๐ณ๐ฑ
homeshowdomain.nl
2026-01-08 22:59:39
(8 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-01-07.
show less
Hacking
Web App Attack
SSH
๐ฌ๐ง
openstrike.co.uk
2026-01-08 06:13:35
(8 months ago)
4 attacks on VC URLs:
GET /.git/config HTTP/1.1
Hacking
๐ณ๐ฑ
jjnxpct
2026-01-08 04:49:37
(8 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: /.git/config (Rule ID: 930130) - Restricted File Access Attempt [Suspicious: .git/ found within REQUEST_FILENAME: /.git/config]
show less
Hacking
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-01-07 22:59:21
(8 months ago)
Auto-ban: >3000 req/min op 2026-01-07
Hacking
Web App Attack
SSH
๐บ๐ธ
TPI-Abuse
2026-01-07 21:31:55
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 35.189.177.75 (75.177.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.177.75 (75.177.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 07 16:31:48.875511 2026] [security2:error] [pid 9999:tid 9999] [client 35.189.177.75:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vertubet.com"] [uri "/.git/config"] [unique_id "aV7QxPndg_sKjWcRNyFVmAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-01-07 21:16:31
(8 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
Anonymous
2026-01-07 21:05:09
(8 months ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
RCS
2026-01-07 21:04:46
(8 months ago)
fail2ban apache-modsecurity
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-07 21:04:01
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 35.189.177.75 (75.177.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.177.75 (75.177.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 07 16:03:58.622806 2026] [security2:error] [pid 12181:tid 12181] [client 35.189.177.75:51916] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "verification.pazzidipizza.com"] [uri "/.git/config"] [unique_id "aV7KPgYVfDCf1qlWffHjVQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-07 20:28:20
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 35.189.177.75 (75.177.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.177.75 (75.177.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 07 15:28:14.991293 2026] [security2:error] [pid 2227:tid 2227] [client 35.189.177.75:34198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vendor21.com"] [uri "/.git/config"] [unique_id "aV7B3g6m2bJ8xBKyrJQP7wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-07 20:06:18
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 35.189.177.75 (75.177.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.177.75 (75.177.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 07 15:06:10.888703 2026] [security2:error] [pid 9458:tid 9458] [client 35.189.177.75:47804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vekk.z-mgmt.com"] [uri "/.git/config"] [unique_id "aV68skUWxJUu8dPEUUL1egAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-01-07 19:38:53
(8 months ago)
Try to access /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-07 17:04:55
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 35.189.177.75 (75.177.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.177.75 (75.177.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 07 12:04:48.886864 2026] [security2:error] [pid 8546:tid 8546] [client 35.189.177.75:44776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whm.69strains.com"] [uri "/.git/config"] [unique_id "aV6SMM4871zR6LhTEoyGqwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
el-brujo
2026-01-07 17:03:27
(8 months ago)
Cloudflare WAF: Request Path: /.git/config Request Query: Host: whk.elhacker.net userAgent: Action ...
show more
Cloudflare WAF: Request Path: /.git/config Request Query: Host: whk.elhacker.net userAgent: Action: block Source: firewallManaged ASN Description: GOOGLE-CLOUD-PLATFORM Country: TW Method: GET Timestamp: 2026-01-07T17:03:27Z ruleId: 23548ee2b36547a1be09bb2c0550c529. Report generated by Cloudflare-WAF-to-AbuseIPDB (https://github.com/MHG-LAB/Cloudflare-WAF-to-AbuseIPDB).
show less
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-07 16:49:29
(8 months ago)
(mod_security) mod_security (id:210492) triggered by 35.189.177.75 (75.177.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.177.75 (75.177.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jan 07 11:49:24.424935 2026] [security2:error] [pid 32560:tid 32560] [client 35.189.177.75:60948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "whitecranemanagement.com"] [uri "/.git/config"] [unique_id "aV6OlGFuc1ud-LXCNFjbcQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack