🇳🇱
homeshowdomain.nl
2026-09-11 22:01:11
(1 hour ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-10.
show less
Web App Attack
SSH
Hacking
🇺🇸
WizardsToolkit
2026-09-11 20:16:24
(2 hours ago)
tried to access forbidden files; attempted to access /app/.env
Web App Attack
🇺🇸
Major Hostility
2026-09-11 19:27:56
(3 hours ago)
"GET /.git/config HTTP/1.1" 404
"GET /.git/.env HTTP/1.1" 404
Web App Attack
Anonymous
2026-09-11 19:21:51
(3 hours ago)
[Fri Sep 11 21:21:49.545082 2026] [proxy_fcgi:error] [pid 66340:tid 66472] [client 34.95.247.156:375 ...
show more
[Fri Sep 11 21:21:49.545082 2026] [proxy_fcgi:error] [pid 66340:tid 66472] [client 34.95.247.156:37546] AH01071: Got error 'Primary script unknown'
[Fri Sep 11 21:21:49.788717 2026] [proxy_fcgi:error] [pid 66340:tid 66503] [client 34.95.247.156:37546] AH01071: Got error 'Primary script unknown'
[Fri Sep 11 21:21:50.011037 2026] [proxy_fcgi:error] [pid 66340:tid 66462] [client 34.95.247.156:37546] AH01071: Got error 'Primary script unknown'
[Fri Sep 11 21:21:50.257279 2026] [proxy_fcgi:error] [pid 66340:tid 66498] [client 34.95.247.156:37546] AH01071: Got error 'Primary script unknown'
[Fri Sep 11 21:21:50.527676 2026] [proxy_fcgi:error] [pid 66340:tid 66458] [client 34.95.247.156:37546] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
🇿🇦
conure.sh
2026-09-11 12:08:33
(11 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 2s
Web App Attack
🇫🇮
YF
2026-09-11 12:00:30
(11 hours ago)
Distributed subnet attack — coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
Anonymous
2026-09-11 11:54:31
(11 hours ago)
Banned by Fail2Ban on server
Web App Attack
🇧🇪
cmbplf
2026-09-11 09:05:14
(14 hours ago)
13.958 requests in 1 hour (3mos1w6d)
Brute-Force
Bad Web Bot
🇩🇪
big-cloud.nl
2026-09-11 08:46:49
(14 hours ago)
Try to access /.git/config
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 07:31:40
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.247.156 (156.247.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.247.156 (156.247.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 03:31:34.890718 2026] [security2:error] [pid 31128:tid 31128] [client 34.95.247.156:41040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.armstrongpartnersllc.com.ssl-grp.com"] [uri "/.git/config"] [unique_id "aqOuVn9TDOv0dA25-4qXWwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 06:56:37
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.247.156 (156.247.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.247.156 (156.247.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 02:56:31.423027 2026] [security2:error] [pid 9261:tid 9261] [client 34.95.247.156:47820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.armorcorp.gulftelecom.com"] [uri "/.git/config"] [unique_id "aqOmH1gfPG8IQWAfAmmskgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 05:53:26
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.247.156 (156.247.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.247.156 (156.247.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 01:53:23.255577 2026] [security2:error] [pid 9289:tid 9289] [client 34.95.247.156:51620] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.armchairdevotional.shepherdsgroup.com"] [uri "/.git/config"] [unique_id "aqOXU9HZjSULwjuLkEeoGwAAADY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 03:40:12
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.95.247.156 (156.247.95.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.95.247.156 (156.247.95.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 23:40:04.823081 2026] [security2:error] [pid 30494:tid 30494] [client 34.95.247.156:40492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.arkqp.kreweofhyatt.com"] [uri "/.git/config"] [unique_id "aqN4FMC4J8d8z8SKKOquMAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-11 03:31:12
(19 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇩🇪
Hazzard
2026-09-11 02:05:32
(21 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection