๐ณ๐ฑ
homeshowdomain.nl
2026-06-10 21:59:50
(1 month ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-09.
show less
Web App Attack
SSH
Hacking
๐ฉ๐ช
4server
2026-06-09 15:16:09
(1 month ago)
[TueJun0917:16:05.9970312026][security2:error][pid3110916:tid3110959][client34.182.236.4:0]ModSecuri ...
show more
[TueJun0917:16:05.9970312026][security2:error][pid3110916:tid3110959][client34.182.236.4:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:10\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.9\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"feldenkraistherapy.ch\"][uri\"/.git/config\"][unique_id\"aiguNXcWKAFTfbbUtLuenQAAAAc\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ฐ
RhQM
2026-06-09 13:51:04
(1 month ago)
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 12:14:15
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.182.236.4 (4.236.182.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.236.4 (4.236.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 08:14:11.809041 2026] [security2:error] [pid 31929:tid 31929] [client 34.182.236.4:56424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.molder.com.hk"] [uri "/.git/config"] [unique_id "aigDkxVJ6lZXkofex1GJ6gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-06-09 11:20:16
(1 month ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 11:06:09
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.182.236.4 (4.236.182.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.236.4 (4.236.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 07:06:02.426948 2026] [security2:error] [pid 5383:tid 5383] [client 34.182.236.4:56878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.dougrhodes.com.inspiraciongaleria.com"] [uri "/.git/config"] [unique_id "aifzmnInXSSBvJwjRGCXmgAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 10:27:22
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.182.236.4 (4.236.182.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.236.4 (4.236.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 06:27:17.616142 2026] [security2:error] [pid 26822:tid 26845] [client 34.182.236.4:52134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "frmoto.com"] [uri "/.git/config"] [unique_id "aifqhVV_bmoQsqgvjwCXLgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-06-09 07:08:38
(1 month ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.182.236.4 (US/United States/4.23 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 34.182.236.4 (US/United States/4.236.182.34.bc.googleusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 06:09:04
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.182.236.4 (4.236.182.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.236.4 (4.236.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 02:08:56.845250 2026] [security2:error] [pid 20401:tid 20401] [client 34.182.236.4:57096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pulsepowermeter.rotarymagnetics.com"] [uri "/.git/config"] [unique_id "aiet-NS2I-cuuUiK_2VJSgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Kreapptivo
2026-06-09 05:15:05
(1 month ago)
[09/Jun/2026:07:15:01 +0200] Web-Request: "GET /.git/config", User-Agent: "Mozilla/5.0 (compatible; ...
show more
[09/Jun/2026:07:15:01 +0200] Web-Request: "GET /.git/config", User-Agent: "Mozilla/5.0 (compatible; Konqueror/4.5; FreeBSD) KHTML/4.5.4 (like Gecko)"
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
simsung
2026-06-09 03:55:47
(1 month ago)
34.182.236.4 - - [09/Jun/2026:03:55:46 +0000] "GET /.git/config HTTP/1.1" 403 177 "-" "Mozilla/5.0 ( ...
show more
34.182.236.4 - - [09/Jun/2026:03:55:46 +0000] "GET /.git/config HTTP/1.1" 403 177 "-" "Mozilla/5.0 (Windows NT 10.0; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/57.0.2987.133 AOL/11.0 AOLBUILD/11.0.1305 Safari/537.36"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-09 03:48:47
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.182.236.4 (4.236.182.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.236.4 (4.236.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 23:48:44.013133 2026] [security2:error] [pid 30063:tid 30063] [client 34.182.236.4:47078] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "genesis-one.com"] [uri "/.git/config"] [unique_id "aieNHIlNxUclxUOybsYDAAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 03:00:46
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.182.236.4 (4.236.182.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.236.4 (4.236.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 23:00:39.578256 2026] [security2:error] [pid 15491:tid 15491] [client 34.182.236.4:45018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.desertshadowsrv.org"] [uri "/.git/config"] [unique_id "aieB14u2HiX3a4MtKwlSnwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 01:05:19
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 34.182.236.4 (4.236.182.34.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 34.182.236.4 (4.236.182.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 21:05:15.884494 2026] [security2:error] [pid 8942:tid 8967] [client 34.182.236.4:43058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.florida-plastic-surgery.aafm.us"] [uri "/.git/config"] [unique_id "aidmy6XsKpmIBopi0l7NdQAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-08 22:05:15
(1 month ago)
Auto-ban: >3000 req/min op 2026-06-08
Web App Attack
SSH
Hacking