π³π±
homeshowdomain.nl
2026-06-09 22:01:08
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-06-09 13:35:07
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.241.106.36 (36.106.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.106.36 (36.106.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 09:35:00.400331 2026] [security2:error] [pid 28453:tid 28453] [client 35.241.106.36:46558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flatontaylor.com"] [uri "/.git/config"] [unique_id "aigWhLwpi_79ZJrEokzpAgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
pltcldvlpr
2026-06-09 11:37:51
(4 days ago)
CMS/framework probe: 35.241.106.36 - - [09/Jun/2026:13:37:51 +0200] "GET /.git/config HTTP/1.1" 301 ...
show more
CMS/framework probe: 35.241.106.36 - - [09/Jun/2026:13:37:51 +0200] "GET /.git/config HTTP/1.1" 301 178 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_14_1) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/62.0.3202.94 Safari/537.36" asn=396982 org="Google LLC" country=HK
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 10:47:57
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.241.106.36 (36.106.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.106.36 (36.106.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 06:47:54.605086 2026] [security2:error] [pid 24436:tid 24436] [client 35.241.106.36:42178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rizkallah.menagri.com"] [uri "/.git/config"] [unique_id "aifvWmlly3_9NiRe2i4hLQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 10:16:26
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.241.106.36 (36.106.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.106.36 (36.106.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 06:16:17.086899 2026] [security2:error] [pid 16872:tid 16872] [client 35.241.106.36:50260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thefiregoddess.net"] [uri "/.git/config"] [unique_id "aifn8aGMPW4QMqioLVgV0wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-06-09 08:01:13
(4 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
π©πͺ
CK_beats
2026-06-09 05:50:01
(4 days ago)
Blocked by os-abuseipdb on OPNsense firewall KN-FW01; 3 hits, proto=tcp, ports=443
Port Scan
Hacking
πΊπΈ
TPI-Abuse
2026-06-09 05:32:06
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.241.106.36 (36.106.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.106.36 (36.106.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 01:31:58.956126 2026] [security2:error] [pid 27953:tid 27953] [client 35.241.106.36:40192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.justiniggercom.indie100.com"] [uri "/.git/config"] [unique_id "aielTkS8Zq6UfvaZ7s7exgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 04:49:27
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.241.106.36 (36.106.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.106.36 (36.106.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 00:49:22.612957 2026] [security2:error] [pid 2424:tid 2424] [client 35.241.106.36:48100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "frenchtowntogether.org"] [uri "/.git/config"] [unique_id "aiebUu21onSMqPYTezWBVgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 04:26:07
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.241.106.36 (36.106.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.106.36 (36.106.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 00:26:03.374845 2026] [security2:error] [pid 6928:tid 6928] [client 35.241.106.36:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globetechsecurities.com"] [uri "/.git/config"] [unique_id "aieV2w64E1qsXbLhz8v_fAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
cwytech
2026-06-09 03:28:23
(4 days ago)
Fleet-wide ban from the Ghostfleet π». Triggered by scenario: cwy/http-honeypath-sniper-crit.
Bad Web Bot
Web App Attack
π©πͺ
strxmpp
2026-06-09 03:04:18
(4 days ago)
35.241.106.36 - - [09/Jun/2026:05:04:18 +0200] "GET /.git/config HTTP/1.1" 404 4554 "-" "Mozilla/5.0 ...
show more
35.241.106.36 - - [09/Jun/2026:05:04:18 +0200] "GET /.git/config HTTP/1.1" 404 4554 "-" "Mozilla/5.0 (Linux; Android 7.1.1; Coolpad 3632A Build/NMF26F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/59.0.3071.125 Mobile Safari/537.36"
...
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-06-09 02:51:31
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.241.106.36 (36.106.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.106.36 (36.106.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 22:51:23.738517 2026] [security2:error] [pid 537:tid 537] [client 35.241.106.36:33012] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "asurprisinglittletown.com"] [uri "/.git/config"] [unique_id "aid_qw9sNX7b7ZPz3_Nx0wAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 00:47:10
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.241.106.36 (36.106.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.106.36 (36.106.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 20:47:04.134023 2026] [security2:error] [pid 15050:tid 15050] [client 35.241.106.36:45958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lionscb.org.ithacalions.com"] [uri "/.git/config"] [unique_id "aidiiOfgAed0dUXJwXpooQAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-06-08 22:04:18
(4 days ago)
Auto-ban: >3000 req/min op 2026-06-08
Web App Attack
SSH
Hacking