๐บ๐ธ
TPI-Abuse
2026-09-22 16:11:26
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.198.89.39 (39.89.198.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.89.39 (39.89.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:11:21.521863 2026] [security2:error] [pid 15812:tid 15900] [client 104.198.89.39:37898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.el-designers.com.oplconnect.com"] [uri "/.git/config"] [unique_id "arKoqVYZ76xF58oh2QW1MQAAAkI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-22 14:10:33
(9 hours ago)
Excessive multi-domain requests
Brute-Force
๐ธ๐ช
vaia.cloud
2026-09-22 13:35:02
(10 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
Anonymous
2026-09-22 12:41:33
(11 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-09-22 11:01:09
(12 hours ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.git/config | 2026-09-22 11:01 UTC
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-09-22 10:21:55
(13 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 07:50:59
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.198.89.39 (39.89.198.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.89.39 (39.89.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 03:50:54.212945 2026] [security2:error] [pid 13635:tid 13635] [client 104.198.89.39:60898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.en.coveyhillenterprises.com"] [uri "/.git/config"] [unique_id "arIzXpcBa1tnfaOuWURJzQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-21 22:01:48
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-21
Web App Attack
SSH
Hacking
Anonymous
2026-09-21 21:48:45
(1 day ago)
[server.tmg.gr] httpd-config-scan: sites=www.eemi.gr; logs=/var/log/httpd/domains/eemi.gr.log; sampl ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.eemi.gr; logs=/var/log/httpd/domains/eemi.gr.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 16:29:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 104.198.89.39 (39.89.198.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.89.39 (39.89.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:29:36.120948 2026] [security2:error] [pid 19704:tid 19704] [client 104.198.89.39:60738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.edwinrphotography.grayhost.net"] [uri "/.git/config"] [unique_id "arFbcIdSfjTDFFW6WLOv_wAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 07:47:45
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 18:58:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 104.198.89.39 (39.89.198.104.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 104.198.89.39 (39.89.198.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 14:58:32.634181 2026] [security2:error] [pid 20961:tid 20967] [client 104.198.89.39:59212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ioqm.aafm.us"] [uri "/.git/config"] [unique_id "arAs2IrWZ5CnQ6_3hcfKrwAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-20 18:51:24
(2 days ago)
104.198.89.39 - - [20/Sep/2026:18:51:12 +0000] "GET /.env HTTP/1.1" 403 7448 "-" "Mozilla/5.0 (X11; ...
show more
104.198.89.39 - - [20/Sep/2026:18:51:12 +0000] "GET /.env HTTP/1.1" 403 7448 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="104.198.89.39"
104.198.89.39 - - [20/Sep/2026:18:51:14 +0000] "GET /.env.local HTTP/1.1" 403 7448 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="104.198.89.39"
104.198.89.39 - - [20/Sep/2026:18:51:14 +0000] "GET /.env.production HTTP/1.1" 403 7448 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="104.198.89.39"
104.198.89.39 - - [20/Sep/2026:18:51:15 +0000] "GET /.env.staging HTTP/1.1" 403 7448 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="104.198.89.39"
104.198.89.39 - - [20/Sep/2026:18:51:16 +0000] "GET /.env.development HTTP/1.1" 403 7448 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebK
...
show less
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 18:00:07
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack