๐ณ๐ฑ
homeshowdomain.nl
2026-06-10 22:00:37
(21 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-09.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 13:51:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.222.108 (108.222.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.222.108 (108.222.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 09:51:14.980966 2026] [security2:error] [pid 25460:tid 25460] [client 34.92.222.108:37408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web237.dnchosting.com"] [uri "/.git/config"] [unique_id "aigaUjX_eyEuxCgPUjrBGgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 12:10:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.222.108 (108.222.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.222.108 (108.222.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 08:10:06.570720 2026] [security2:error] [pid 16777:tid 16777] [client 34.92.222.108:56688] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.scc1.us"] [uri "/.git/config"] [unique_id "aigCnr63tHMhUJ8nucjk2gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 10:54:59
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.222.108 (108.222.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.222.108 (108.222.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 06:54:56.059358 2026] [security2:error] [pid 3081:tid 3081] [client 34.92.222.108:59362] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.venture-consulting.com"] [uri "/.git/config"] [unique_id "aifxAPON8MzaW9bN2QLlVwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 08:40:15
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.222.108 (108.222.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.222.108 (108.222.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 04:40:10.522033 2026] [security2:error] [pid 18077:tid 18077] [client 34.92.222.108:38502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.londongroup.info"] [uri "/.git/config"] [unique_id "aifRakkt6qa7QKXJjNVETwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-09 06:26:47
(2 days ago)
[TueJun0908:26:44.5775182026][security2:error][pid2474902:tid2474914][client34.92.222.108:0]ModSecur ...
show more
[TueJun0908:26:44.5775182026][security2:error][pid2474902:tid2474914][client34.92.222.108:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"robertselitrenny.ch.136-243-54-122.cpanel.site\"][uri\"/.git/config\"][unique_id\"aieyJBkRQMNNw09FY10dtAAAAAE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ณ๐ฑ
ipoac.nl
2026-06-09 06:22:24
(2 days ago)
-:443 34.92.222.108 - - [09/Jun/2026:08:22:23 +0200] - "GET /.git/config HTTP/1.1" 403 5441 "-" "Moz ...
show more
-:443 34.92.222.108 - - [09/Jun/2026:08:22:23 +0200] - "GET /.git/config HTTP/1.1" 403 5441 "-" "Mozilla/5.0 (Linux; Android 8.0.0; XT1650) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/74.0.3729.157 Mobile Safari/537.36"
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-09 05:57:14
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.222.108 (108.222.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.222.108 (108.222.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 01:57:06.863812 2026] [security2:error] [pid 26008:tid 26031] [client 34.92.222.108:59876] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.eldebslaw.com.oplconnect.com"] [uri "/.git/config"] [unique_id "aierMnqILviD51uzcP3xHgAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-06-09 05:41:22
(2 days ago)
34.92.222.108 - - [09/Jun/2026:07:41:21 +0200] "GET /.git/config HTTP/1.1" 403 4975 "-" "Opera/9.80 ...
show more
34.92.222.108 - - [09/Jun/2026:07:41:21 +0200] "GET /.git/config HTTP/1.1" 403 4975 "-" "Opera/9.80 (Macintosh; Intel Mac OS X; U; en) Presto/2.6.30 Version/10.61"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 05:07:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.222.108 (108.222.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.222.108 (108.222.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 01:07:34.088097 2026] [security2:error] [pid 23534:tid 23534] [client 34.92.222.108:54608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "staging.indyrheumatology.com"] [uri "/.git/config"] [unique_id "aieflsCnIWZKMVFDdYOlRQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 03:55:28
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.222.108 (108.222.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.222.108 (108.222.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 23:55:21.938536 2026] [security2:error] [pid 13468:tid 13468] [client 34.92.222.108:47794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jacobyonline.com"] [uri "/.git/config"] [unique_id "aieOqdY_x8BVaYt3kw6jdAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 03:26:58
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.222.108 (108.222.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.222.108 (108.222.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 23:26:52.558406 2026] [security2:error] [pid 988:tid 988] [client 34.92.222.108:41774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "churchtop.com"] [uri "/.git/config"] [unique_id "aieH_K-sKXOe-Xc5AsMpbwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-06-09 03:03:12
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 00:31:41
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.222.108 (108.222.92.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.222.108 (108.222.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 20:31:34.287143 2026] [security2:error] [pid 16931:tid 16931] [client 34.92.222.108:38104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "baliaccommodationpadangpadang.com"] [uri "/.git/config"] [unique_id "aide5mmWuJjCGJWN21vmeQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Dominik Lysiak
2026-06-08 23:36:35
(2 days ago)
34.92.222.108 - - [09/Jun/2026:01:36:34 +0200] "GET /.env.docker HTTP/1.1" 404 178 "-" "Mozilla/5.0 ...
show more
34.92.222.108 - - [09/Jun/2026:01:36:34 +0200] "GET /.env.docker HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Windows NT 6.1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.100 Safari/537.36"
34.92.222.108 - - [09/Jun/2026:01:36:34 +0200] "GET /.env.uat HTTP/1.1" 404 146 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 10_0 like Mac OS X) AppleWebKit/602.1.50 (KHTML, like Gecko) Version/10.0 Mobile/14A346 Safari/602.1"
34.92.222.108 - - [09/Jun/2026:01:36:35 +0200] "GET /.env.development HTTP/1.1" 404 178 "-" "Mozilla/5.0 (Linux; Android 9; Pixel) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36"
...
show less
Web App Attack