๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:00:50
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 16:15:47
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.97.29.148 (148.29.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.29.148 (148.29.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 12:15:40.883803 2026] [security2:error] [pid 19159:tid 19159] [client 34.97.29.148:60392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.eileensinc.cathrynn.com"] [uri "/.git/config"] [unique_id "aig8LMW7IQ0BPYwBl3u56gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 13:55:38
(1 week ago)
34.97.29.148 - - [09/Jun/2026:21:55:38 +0800] "GET /.git/config HTTP/1.1" 301 - "-" "Mozilla/5.0 (Wi ...
show more
34.97.29.148 - - [09/Jun/2026:21:55:38 +0800] "GET /.git/config HTTP/1.1" 301 - "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3786.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 11:43:22
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.97.29.148 (148.29.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.29.148 (148.29.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 07:43:15.731109 2026] [security2:error] [pid 10750:tid 10750] [client 34.97.29.148:44790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "allisonokon.com"] [uri "/.git/config"] [unique_id "aif8U4kLw4UgAnp5tpRilwAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 09:54:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.97.29.148 (148.29.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.29.148 (148.29.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 05:54:25.262852 2026] [security2:error] [pid 21481:tid 21481] [client 34.97.29.148:39272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.saratogaequity.com.martintommer.com"] [uri "/.git/config"] [unique_id "aifi0UCVM0E8HMCBYKdxqQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-06-09 09:18:57
(1 week ago)
[TueJun0911:18:51.6102072026][security2:error][pid358312:tid360063][client34.97.29.148:0]ModSecurity ...
show more
[TueJun0911:18:51.6102072026][security2:error][pid358312:tid360063][client34.97.29.148:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"walter-worndli.ch\"][uri\"/.git/config\"][unique_id\"aifae7M3jJzdCmfWS42g-wAAAIg\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-06-09 08:44:34
(1 week ago)
Try to access /.git/config
Web App Attack
๐ฉ๐ช
Progetto1
2026-06-09 05:29:01
(1 week ago)
Detected via HAProxyScanner at 2026-06-09 05:29:01 UTC on destination port WEB (80/443). Repeated sc ...
show more
Detected via HAProxyScanner at 2026-06-09 05:29:01 UTC on destination port WEB (80/443). Repeated scan / connection.
show less
Port Scan
Hacking
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-09 03:08:42
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.97.29.148 (148.29.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.29.148 (148.29.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 23:08:36.457378 2026] [security2:error] [pid 14172:tid 14172] [client 34.97.29.148:36598] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "contiautos.com"] [uri "/.git/config"] [unique_id "aieDtNNwuhEW8v7gY8VxrAAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 02:01:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.97.29.148 (148.29.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.29.148 (148.29.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 22:01:23.241230 2026] [security2:error] [pid 13800:tid 13800] [client 34.97.29.148:44534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.versahealthcare.versacardio.com"] [uri "/.git/config"] [unique_id "aidz8wUvUpFwdHItqfLdZgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 01:19:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.97.29.148 (148.29.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.29.148 (148.29.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 21:19:07.974058 2026] [security2:error] [pid 6053:tid 6053] [client 34.97.29.148:44340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidnevue.com"] [uri "/.git/config"] [unique_id "aidqC6bm1aEHt2qQN8xrYAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-06-09 00:56:00
(1 week ago)
Scraping with a high error ratio and request rate Requests to unauthorized or suspicious endpoints ( ...
show more
Scraping with a high error ratio and request rate Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
show less
Bad Web Bot
๐ฉ๐ช
Roper123
2026-06-08 19:45:32
(1 week ago)
Web exploits
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 18:59:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 34.97.29.148 (148.29.97.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.97.29.148 (148.29.97.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 14:59:42.753635 2026] [security2:error] [pid 1443:tid 1443] [client 34.97.29.148:41736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tpskc.teleplussolutions.com"] [uri "/.git/config"] [unique_id "aicRHkwP2VhrvfzhtLEuOQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
sefinek.net
2026-06-08 18:40:44
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from JP.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoi ...
show more
Triggered Cloudflare WAF (firewallCustom) from JP.
Action: BLOCK | Protocol: HTTP/1.1 (GET) | Endpoint: /.git/config | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_10_2) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.82 Safari/537.36 OPR/29.0.1795.41 โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot