๐บ๐ธ
TPI-Abuse
2026-09-24 04:28:44
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 104.199.198.185 (185.198.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.198.185 (185.198.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:28:40.322668 2026] [security2:error] [pid 24961:tid 24961] [client 104.199.198.185:39486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crearetest.com"] [uri "/htdocs/.git/config"] [unique_id "arSm-JTjNYrMGmziOod58wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 02:37:42
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.198.185 (185.198.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.198.185 (185.198.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:37:34.726495 2026] [security2:error] [pid 3349907:tid 3349907] [client 104.199.198.185:38994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.sinsky.net"] [uri "/wordpress/.git/config"] [unique_id "arSM7oDUiqVduIGDGHgs4wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-24 00:55:05
(5 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-24 00:42:50
(5 hours ago)
[ti-07al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 104.199.198.185 - - [24/Sep/2026:02:42:48 +0200] "GET /public/.git/config HTTP/1.1" 302 5798 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 00:35:59
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.198.185 (185.198.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.198.185 (185.198.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:35:52.619522 2026] [security2:error] [pid 15202:tid 15202] [client 104.199.198.185:43662] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.iconbizpromo.com"] [uri "/backend/.git/config"] [unique_id "arRwaErbO42eZby81xt4owAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 23:08:47
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.198.185 (185.198.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.198.185 (185.198.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 19:08:41.759170 2026] [security2:error] [pid 27562:tid 27562] [client 104.199.198.185:36100] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "constructionloansfunding.com"] [uri "/public/.git/config"] [unique_id "arRb-UjaWZ-sv0kd1a95MAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-09-23 22:33:17
(7 hours ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 104.199.19 ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 104.199.198.185 (TW/Taiwan/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 104.199.198.185 (TW/Taiwan/185.198.199.104.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 22:32:57
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.198.185 (185.198.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.198.185 (185.198.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 18:32:49.547506 2026] [security2:error] [pid 21949:tid 21949] [client 104.199.198.185:52444] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "committeeonstates.progressivefileshare.org"] [uri "/public/.git/config"] [unique_id "arRTkbwJuY2uB4EFXBd7QAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-23 22:13:44
(7 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:42:07
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.198.185 (185.198.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.198.185 (185.198.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:41:59.570506 2026] [security2:error] [pid 8502:tid 8502] [client 104.199.198.185:43646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chico2000.com"] [uri "/.git/config"] [unique_id "arQrh1Ul1SJmM5xYyuqkuAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-23 19:16:22
(10 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-23 18:05:41
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.198.185 (185.198.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.198.185 (185.198.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:05:37.503867 2026] [security2:error] [pid 1685:tid 1685] [client 104.199.198.185:42524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cc.austinbiblestudents.org"] [uri "/wordpress/.git/config"] [unique_id "arQU8drHUO7krJk6gHf-lAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-23 17:36:09
(12 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-23 15:09:25
(14 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 14:48:05
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.198.185 (185.198.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.198.185 (185.198.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 10:47:59.567643 2026] [security2:error] [pid 27362:tid 27362] [client 104.199.198.185:58834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brbvip.com"] [uri "/www/.git/config"] [unique_id "arPmn6_ocenjtEEZhDhspQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack