🇳🇱
homeshowdomain.nl
2026-09-06 22:01:40
(15 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-05.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-09-06 07:57:09
(1 day ago)
34.47.26.48 - - [06/Sep/2026:09:57:08 +0200] "GET /site/.git/config HTTP/1.1" 444 0 "-" "crusader-wo ...
show more
34.47.26.48 - - [06/Sep/2026:09:57:08 +0200] "GET /site/.git/config HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
34.47.26.48 - - [06/Sep/2026:09:57:08 +0200] "GET /www/.git/config HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
🇧🇾
lns.bz
2026-09-06 06:25:55
(1 day ago)
Too many 404 requests [BY]
Web App Attack
🇫🇷
masterguru
2026-09-06 03:53:38
(1 day ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 34.47.26.48 (CA/Canada/48.26.47.34.bc.googleus ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 34.47.26.48 (CA/Canada/48.26.47.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-196)
show less
Hacking
🇩🇪
stinpriza
2026-09-06 01:55:24
(1 day ago)
common Web Exploits being scanned
Web App Attack
🇳🇱
Eric
2026-09-06 01:41:32
(1 day ago)
[Sun Sep 06 01:41:26.309264 2026] [security2:error] [pid 252356:tid 252356] [client 34.47.26.48:3485 ...
show more
[Sun Sep 06 01:41:26.309264 2026] [security2:error] [pid 252356:tid 252356] [client 34.47.26.48:34858] [client 34.47.26.48] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "fambus.nl"] [uri "/src/.git/config"] [unique_id "apzExhPxcx-Rwv3tEXSgJwAAAAU"]
[Sun Sep 06 01:41:26.309732 2026] [security2:error] [pid 251582:tid 251582] [client 34.47.26.48:34852] [client 34.47.26.48] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity
...
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 23:19:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.26.48 (48.26.47.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.26.48 (48.26.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:19:34.983052 2026] [security2:error] [pid 17155:tid 17155] [client 34.47.26.48:42348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "compformation.com"] [uri "/src/.git/config"] [unique_id "apyjhhcNcNLhYfxb0m9YdQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:08:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.26.48 (48.26.47.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.26.48 (48.26.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:08:43.568629 2026] [security2:error] [pid 4094055:tid 4094075] [client 34.47.26.48:54306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "n30ew.com"] [uri "/.git/config"] [unique_id "apyS666cqs6FLYTdRl-pnwAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 21:20:04
(1 day ago)
Web application attack detected.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:10:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.47.26.48 (48.26.47.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.47.26.48 (48.26.47.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:10:19.728911 2026] [security2:error] [pid 15289:tid 15289] [client 34.47.26.48:55158] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "valuechains4poor.net"] [uri "/public/.git/config"] [unique_id "apyFO9PGHj4SSWrv7DTr0gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-05 21:09:30
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇩🇪
pigro
2026-09-04 17:57:57
(2 days ago)
34.47.26.48 - - [04/Sep/2026:19:57:57 +0200] "GET /public/cards.min.js.map/ HTTP/1.1" 404 6771 "http ...
show more
34.47.26.48 - - [04/Sep/2026:19:57:57 +0200] "GET /public/cards.min.js.map/ HTTP/1.1" 404 6771 "https://mail.pigro.site/public/cards.min.js.map" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
34.47.26.48 - - [04/Sep/2026:19:57:57 +0200] "GET /public/member-attribution.min.js.map/ HTTP/1.1" 404 6771 "https://mail.pigro.site/public/member-attribution.min.js.map" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
...
show less
Web App Attack
🇳🇱
Cloud86 B.V.
2026-09-04 06:54:01
(3 days ago)
categories: DDoS Attack
DDoS Attack