๐ณ๐ฑ
homeshowdomain.nl
2026-09-18 21:59:32
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-17.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-17 03:47:56
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.60.165.9 (9.165.60.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.60.165.9 (9.165.60.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 23:47:52.505522 2026] [security2:error] [pid 29484:tid 29490] [client 34.60.165.9:32874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "siriuspharmaceuticals.com"] [uri "/.git/config"] [unique_id "aqti6GF3gjv09JWJTgoaJgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
JonathanYoung2161
2026-09-17 02:54:36
(3 days ago)
sipconnect.simplifiedmedia.net 34.60.165.9 - - [16/Sep/2026:21:54:34 -0500] "GET /.git/config HTTP/2 ...
show more
sipconnect.simplifiedmedia.net 34.60.165.9 - - [16/Sep/2026:21:54:34 -0500] "GET /.git/config HTTP/2.0" 403 2998 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
sipconnect.simplifiedmedia.net 34.60.165.9 - - [16/Sep/2026:21:54:35 -0500] "GET /.env HTTP/2.0" 403 2998 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
sipconnect.simplifiedmedia.net 34.60.165.9 - - [16/Sep/2026:21:54:35 -0500] "GET /.env.local HTTP/2.0" 403 2998 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ฎ๐ฉ
zam
2026-09-17 02:52:34
(3 days ago)
34.60.165.9 - - [17/Sep/2026:02:52:29 +0000] "GET /administrator/phpinfo.php HTTP/1.1" 302 286
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 02:36:15
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.60.165.9 (9.165.60.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.60.165.9 (9.165.60.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:36:08.251173 2026] [security2:error] [pid 32431:tid 32431] [client 34.60.165.9:35366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "siouxfallslimos.com"] [uri "/.git/config"] [unique_id "aqtSGLXV1usYragGV3O1iQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 02:12:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.60.165.9 (9.165.60.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.60.165.9 (9.165.60.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:11:58.943228 2026] [security2:error] [pid 704294:tid 704294] [client 34.60.165.9:36680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sinsky.net"] [uri "/.git/config"] [unique_id "aqtMboLq6uo-029jNlwelwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-16 16:42:28
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 16:42:06
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.60.165.9 (9.165.60.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.60.165.9 (9.165.60.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:41:57.076865 2026] [security2:error] [pid 15530:tid 15530] [client 34.60.165.9:51724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rums-of-the-world.com"] [uri "/.git/config"] [unique_id "aqrG1W_BUhYfQ3Hw9TQsrQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 15:25:35
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.60.165.9 (9.165.60.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.60.165.9 (9.165.60.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 11:25:29.098148 2026] [security2:error] [pid 17756:tid 17756] [client 34.60.165.9:50440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ruizpuche.com"] [uri "/.git/config"] [unique_id "aqq06ftKXGBv12Y-3VkcvgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-16 14:39:58
(4 days ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 34.60.165.9 - - [16/Sep/2026:16:39:51 +0200] "GET /.git/config HTTP/1.1" 301 512 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-16 14:30:04
(4 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-16 14:13:05
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 27
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:43:54
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.60.165.9 (9.165.60.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.60.165.9 (9.165.60.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:43:38.153926 2026] [security2:error] [pid 25145:tid 25145] [client 34.60.165.9:56144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rudiscreations.org"] [uri "/.git/config"] [unique_id "aqqdCjK1vicj6QjSa3GfQAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Origon
2026-09-16 13:23:28
(4 days ago)
http-sensitive-files - IP: 34.60.165.9 - time="2026-09-16T15:23:28+02:00" level=info msg="(555f66b4 ...
show more
http-sensitive-files - IP: 34.60.165.9 - time="2026-09-16T15:23:28+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 34.60.165.9 (US/396982) : 4h ban on Ip 34.60.165.9" module=db
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:11:52
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 34.60.165.9 (9.165.60.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.60.165.9 (9.165.60.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:11:45.791301 2026] [security2:error] [pid 17850:tid 17850] [client 34.60.165.9:34026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rubypines.com"] [uri "/.git/config"] [unique_id "aqqVkZ7GdmOBcKuC1FxOjAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack