π³π±
homeshowdomain.nl
2026-06-15 22:03:22
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-14.
show less
Web App Attack
SSH
Hacking
π¬π§
thetomtaylor.co.uk
2026-06-15 09:07:02
(1 day ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-15 09:05:02
(1 day ago)
suspicious request in access.log
Web App Attack
π©πͺ
Lino Project
2026-06-15 08:46:37
(1 day ago)
CrowdSec abuse IP report (host SRV-2) Scenario: crowdsecurity/http-sensitive-files
Hacking
π³π±
Mangelot Hosting
2026-06-15 08:33:31
(1 day ago)
(modsecurity) srv101 ModSecurity 34.87.50.125 (SG/Singapore/125.50.87.34.bc.googleusercontent.com): ...
show more
(modsecurity) srv101 ModSecurity 34.87.50.125 (SG/Singapore/125.50.87.34.bc.googleusercontent.com): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 08:22:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.87.50.125 (125.50.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.50.125 (125.50.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 04:22:49.097671 2026] [security2:error] [pid 15779:tid 15779] [client 34.87.50.125:37156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ltscatering.com"] [uri "/blog/.git/config"] [unique_id "ai-2WXsn8b7_s_sZb9TyigAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³πΏ
Antinson
2026-06-15 07:35:16
(1 day ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-06-15 06:28:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.87.50.125 (125.50.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.50.125 (125.50.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 02:28:43.269118 2026] [security2:error] [pid 17182:tid 17182] [client 34.87.50.125:60762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brookspowell.com"] [uri "/.git/config"] [unique_id "ai-bm-85aIZiVzh3WNyqxgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-06-15 05:34:16
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 05:20:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.87.50.125 (125.50.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.50.125 (125.50.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 01:20:49.117713 2026] [security2:error] [pid 11983:tid 12120] [client 34.87.50.125:42030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cirugiaestetica.us.aafm.us"] [uri "/html/.git/config"] [unique_id "ai-LsZvhI7JvnBu6cqXo1AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 04:49:00
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.87.50.125 (125.50.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.50.125 (125.50.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 00:48:52.572615 2026] [security2:error] [pid 23791:tid 23791] [client 34.87.50.125:51362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.b2qc.com.anthonyanimalclinic.net"] [uri "/dashboard/.git/config"] [unique_id "ai-ENHHqG0BxLuDp9j9edwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
SSH-Admin
2026-06-15 04:00:04
(1 day ago)
Probing for Exploits on ns200
Exploited Host
Web App Attack
π©πͺ
MBombeck
2026-06-15 03:52:50
(1 day ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-15 03:32:26
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.87.50.125 (125.50.87.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.87.50.125 (125.50.87.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 23:32:21.645648 2026] [security2:error] [pid 12890:tid 12890] [client 34.87.50.125:60622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fedeolivaperu.com"] [uri "/www/.git/config"] [unique_id "ai9yRT6r2AxxFhah2o18_QAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
4server
2026-06-15 02:42:07
(1 day ago)
[MonJun1504:42:02.5606362026][security2:error][pid3433961:tid3433967][client34.87.50.125:0]ModSecuri ...
show more
[MonJun1504:42:02.5606362026][security2:error][pid3433961:tid3433967][client34.87.50.125:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.elearning.aaaa6877.org\"][uri\"/.git/config\"][unique_id\"ai9mevVHKKAbdH2Vu-gjQAAAAAI\"]
show less
Port Scan
Brute-Force
Web App Attack