๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:00:47
(6 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
๐ง๐ช
cmbplf
2026-06-09 17:30:47
(10 hours ago)
12.527 requests with url.path *.git/*
Brute-Force
Bad Web Bot
๐ฎ๐ฉ
Burayot
2026-06-09 15:49:06
(12 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.92.131.96 (HK/Hong Kong/96.131.9 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.92.131.96 (HK/Hong Kong/96.131.92.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 15:25:35
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.131.96 (96.131.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.131.96 (96.131.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 11:25:29.595737 2026] [security2:error] [pid 11649:tid 11649] [client 34.92.131.96:60894] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sieder.com.ar"] [uri "/.git/config"] [unique_id "aigwaYE5txEJ0Z2oi-4qAAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 15:10:13
(12 hours ago)
34.92.131.96 - - [09/Jun/2026:15:10:12 +0000] "GET /.git/config HTTP/1.1" 404 6940 "-" "Mozilla/5.0 ...
show more
34.92.131.96 - - [09/Jun/2026:15:10:12 +0000] "GET /.git/config HTTP/1.1" 404 6940 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/67.0.3396.87 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-09 14:48:37
(13 hours ago)
Try to access /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 14:47:52
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.131.96 (96.131.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.131.96 (96.131.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 10:47:48.419591 2026] [security2:error] [pid 21447:tid 21447] [client 34.92.131.96:43282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gracefaerie.com"] [uri "/.git/config"] [unique_id "aignlEOc7RXotmoZZX3oxAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
oralunal
2026-06-09 14:38:07
(13 hours ago)
IP banned by Fail2Ban in jail suss access.log ah-app-1
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 13:30:53
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.131.96 (96.131.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.131.96 (96.131.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 09:30:49.790959 2026] [security2:error] [pid 1126:tid 1126] [client 34.92.131.96:45236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.mumawvickers.com"] [uri "/.git/config"] [unique_id "aigViduI7pcOik5T0nmmfQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-09 12:33:43
(15 hours ago)
[TueJun0914:33:39.4408742026][security2:error][pid2909886:tid2910013][client34.92.131.96:0]ModSecuri ...
show more
[TueJun0914:33:39.4408742026][security2:error][pid2909886:tid2910013][client34.92.131.96:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.cnv.wildpferde.ch\"][uri\"/.git/config\"][unique_id\"aigII2YB8zr5nDJ7pVvOswAAAQk\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-09 12:24:06
(15 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 11:27:08
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.131.96 (96.131.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.131.96 (96.131.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 07:27:04.569112 2026] [security2:error] [pid 25122:tid 25122] [client 34.92.131.96:53180] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.smog-test-coupons.smogsandiego.com"] [uri "/.git/config"] [unique_id "aif4iDcqExHJ51c5hy4-qQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 10:02:20
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.131.96 (96.131.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.131.96 (96.131.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 06:02:13.979627 2026] [security2:error] [pid 21444:tid 21444] [client 34.92.131.96:41170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "debbieweibler.com"] [uri "/.git/config"] [unique_id "aifkpW5Kx3Wl1-fsSIxMtgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 08:23:30
(19 hours ago)
(mod_security) mod_security (id:949110) triggered by 34.92.131.96 (96.131.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 34.92.131.96 (96.131.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 04:23:25.276641 2026] [security2:error] [pid 22910:tid 22910] [client 34.92.131.96:59758] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "theshitmykidsays.com"] [uri "/.git/config"] [unique_id "aifNfQTD-vhurdg5YJ2PuwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 08:05:23
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.92.131.96 (96.131.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.131.96 (96.131.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 04:05:19.290715 2026] [security2:error] [pid 6627:tid 6642] [client 34.92.131.96:59472] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lisabee.mailporte.com"] [uri "/.git/config"] [unique_id "aifJP4s-hiznFUaBx_pz3gAAAEw"]
show less
Brute-Force
Bad Web Bot
Web App Attack