๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 21:59:47
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
๐ซ๐ท
masterguru
2026-06-09 03:19:30
(1 week ago)
(modsec_5015) ModSec 5015: Suspicious User-Agent from 34.71.98.179 (US/United States/179.98.71.34.bc ...
show more
(modsec_5015) ModSec 5015: Suspicious User-Agent from 34.71.98.179 (US/United States/179.98.71.34.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-08 21:10:14
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.71.98.179 (179.98.71.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.71.98.179 (179.98.71.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 17:10:09.926005 2026] [security2:error] [pid 5997:tid 5997] [client 34.71.98.179:47044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.itimetable21.com"] [uri "/.git/config"] [unique_id "aicvsXZrWWQ8VYgwKZ2g3AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 20:10:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.71.98.179 (179.98.71.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.71.98.179 (179.98.71.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 16:10:00.277387 2026] [security2:error] [pid 4622:tid 4622] [client 34.71.98.179:46788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "epk.gmacguffin.com"] [uri "/.git/config"] [unique_id "aichmOmuXZSFv9pjbc5eVQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 19:29:51
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.71.98.179 (179.98.71.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.71.98.179 (179.98.71.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 15:29:46.820864 2026] [security2:error] [pid 28391:tid 28391] [client 34.71.98.179:54014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "venture2-22.org"] [uri "/.git/config"] [unique_id "aicYKso1c0ye7j-9JjAlTQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-06-08 19:28:21
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-08 18:17:07
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.71.98.179 (179.98.71.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.71.98.179 (179.98.71.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 14:17:00.695048 2026] [security2:error] [pid 4374:tid 4393] [client 34.71.98.179:49582] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ip.kd9uri.com"] [uri "/.git/config"] [unique_id "aicHHOeDhzLlILq7UneAkAAAAQs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-08 17:36:43
(1 week ago)
[MonJun0819:36:41.0749502026][security2:error][pid1590354:tid1590528][client34.71.98.179:0]ModSecuri ...
show more
[MonJun0819:36:41.0749502026][security2:error][pid1590354:tid1590528][client34.71.98.179:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"bellissimo.io.136-243-54-122.cpanel.site\"][uri\"/.git/config\"][unique_id\"aib9qVNm6lAbKsBcOEpmUgAAAM0\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 15:24:47
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 34.71.98.179 (179.98.71.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.71.98.179 (179.98.71.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 11:24:39.453888 2026] [security2:error] [pid 21685:tid 21685] [client 34.71.98.179:43268] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "ritualistik.com.experimentalscene.com"] [uri "/.git/config"] [unique_id "aibet-ara1Ft-cP-OVwvRQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 12:58:54
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.71.98.179 (179.98.71.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.71.98.179 (179.98.71.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 08:58:50.068688 2026] [security2:error] [pid 24961:tid 24961] [client 34.71.98.179:35814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnmorogiello.com"] [uri "/.git/config"] [unique_id "aia8iuFOh-guyfQcHDugtAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-08 12:50:25
(1 week ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 12:13:51
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.71.98.179 (179.98.71.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.71.98.179 (179.98.71.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 08:13:43.449032 2026] [security2:error] [pid 18162:tid 18162] [client 34.71.98.179:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.distro.media"] [uri "/.git/config"] [unique_id "aiax97A6CxEqXUGpilkpbgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-06-08 08:13:34
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Nokia6630/1.0 (2.39.15) SymbianOS/8.0 Series60/2.6 Profile/MIDP-2.0 Configuration/CLDC-1.1
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐จ๐ญ
4server
2026-06-08 07:51:23
(1 week ago)
[MonJun0809:51:16.8651952026][security2:error][pid3195932:tid3196346][client34.71.98.179:0]ModSecuri ...
show more
[MonJun0809:51:16.8651952026][security2:error][pid3195932:tid3196346][client34.71.98.179:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.dc-graphicart.com.81-17-25-250.cpanel.site\"][uri\"/.git/config\"][unique_id\"aiZ0dCZOxGuMuJzUxKd-VAAAAJU\"]
show less
Hacking
Web App Attack
๐บ๐ธ
OceanTreasure
2026-06-08 07:35:06
(1 week ago)
tcp/443; Git configuration exposure attempt: "GET /.git/config" @ 2026-06-08T07:26:27Z [proxy]
Web App Attack