๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:01:44
(17 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 13:27:52
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.92.148.196 (196.148.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.148.196 (196.148.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 09:27:47.666979 2026] [security2:error] [pid 19617:tid 19617] [client 34.92.148.196:41040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.howtokeepgoodemployeescom.indie100.com"] [uri "/.git/config"] [unique_id "aigU01Tcf9opoycO_f2doAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-09 12:42:45
(1 day ago)
Try to access /.git/config
Web App Attack
๐ซ๐ฎ
as211431.net
2026-06-09 11:59:32
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from HK.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET metho ...
show more
Triggered Cloudflare WAF (firewallCustom) from HK.
Action taken: BLOCK
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_13_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.87 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-09 11:37:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.92.148.196 (196.148.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.148.196 (196.148.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 07:37:08.865236 2026] [security2:error] [pid 32260:tid 32260] [client 34.92.148.196:33774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.beta.instagenii.com"] [uri "/.git/config"] [unique_id "aif65FKe1vK925Wkve0YxQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 10:37:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.92.148.196 (196.148.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.148.196 (196.148.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 06:36:55.592491 2026] [security2:error] [pid 9600:tid 9600] [client 34.92.148.196:59042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lubbockknights.com"] [uri "/.git/config"] [unique_id "aifsx2CnB42Ax1zP38PdFwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-06-09 10:25:25
(1 day ago)
[TueJun0912:25:22.9458862026][security2:error][pid632167:tid632441][client34.92.148.196:0]ModSecurit ...
show more
[TueJun0912:25:22.9458862026][security2:error][pid632167:tid632441][client34.92.148.196:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"avvnicolaurbani.ch\"][uri\"/.git/config\"][unique_id\"aifqEvUygZV65XyjD-YwdgAAARU\"]
show less
Hacking
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-06-09 07:26:43
(1 day ago)
[Tue Jun 09 17:26:42.367479 2026] [security2:error] [pid 203945] [client 34.92.148.196:40980] [clien ...
show more
[Tue Jun 09 17:26:42.367479 2026] [security2:error] [pid 203945] [client 34.92.148.196:40980] [client 34.92.148.196] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "talentaymerch.com.au"] [uri "/.git/config"] [unique_id "aifAMmcc2RyrHRwG2lxYQQAAAAg"]
...
show less
Web App Attack
๐ซ๐ท
โจ
2026-06-09 03:54:04
(1 day ago)
Domain : gestioncgt.es
Rule : config
2026-06-09 03:53:16 ***hidden-privacy*** GET /.git/config - 443 ...
show more
Domain : gestioncgt.es
Rule : config
2026-06-09 03:53:16 ***hidden-privacy*** GET /.git/config - 443 - 34.92.148.196 HTTP/1.1 Mozilla/5.0 (Windows; U; WinNT4.0; en-US; rv:1.2b) Gecko/20021001 Phoenix/0.2 - gestioncgt.es 404 8 0 5373 206 414 - -
show less
Hacking
SQL Injection
Anonymous
2026-06-09 03:15:01
(1 day ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 02:34:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.92.148.196 (196.148.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.148.196 (196.148.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 22:34:05.150426 2026] [security2:error] [pid 4026:tid 4026] [client 34.92.148.196:51766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nflelectronics.com.tlambert.us"] [uri "/.git/config"] [unique_id "aid7nUApQAmFPrUNkA2J-wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 00:26:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.92.148.196 (196.148.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.148.196 (196.148.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 20:26:30.730165 2026] [security2:error] [pid 9213:tid 9213] [client 34.92.148.196:53440] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jaykaydrone.pics.krakowski.net"] [uri "/.git/config"] [unique_id "aiddtuSFTh3Qbj9RKC6D5AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
bcsaba
2026-06-08 17:57:16
(1 day ago)
Probing for .git:
34.92.148.196 - - [08/Jun/2026:19:57:14 +0200] "GET /.git/config HTTP/1.1" 403 146 ...
show more
Probing for .git:
34.92.148.196 - - [08/Jun/2026:19:57:14 +0200] "GET /.git/config HTTP/1.1" 403 146 "-" "Mozilla/5.0 (Linux; U; Android 2.2; en-us; SCH-I800 Build/FROYO) AppleWebKit/533.1 (KHTML, like Gecko) Version/4.0 Mobile Safari/533.1"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 15:07:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.148.196 (196.148.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.148.196 (196.148.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 11:07:12.207695 2026] [security2:error] [pid 20844:tid 20844] [client 34.92.148.196:49708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "assembliesofgodinsamoa.org.nomanszone.org"] [uri "/.git/config"] [unique_id "aibaoFEblA9rSbSVkVKRwgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 14:32:40
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.148.196 (196.148.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.148.196 (196.148.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 10:32:34.375663 2026] [security2:error] [pid 9914:tid 9914] [client 34.92.148.196:48062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mail2.shirtzz.com"] [uri "/.git/config"] [unique_id "aibSgmUcMTMe0neTxcP3JwAAAGA"]
show less
Brute-Force
Bad Web Bot
Web App Attack