🇺🇸
TPI-Abuse
2026-09-04 21:28:39
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 34.150.35.225 (225.35.150.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.35.225 (225.35.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:28:34.534836 2026] [security2:error] [pid 23330:tid 23330] [client 34.150.35.225:50410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.garrisonfinancial.net"] [uri "/site/.git/config"] [unique_id "aps4AqUsIgRyUxT3CmqfygAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
gadix
2026-09-04 21:18:54
(1 hour ago)
[04/Sep/2026:23:18:53.564396 +0200] aps1vajBEU99rOnFJjqKjAAAAFU 34.150.35.225 42878 127.0.0.1 7081
[ ...
show more
[04/Sep/2026:23:18:53.564396 +0200] aps1vajBEU99rOnFJjqKjAAAAFU 34.150.35.225 42878 127.0.0.1 7081
[04/Sep/2026:23:18:53.565195 +0200] aps1vajBEU99rOnFJjqKjQAAAEE 34.150.35.225 42890 127.0.0.1 7081
[04/Sep/2026:23:18:53.566303 +0200] aps1vdWzcWr-UviINLTOogAAAAA 34.150.35.225 42904 127.0.0.1 7081
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 20:13:28
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.35.225 (225.35.150.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.35.225 (225.35.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 16:13:25.190112 2026] [security2:error] [pid 20650:tid 20650] [client 34.150.35.225:38660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "doctorbalog.com"] [uri "/app/.git/config"] [unique_id "apsmZWsIdXgn96flnB-YoAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
NewGastroline
2026-09-04 19:00:43
(3 hours ago)
Malicious request blocked by CrowdSec on gastro-prod1.boreus.de
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 18:16:12
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.35.225 (225.35.150.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.35.225 (225.35.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 14:16:06.686752 2026] [security2:error] [pid 25009:tid 25009] [client 34.150.35.225:55212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trendingnowsales.com.wholesalelivelobsters.com"] [uri "/var/www/.git/config"] [unique_id "apsK5kKFybjC93wislHbwgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
Olexiy Backend
2026-09-04 17:20:09
(5 hours ago)
34.150.35.225
...
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 15:46:14
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.35.225 (225.35.150.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.35.225 (225.35.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:46:09.745234 2026] [security2:error] [pid 27359:tid 27359] [client 34.150.35.225:44476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.21north.com"] [uri "/backend/.git/config"] [unique_id "aprnwSPIPuwwCySszWNF8AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
lolyay
2026-09-04 14:35:32
(8 hours ago)
34.150.35.225 - - [04/Sep/2026:14:35:31 +0000] "GET /www/.git/config HTTP/1.1" 200 4 "-" "crusader-w ...
show more
34.150.35.225 - - [04/Sep/2026:14:35:31 +0000] "GET /www/.git/config HTTP/1.1" 200 4 "-" "crusader-worker/1.0"
34.150.35.225 - - [04/Sep/2026:14:35:31 +0000] "GET /public/.git/config HTTP/1.1" 200 4 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Bad Web Bot
🇨🇭
4server
2026-09-04 08:06:19
(14 hours ago)
[FriSep0410:06:14.2165812026][security2:error][pid3976482:tid3976752][client34.150.35.225:0]ModSecur ...
show more
[FriSep0410:06:14.2165812026][security2:error][pid3976482:tid3976752][client34.150.35.225:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"marcionetti.es\"][uri\"/www/.git/config\"][unique_id\"app79sGAuUnucRiIpl7rZQAAABc\"]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:08:07
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.35.225 (225.35.150.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.35.225 (225.35.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:08:01.130682 2026] [security2:error] [pid 19079:tid 19079] [client 34.150.35.225:33606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "esmital.tecnoconce.com"] [uri "/backend/.git/config"] [unique_id "appuUfQmrkKxc3pkn3-GzwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:43:33
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 34.150.35.225 (225.35.150.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.35.225 (225.35.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:43:26.262266 2026] [security2:error] [pid 8196:tid 8196] [client 34.150.35.225:49038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "illinois-online.org"] [uri "/www/.git/config"] [unique_id "appojt87fukB7GE5gMvNzQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
XICTRON
2026-09-04 02:00:05
(20 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 18:46:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 34.150.35.225 (225.35.150.34.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 34.150.35.225 (225.35.150.34.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 14:46:13.002061 2026] [security2:error] [pid 6850:tid 6850] [client 34.150.35.225:37002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marketfuel.co"] [uri "/api/.git/config"] [unique_id "apnAdbRI_aI6CMK4QwBcbgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
clauss
2026-09-03 16:34:24
(1 day ago)
34.150.35.225 - - [03/Sep/2026:19:34:23 +0300] "GET /html/.git/config HTTP/1.1" 403 10361 "-" "crusa ...
show more
34.150.35.225 - - [03/Sep/2026:19:34:23 +0300] "GET /html/.git/config HTTP/1.1" 403 10361 "-" "crusader-worker/1.0"
34.150.35.225 - - [03/Sep/2026:19:34:23 +0300] "GET /htdocs/.git/config HTTP/1.1" 403 10365 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇳🇱
e.fierstra
2026-09-03 16:09:36
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack