🇺🇸
TPI-Abuse
2026-09-06 07:46:41
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.225.119 (119.225.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.225.119 (119.225.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 03:46:33.847682 2026] [security2:error] [pid 5463:tid 5463] [client 104.199.225.119:50128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dodgersboosterclub.com"] [uri "/backend/.git/config"] [unique_id "ap0aWamiwXpzTn2zwjGY0AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-06 05:55:31
(7 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 01:56:37
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.225.119 (119.225.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.225.119 (119.225.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 21:56:33.689232 2026] [security2:error] [pid 13299:tid 13299] [client 104.199.225.119:43268] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thebumans.com"] [uri "/src/.git/config"] [unique_id "apzIUeUiKt0EHwdDUfuEKgAAAHo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-06 01:50:16
(11 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-06 01:46:33
(11 hours ago)
104.199.225.119 - - [06/Sep/2026:03:46:31 +0200] "GET /www/.git/config HTTP/1.1" 404 4441 "-" "crusa ...
show more
104.199.225.119 - - [06/Sep/2026:03:46:31 +0200] "GET /www/.git/config HTTP/1.1" 404 4441 "-" "crusader-worker/1.0"
104.199.225.119 - - [06/Sep/2026:03:46:31 +0200] "GET /htdocs/.git/config HTTP/1.1" 404 4441 "-" "crusader-worker/1.0"
104.199.225.119 - - [06/Sep/2026:03:46:31 +0200] "GET /api/.git/config HTTP/1.1" 404 4439 "-" "crusader-worker/1.0"
104.199.225.119 - - [06/Sep/2026:03:46:31 +0200] "GET /site/.git/config HTTP/1.1" 404 4439 "-" "crusader-worker/1.0"
104.199.225.119 - - [06/Sep/2026:03:46:31 +0200] "GET /.git/config HTTP/1.1" 403 4444 "-" "crusader-worker/1.0"
104.199.225.119 - - [06/Sep/2026:03:46:31 +0200] "GET /public/.git/config HTTP/1.1" 404 4441 "-" "crusader-worker/1.0"
104.199.225.119 - - [06/Sep/2026:03:46:31 +0200] "GET /wordpress/.git/config HTTP/1.1" 404 4439 "-" "crusader-worker/1.0"
104.199.225.119 - - [06/Sep/2026:03:46:31 +0200] "GET /src/.git/config HTTP/1.1" 404 4439 "-" "crusader-worker/1.0"
104.199.225.119 - - [06/Sep/2026:03:46:31 +0200] "GET /backend/
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 22:24:26
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 104.199.225.119 (119.225.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 104.199.225.119 (119.225.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:24:19.365285 2026] [security2:error] [pid 5818:tid 5818] [client 104.199.225.119:41788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.fwa51.com"] [uri "/src/.git/config"] [unique_id "apyWk_LDA_GStBv_m3CD-gAAAFQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-05 21:59:30
(15 hours ago)
Auto-ban: >3000 req/min op 2026-09-05
Web App Attack
SSH
Hacking
🇺🇸
IndigoRidge
2026-09-05 21:02:50
(16 hours ago)
[05/Sep/2026:17:02:50.660250 --0400] apyDelFc9-QZ6xBIBn8cwgAAAVM 104.199.225.119 34030 205.233.18.17 ...
show more
[05/Sep/2026:17:02:50.660250 --0400] apyDelFc9-QZ6xBIBn8cwgAAAVM 104.199.225.119 34030 205.233.18.17 7080
[05/Sep/2026:17:02:50.661967 --0400] apyDeipoDWFq8ni5eHprKwAAANU 104.199.225.119 34044 205.233.18.17 7080
[05/Sep/2026:17:02:50.665525 --0400] apyDemOnqmDwaCdcQ@XYFQAAAYk 104.199.225.119 34056 205.233.18.17 7080
[05/Sep/2026:17:02:50.675196 --0400] apyDelFc9-QZ6xBIBn8cwwAAAVA 104.199.225.119 34070 205.233.18.17 7080
[05/Sep/2026:17:02:50.675706 --0400] apyDelFc9-QZ6xBIBn8cxAAAAVA 104.199.225.119 34078 205.233.18.17 7080
...
show less
Hacking
🇩🇪
arnisolutions
2026-09-05 11:56:36
(1 day ago)
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production s ...
show more
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production server. Observed on 1 day(s) between 2026-09-05 and 2026-09-05 (UTC). Sample request: GET /htdocs/.git/config HTTP/1.1
show less
Web App Attack
Hacking
🇫🇷
dynamix
2026-09-05 11:04:34
(1 day ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-04 11:06:37
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack