🇳🇱
homeshowdomain.nl
2026-08-27 22:00:34
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-26.
show less
Web App Attack
SSH
Hacking
🇬🇧
thetomtaylor.co.uk
2026-08-26 20:08:02
(3 days ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 19:50:34
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.83.163.209 (209.163.83.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.83.163.209 (209.163.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 15:50:27.323960 2026] [security2:error] [pid 12997:tid 12997] [client 34.83.163.209:13510] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bouldercorporate.com"] [uri "/.git/config"] [unique_id "ao9Dgw_DJE7MWRVJS8rx5QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 19:33:53
(3 days ago)
git/env leak probe
Web App Attack
🇿🇦
conure.sh
2026-08-26 19:27:43
(3 days ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 2 domain(s) in 0s
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 19:24:38
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 34.83.163.209 (209.163.83.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 34.83.163.209 (209.163.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 15:24:30.548573 2026] [security2:error] [pid 29532:tid 29532] [client 34.83.163.209:47634] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "brianandstar.com"] [uri "/.git/config"] [unique_id "ao89bqQICCRyOPGshm7AogAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇩
Burayot
2026-08-26 19:08:05
(3 days ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.83.163.209 (US/United States/209 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.83.163.209 (US/United States/209.163.83.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-08-26 19:08:00
(3 days ago)
Fail2Ban - [RECIDIVE]Repeat offender across multiple jails on recidive ... [ice02,mx02,wa01,wa02]
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 19:06:23
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.83.163.209 (209.163.83.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.83.163.209 (209.163.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 15:06:19.037258 2026] [security2:error] [pid 5497:tid 5497] [client 34.83.163.209:44912] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arttechnology.net"] [uri "/.git/config"] [unique_id "ao85K96u0BLsV_bzrLIOwwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
boxed-it
2026-08-26 18:29:42
(3 days ago)
GET /.git/config (Tarpitted for 2m10s, wasted 7.73kB)
Web App Attack
🇺🇸
TPI-Abuse
2026-08-26 18:17:29
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 34.83.163.209 (209.163.83.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.83.163.209 (209.163.83.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 14:17:25.346931 2026] [security2:error] [pid 13444:tid 13444] [client 34.83.163.209:1126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bicaco.com"] [uri "/.git/config"] [unique_id "ao8ttdbvxmusQsdZ2aJ1agAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-26 18:17:27
(3 days ago)
apache vulnerability scan
Web App Attack
🇩🇪
macrob
2026-08-26 18:05:22
(3 days ago)
2026/08/26 18:05:20 [error] 2096797#2096797: *523693629 access forbidden by rule, client: 34.83.163. ...
show more
2026/08/26 18:05:20 [error] 2096797#2096797: *523693629 access forbidden by rule, client: 34.83.163.209, server: binixo.mx, request: "GET /.git/config HTTP/1.1", host: "binixo.mx"
2026/08/26 18:05:21 [error] 2096797#2096797: *523693641 access forbidden by rule, client: 34.83.163.209, server: fn.binixo.es, request: "GET /.git/config HTTP/1.1", host: "binixo.bg"
2026/08/26 18:05:21 [error] 2096797#2096797: *523693640 access forbidden by rule, client: 34.83.163.209, server: binixo.com.ua, request: "GET /.git/config HTTP/1.1", host: "binixo.com.ua"
...
show less
Web App Attack
🇦🇺
2000cn.com.au
2026-08-26 18:05:22
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
kosada.com
2026-08-26 18:01:38
(3 days ago)
Web vulnerability probing: /.git/config
Web App Attack