_id "aifL8UQ13oJ3BUzYmcc5kwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-09 08:12:14
(6 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 12
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 07:17:36
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 34.44.164.166 (166.164.44.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.44.164.166 (166.164.44.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 03:17:30.793061 2026] [security2:error] [pid 32599:tid 32599] [client 34.44.164.166:36654] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.infinite-fitness.com.helpkccare.org"] [uri "/.git/config"] [unique_id "aie-CpXIsLGJwy15CcgAuQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
SOC PR
2026-06-09 05:50:51
(6 days ago)
IPS: Web Server Exposed Git Repository Information Disclosure.
Hacking