๐ณ๐ฑ
homeshowdomain.nl
2026-05-23 21:59:41
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-22.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-05-22 22:02:49
(1 week ago)
Auto-ban: >3000 req/min op 2026-05-22
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-22 19:20:25
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 8.228.198.3 (3.198.228.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.198.3 (3.198.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 15:20:12.306688 2026] [security2:error] [pid 17867:tid 17867] [client 8.228.198.3:38856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.germanflatts.mohawk-ny.org"] [uri "/.git/config"] [unique_id "ahCsbGxf5In4wv3Y8eq2ugAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 17:29:09
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 8.228.198.3 (3.198.228.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.198.3 (3.198.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 13:29:01.927092 2026] [security2:error] [pid 25116:tid 25116] [client 8.228.198.3:58408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nicholsonbrosconcrete.com.modeltdr.com"] [uri "/.git/config"] [unique_id "ahCSXWckmXxhzxIwdNyY8QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 12:48:47
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 8.228.198.3 (3.198.228.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.198.3 (3.198.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 08:48:41.859869 2026] [security2:error] [pid 23177:tid 23177] [client 8.228.198.3:47860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "probiopharmaceutical.com"] [uri "/.git/config"] [unique_id "ahBQqQQsD6ZNhfFBFDUysAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 12:31:47
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 8.228.198.3 (3.198.228.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.198.3 (3.198.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 08:31:41.835671 2026] [security2:error] [pid 18952:tid 18952] [client 8.228.198.3:39434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "newcastle91.org"] [uri "/.git/config"] [unique_id "ahBMrS2ohy9hlANv2J9HuAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 09:15:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 8.228.198.3 (3.198.228.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.198.3 (3.198.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 05:14:56.721060 2026] [security2:error] [pid 776:tid 776] [client 8.228.198.3:52074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.puckerbottombikini.com"] [uri "/.git/config"] [unique_id "ahAekLOJEFEZjICJXtUIbAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-22 07:57:47
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 8.228.198.3 (3.198.228.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.198.3 (3.198.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 03:57:42.886774 2026] [security2:error] [pid 10220:tid 10220] [client 8.228.198.3:34010] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.notedstories.com"] [uri "/.git/config"] [unique_id "ahAMdt6S0-f4YLSh_gmPAQAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-05-22 04:54:51
(1 week ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 8.228.198.3 (SA/Saudi Arabia/3.198.22 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 8.228.198.3 (SA/Saudi Arabia/3.198.228.8.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ซ๐ท
masterguru
2026-05-22 00:47:20
(1 week ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 8.228.198.3 (SA/Saudi Arabia/3.198.22 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 8.228.198.3 (SA/Saudi Arabia/3.198.228.8.bc.googleusercontent.com): 1 in the last 3600 secs (0-197)
show less
Hacking