🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 02:33:27
(16 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 02:29:22
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.43.199 (199.43.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.43.199 (199.43.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 22:29:16.458371 2026] [security2:error] [pid 8297:tid 8338] [client 104.196.43.199:43386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.davidchapamusic.com"] [uri "/htdocs/.git/config"] [unique_id "apt-fFF0V6dcAmwFugfycgAAAIE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-09-05 02:15:40
(16 hours ago)
AutoBlock: ⚙️ Configuration File Access (Non Decay-Based)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 22:51:35
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.43.199 (199.43.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.43.199 (199.43.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 18:51:31.619989 2026] [security2:error] [pid 19943:tid 19943] [client 104.196.43.199:52260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rotentendales.com"] [uri "/backend/.git/config"] [unique_id "aptLc0X1MZlUn9snw5bJiQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:48:36
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.43.199 (199.43.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.43.199 (199.43.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:48:29.301706 2026] [security2:error] [pid 19306:tid 19306] [client 104.196.43.199:48784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.twtcsl.com"] [uri "/www/.git/config"] [unique_id "aps8rdD2RUDV9CxUkvOaUAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-04 21:03:03
(21 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 20:34:21
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.196.43.199 (199.43.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.43.199 (199.43.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 16:34:14.375941 2026] [security2:error] [pid 9600:tid 9600] [client 104.196.43.199:34678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dodgersboosterclub.com"] [uri "/app/.git/config"] [unique_id "apsrRoFsYfHNv421zsCp1wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-04 19:23:57
(23 hours ago)
cloudlinux2 fail2ban: 2026-09-04 21:18:58,658 fail2ban.actions [1594]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-04 21:18:58,658 fail2ban.actions [1594]: NOTICE [plesk-modsecurity] Unban 34.89.172.92cloudlinux2 fail2ban: 2026-09-04 21:19:34,215 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 193.56.116.66 - 2026-09-04 21:19:33cloudlinux2 fail2ban: 2026-09-04 21:21:04,983 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 193.56.116.80 - 2026-09-04 21:21:04cloudlinux2 fail2ban: 2026-09-04 21:21:01,067 fail2ban.filter [1594]: INFO [plesk-wordpress] Found 193.56.116.80 - 2026-09-04 21:21:00cloudlinux2 fail2ban: 2026-09-04 21:21:09,909 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 104.196.43.199 - 2026-09-04 21:21:09cloudlinux2 fail2ban: 2026-09-04 21:21:10,004 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 104.196.43.199 - 2026-09-04 21:21:10cloudlinux2 fail2ban: 2026-09-04 21:21:09,945 fail2ban.filter [1594]: INFO [plesk-modsecurity] Found 104.196.43.199 - 2026-09-04 21:21:09cloudlinux2 fail2ban:
show less
Web App Attack
Anonymous
2026-09-04 19:15:05
(23 hours ago)
suspicious request in access.log
Web App Attack
🇲🇽
Leonor
2026-09-04 16:22:00
(1 day ago)
Wordpress attack, Port 80 "GET /wordpress/.git/config HTTP/1.1" 301 650 "-" "crusader-worker/1.0"
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:47:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.196.43.199 (199.43.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.43.199 (199.43.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:47:40.691672 2026] [security2:error] [pid 22288:tid 22357] [client 104.196.43.199:39562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dpiazza.com"] [uri "/html/.git/config"] [unique_id "aproHOrYmpX3tlK6b6yA2wAAAYg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 13:02:47
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇸🇪
vaia.cloud
2026-09-04 09:35:01
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 08:35:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.196.43.199 (199.43.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.43.199 (199.43.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 04:35:27.813648 2026] [security2:error] [pid 31990:tid 31990] [client 104.196.43.199:50036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ulrike-petri.vjrott.com"] [uri "/backend/.git/config"] [unique_id "apqCzyXxrnhjTA_69fMk-AAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 03:49:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.196.43.199 (199.43.196.104.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 104.196.43.199 (199.43.196.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:49:10.444285 2026] [security2:error] [pid 2269:tid 2269] [client 104.196.43.199:43168] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "method-one.net.method1.net"] [uri "/htdocs/.git/config"] [unique_id "apo_tgh0qVBoHrqrueWm9gAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack