π³π±
homeshowdomain.nl
2026-06-27 22:02:16
(22 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-26.
show less
Web App Attack
SSH
Hacking
π§πͺ
cmbplf
2026-06-26 02:42:42
(2 days ago)
1.031 requests with url.path */.git/config
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-06-26 01:57:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.49.2 (2.49.234.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.49.2 (2.49.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 21:56:56.032811 2026] [security2:error] [pid 22934:tid 22934] [client 35.234.49.2:51384] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cynthiabaxter.com"] [uri "/symfony/.git/config"] [unique_id "aj3caFJLg2mPspWDneEWSQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
pipeline.es
2026-06-26 00:47:08
(2 days ago)
Port scanning / recon | Evidence: date=2026-06-26 time=02:46:57 devname="[redacted]" devid="[redacte ...
show more
Port scanning / recon | Evidence: date=2026-06-26 time=02:46:57 devname="[redacted]" devid="[redacted]" eventtime=1782434817731341810 tz=\"+0200\" logid=\"0000000013\" type=\"traffic\" subtype=\"forward\" level=\"notice\" vd="[redacted]" srcip=35.234.49.2 srcport=34232 srcintf="[redacted]" srcintfrole=\"wan\" dstip=[redacted] dstport=443 dstintf="[redacted]" dstintfrole=\"lan\" srccountry=\"Taiwan\" dstcountry=\"Spain\" sessionid= | ASN: GOOGLE-CLOUD-PLATFORM | Country: TW
show less
Port Scan
Web App Attack
πΊπΈ
CBJ
2026-06-26 00:23:24
(2 days ago)
fail2ban: apache-filepath-recon
...
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-25 23:04:24
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.49.2 (2.49.234.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.49.2 (2.49.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 19:04:21.029126 2026] [security2:error] [pid 28130:tid 28130] [client 35.234.49.2:48014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.openmolecules.org"] [uri "/symfony/.git/config"] [unique_id "aj2z9WwBoH3sE0r3P1WFogAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-25 22:39:24
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.49.2 (2.49.234.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.49.2 (2.49.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 25 18:39:18.110750 2026] [security2:error] [pid 8813:tid 8862] [client 35.234.49.2:35816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "interludes.info"] [uri "/code/.git/config"] [unique_id "aj2uFuzfj8kCYpkAUDed5wAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-06-25 15:17:12
(3 days ago)
20 attempts against mh-misbehave-ban on staging
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-06-25 14:57:33
(3 days ago)
30 attempts against mh-misbehave-ban on wheat
Brute-Force
Bad Web Bot
Web App Attack