π©πͺ
klaus_ph
2026-09-27 22:04:02
(5 hours ago)
2026-09-26 23:35:12,170 fail2ban.actions [8144]: NOTICE [ipblocklist] Ban 34.61.126.6
...
Bad Web Bot
Anonymous
2026-09-25 23:06:44
(2 days ago)
Trying to access config files
Web App Attack
π³π±
homeshowdomain.nl
2026-09-25 22:02:02
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-24.
show less
Web App Attack
SSH
Hacking
πΏπ¦
conure.sh
2026-09-25 12:02:04
(2 days ago)
csagent: score 20.1: secrets grab x2, 404 noise floor x1; 2 domain(s) in 3s
Web App Attack
πΊπΈ
mnsf
2026-09-24 20:05:42
(3 days ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-24 19:24:30
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.61.126.6 (6.126.61.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.126.6 (6.126.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 15:24:25.262478 2026] [security2:error] [pid 30033:tid 30033] [client 34.61.126.6:59866] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "charlesrader.com"] [uri "/.git/config"] [unique_id "arV46SmqpzrIbQY5OiFmlwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
ingroscart.it
2026-09-24 18:59:42
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-24 18:55:51
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.61.126.6 (6.126.61.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.126.6 (6.126.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:55:48.069873 2026] [security2:error] [pid 10032:tid 10032] [client 34.61.126.6:40164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cekilis.kircali.net"] [uri "/.git/config"] [unique_id "arVyNJeqPJq2od1h5Z-5ZwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 18:48:34
(3 days ago)
34.61.126.6 - - [24/Sep/2026:18:48:33 +0000] "GET /.git/config HTTP/1.1" 403 4455 "-" "-"
...
Bad Web Bot
Web App Attack
π©πͺ
Hary74656
2026-09-24 18:40:12
(3 days ago)
Fail2Ban on schani.hostmi.at: jail=apache-instablock, failures=1.
[client 34.61.126.6] [realclient 3 ...
show more
Fail2Ban on schani.hostmi.at: jail=apache-instablock, failures=1.
[client 34.61.126.6] [realclient 34.61.126.6] [24/Sep/2026:20:40:11 +0200] [vhost schani.hostmi.at] 403 "GET /.git/config HTTP/1.1"
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-24 18:30:20
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.61.126.6 (6.126.61.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.126.6 (6.126.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:30:14.277117 2026] [security2:error] [pid 561:tid 561] [client 34.61.126.6:56120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cbrcabrero.cl.tecnoconce.com"] [uri "/.git/config"] [unique_id "arVsNpnNtFwhptVPifGw0wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-24 18:07:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.61.126.6 (6.126.61.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.126.6 (6.126.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:07:14.054270 2026] [security2:error] [pid 18933:tid 18933] [client 34.61.126.6:47380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "casademunt.com"] [uri "/.git/config"] [unique_id "arVm0rvZliMd_zAcVQOoUAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-24 17:51:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.61.126.6 (6.126.61.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.61.126.6 (6.126.61.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 13:50:58.403075 2026] [security2:error] [pid 21676:tid 21676] [client 34.61.126.6:41646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "carbonless.net"] [uri "/.git/config"] [unique_id "arVjAv5htDBNsd5u4_gilQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
BlueWire Hosting
2026-09-24 17:48:54
(3 days ago)
High-confidence malicious configuration/VCS probe
Web App Attack
Anonymous
2026-09-24 17:42:34
(3 days ago)
[ssd5.kdns.gr] httpd-config-scan: sites=www.cancelletto.gr; logs=/var/log/httpd/domains/cancelletto. ...
show more
[ssd5.kdns.gr] httpd-config-scan: sites=www.cancelletto.gr; logs=/var/log/httpd/domains/cancelletto.gr.log; samples=/.git/config
show less
Hacking
Web App Attack