๐ณ๐ฑ
homeshowdomain.nl
2026-04-04 22:02:13
(2 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-04-03.
show less
Web App Attack
SSH
Hacking
๐ญ๐ท
bubausluge
2026-04-04 07:02:05
(2 months ago)
Detected by Aegis SOC: Web Credential File Probe | MITRE: T1552.001 | Fails: 1 | Period: 2026-04-03T ...
show more
Detected by Aegis SOC: Web Credential File Probe | MITRE: T1552.001 | Fails: 1 | Period: 2026-04-03T15:54:41 to 2026-04-03T15:54:41
show less
Brute-Force
๐ฌ๐ง
openstrike.co.uk
2026-04-04 05:14:24
(2 months ago)
2 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
๐ณ๐ฑ
jjnxpct
2026-04-04 03:53:30
(2 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.git/config (Rule ID: 930130) - Restricted File Access Attempt [Suspicious: .git/ found within REQUEST_FILENAME: /.git/config]
show less
Web App Attack
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-04-03 21:59:26
(2 months ago)
Auto-ban: >3000 req/min op 2026-04-03
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-03 20:11:40
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 34.9.220.82 (82.220.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.220.82 (82.220.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 16:11:36.828665 2026] [security2:error] [pid 31817:tid 31817] [client 34.9.220.82:33874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.martinka.martinka.org"] [uri "/.git/config"] [unique_id "adAe-CLEDeHOxQ-yfTIsIQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-04-03 19:57:39
(2 months ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 19:48:33
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 34.9.220.82 (82.220.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.220.82 (82.220.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 15:48:29.503515 2026] [security2:error] [pid 28229:tid 28241] [client 34.9.220.82:38450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.maritimeclinic.net"] [uri "/.git/config"] [unique_id "adAZjfePvtlP4rMcjAhRYwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฟ
ddw
2026-04-03 19:25:47
(2 months ago)
ModSecurity detection - Rules: 930130(Restricted File Access Attempt)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 19:11:52
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 34.9.220.82 (82.220.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.220.82 (82.220.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 15:11:44.445774 2026] [security2:error] [pid 4072:tid 4072] [client 34.9.220.82:34030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mando.cloudex.link"] [uri "/.git/config"] [unique_id "adAQ8HsEvmoM1fscGNLvqgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Roper123
2026-04-03 18:53:52
(2 months ago)
Web exploits
Web App Attack
๐ฎ๐ฉ
Burayot
2026-04-03 18:47:28
(2 months ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.9.220.82 (US/United States/82.22 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.9.220.82 (US/United States/82.220.9.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐ณ๐ฟ
Antinson
2026-04-03 18:46:26
(2 months ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
๐ฉ๐ช
Lino Project
2026-04-03 18:29:19
(2 months ago)
34.9.220.82 - - [03/Apr/2026:20:29:19 +0200] "GET /.git/config HTTP/1.1" 404 3697 "-" "-"
...
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-03 18:22:26
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 34.9.220.82 (82.220.9.34.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 34.9.220.82 (82.220.9.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 14:22:18.481262 2026] [security2:error] [pid 31631:tid 31631] [client 34.9.220.82:46036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mail.zmgmt.com"] [uri "/.git/config"] [unique_id "adAFWn0-2kWxhXI0fXm6xAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack