๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:01:04
(5 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
๐ฎ๐ฉ
Burayot
2026-06-09 16:29:31
(5 days ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.92.49.196 (HK/Hong Kong/196.49.9 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.92.49.196 (HK/Hong Kong/196.49.92.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 13:42:34
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.49.196 (196.49.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.49.196 (196.49.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 09:42:29.892892 2026] [security2:error] [pid 16142:tid 16142] [client 34.92.49.196:47444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.giganticmediallc.com"] [uri "/.git/config"] [unique_id "aigYRcff32zUU8fliKF1wwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 13:24:52
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.49.196 (196.49.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.49.196 (196.49.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 09:24:46.657160 2026] [security2:error] [pid 8152:tid 8152] [client 34.92.49.196:34434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.danielbrower.circleofsound.org"] [uri "/.git/config"] [unique_id "aigUHsHNFBgxrjowTCX4bwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
piticu iuli
2026-06-09 12:18:56
(5 days ago)
(mod_security) mod_security triggered on hostname [redacted] 34.92.49.196 (HK/Hong Kong/196.49.92.34 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 34.92.49.196 (HK/Hong Kong/196.49.92.34.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-06-09 12:10:28
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.49.196 (196.49.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.49.196 (196.49.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 08:10:21.425861 2026] [security2:error] [pid 6753:tid 6753] [client 34.92.49.196:51856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aprilparks.boaredraven.com"] [uri "/.git/config"] [unique_id "aigCrWdshWc_eA3410Vr_wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 11:35:10
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.49.196 (196.49.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.49.196 (196.49.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 07:35:04.882412 2026] [security2:error] [pid 8775:tid 8775] [client 34.92.49.196:58662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lightedpath.com"] [uri "/.git/config"] [unique_id "aif6aB3LVn75KVAG0qTzpgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 10:51:54
(5 days ago)
34.92.49.196 - - [09/Jun/2026:12:51:53 +0200] "GET /.git/config HTTP/1.1" 301 169 "-" "Mozilla/5.0 ( ...
show more
34.92.49.196 - - [09/Jun/2026:12:51:53 +0200] "GET /.git/config HTTP/1.1" 301 169 "-" "Mozilla/5.0 (Linux; Android 9; SM-G960W) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 10:12:46
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.49.196 (196.49.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.49.196 (196.49.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 06:12:40.112788 2026] [security2:error] [pid 27646:tid 27646] [client 34.92.49.196:56540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.switkoprofiri.org.gabver.com"] [uri "/.git/config"] [unique_id "aifnGN82-laXvcBWQs--aQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-06-09 09:22:12
(5 days ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/http-honeypath-sniper-crit.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 08:24:28
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.49.196 (196.49.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.49.196 (196.49.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 04:24:25.234093 2026] [security2:error] [pid 5836:tid 5836] [client 34.92.49.196:54532] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.greatwesternfirearms.deubellzebub.com"] [uri "/.git/config"] [unique_id "aifNuSY2KJ6mAqxlxdo-fAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 06:58:15
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.49.196 (196.49.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.49.196 (196.49.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 02:58:09.443215 2026] [security2:error] [pid 15066:tid 15066] [client 34.92.49.196:51062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ai.panmaneecnc.com"] [uri "/.git/config"] [unique_id "aie5gc_1xC9jAA8seoBDdgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-06-09 06:40:26
(5 days ago)
34.92.49.196 - - [09/Jun/2026:00:40:26 -0600] "GET /.git/config HTTP/1.1" 301 7257 "-" "Mozilla/5.0 ...
show more
34.92.49.196 - - [09/Jun/2026:00:40:26 -0600] "GET /.git/config HTTP/1.1" 301 7257 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Ubuntu Chromium/73.0.3683.86 Chrome/73.0.3683.86 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 05:26:01
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 34.92.49.196 (196.49.92.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.92.49.196 (196.49.92.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 01:25:57.939012 2026] [security2:error] [pid 16852:tid 16852] [client 34.92.49.196:34406] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "feministvoice.blog"] [uri "/.git/config"] [unique_id "aiej5X8SmPgQA8bQ9bYOZwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-06-09 03:35:39
(5 days ago)
Scraping with a high error ratio and request rate
Bad Web Bot