๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:01:31
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
4server
2026-06-09 15:54:28
(1 week ago)
[TueJun0917:54:23.1439032026][security2:error][pid3148356:tid3148428][client34.62.249.152:0]ModSecur ...
show more
[TueJun0917:54:23.1439032026][security2:error][pid3148356:tid3148428][client34.62.249.152:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"aexthesya.ch\"][uri\"/.git/config\"][unique_id\"aig3L_JBCuiNejK73E4UEAAAAIo\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 15:19:06
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.62.249.152 (152.249.62.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.249.152 (152.249.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 11:18:59.316453 2026] [security2:error] [pid 5945:tid 5945] [client 34.62.249.152:45466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sthefany.aguasolar.com"] [uri "/.git/config"] [unique_id "aigu45mCLqXlaO-soEwUqQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-06-09 15:15:59
(1 week ago)
Accessed trap at '/.git/config'
Web App Attack
๐บ๐ธ
lnklnx
2026-06-09 09:47:17
(1 week ago)
www.lnklnx.com:443 34.62.249.152 - - [09/Jun/2026:04:47:14 -0500] "GET /.git/config HTTP/1.1" 403 38 ...
show more
www.lnklnx.com:443 34.62.249.152 - - [09/Jun/2026:04:47:14 -0500] "GET /.git/config HTTP/1.1" 403 3823 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 12_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) CriOS/76.0.3809.81 Mobile/15E148 Safari/605.1"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 09:35:10
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.62.249.152 (152.249.62.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.249.152 (152.249.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 05:35:06.690043 2026] [security2:error] [pid 24337:tid 24337] [client 34.62.249.152:38008] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kingdomvalleyfarm.com"] [uri "/.git/config"] [unique_id "aifeSi-eKx-VmGp3rPIVogAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 08:30:26
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.62.249.152 (152.249.62.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.249.152 (152.249.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 04:30:21.224577 2026] [security2:error] [pid 22377:tid 22377] [client 34.62.249.152:33814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wandathelittlestwizard.dvdmasters.com"] [uri "/.git/config"] [unique_id "aifPHT42uOnnvje6Fhm3yAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 07:31:03
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.62.249.152 (152.249.62.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.249.152 (152.249.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 03:30:56.987497 2026] [security2:error] [pid 9981:tid 9996] [client 34.62.249.152:36440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3stepreviewforyou.com"] [uri "/.git/config"] [unique_id "aifBMPFXVgRp6K1Y9XU5LwAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-09 07:28:16
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 06:34:34
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.62.249.152 (152.249.62.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.249.152 (152.249.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 02:34:28.595951 2026] [security2:error] [pid 6597:tid 6597] [client 34.62.249.152:37624] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "altruaglobalsolutions.com"] [uri "/.git/config"] [unique_id "aiez9DVngjDdLJVeiLUk3QAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
joharikop
2026-06-09 06:34:32
(1 week ago)
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-cred ...
show more
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-credential-probes jail.
show less
Web App Attack
๐ฉ๐ช
IVski
2026-06-09 06:10:53
(1 week ago)
IVski WAF | Sensitive file probe detected - looking for .git
Port Scan
Brute-Force
Web App Attack
๐ซ๐ท
masterguru
2026-06-09 05:57:30
(1 week ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.62.249.152 (BE/Belgium/152.249.62. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 34.62.249.152 (BE/Belgium/152.249.62.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐จ๐ญ
backslash
2026-06-09 05:42:01
(1 week ago)
block ruleset bad bot: github scan 052A73F305734A39936C6BD919E2C0BF536B62AC
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-09 02:45:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.62.249.152 (152.249.62.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.62.249.152 (152.249.62.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 22:45:32.089915 2026] [security2:error] [pid 1814:tid 1814] [client 34.62.249.152:55102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tribecalledfamilypodcast.org"] [uri "/.git/config"] [unique_id "aid-TCk5gPwCuqkywOkMsQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack