🇺🇸
TPI-Abuse
2026-09-06 04:08:46
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.185.60.252 (252.60.185.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.185.60.252 (252.60.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 00:08:41.825675 2026] [security2:error] [pid 256171:tid 256191] [client 35.185.60.252:48416] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||buy-optimum.com.exede-sales.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "buy-optimum.com.exede-sales.com"] [uri "/database.sql"] [unique_id "apznSShFH94LSFzdoC2A6QAAAM8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-06 03:05:42
(11 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 01:43:50
(12 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-05 23:38:30
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.60.252 (252.60.185.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.60.252 (252.60.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 19:38:22.507627 2026] [security2:error] [pid 4750:tid 4750] [client 35.185.60.252:46258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "buyperfumeonline.net"] [uri "/app/.git/config"] [unique_id "apyn7q9JehHWsORmGmmIZQAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-05 23:30:04
(15 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-05 23:20:45
(15 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.185.60.252 (US/United States/252.60.185.35.b ...
show more
(mod_security) mod_security (id:949110) triggered by 35.185.60.252 (US/United States/252.60.185.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
Anonymous
2026-09-05 22:59:09
(15 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇮🇹
Inartis
2026-09-05 21:57:14
(16 hours ago)
35.185.60.252 - - [05/Sep/2026:23:57:10 +0200] "GET /admin/phpinfo.php HTTP/1.1" 403 5023 "-" "Mozil ...
show more
35.185.60.252 - - [05/Sep/2026:23:57:10 +0200] "GET /admin/phpinfo.php HTTP/1.1" 403 5023 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:48:20
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.60.252 (252.60.185.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.60.252 (252.60.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:48:17.038957 2026] [security2:error] [pid 18824:tid 18824] [client 35.185.60.252:60170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.wokedreamer.com"] [uri "/site/.git/config"] [unique_id "apyOIVrq45vGCHNuwb7RIAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:03:37
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.60.252 (252.60.185.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.60.252 (252.60.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:03:30.377620 2026] [security2:error] [pid 26564:tid 26590] [client 35.185.60.252:50456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.uoexpanse.com"] [uri "/site/.git/config"] [unique_id "apyDojdrqG9NGsvZ8dEmYAAAAZU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 20:36:53
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.60.252 (252.60.185.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.60.252 (252.60.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 16:36:46.698292 2026] [security2:error] [pid 22928:tid 22928] [client 35.185.60.252:42392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sarahpeebles.net"] [uri "/wordpress/.git/config"] [unique_id "apx9Xo8HMv3ER1BPEGw4_wAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Starburst SysOp Team
2026-09-05 11:23:47
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-stl2-13)
Hacking
Web App Attack
🇩🇪
Kitki30.com
2026-09-05 10:24:33
(1 day ago)
HTTP Probing (server 3). Log: 35.185.60.252 - - [05/Sep/2026:10:24:32 +0000] "GET /.git/config HTTP/ ...
show more
HTTP Probing (server 3). Log: 35.185.60.252 - - [05/Sep/2026:10:24:32 +0000] "GET /.git/config HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
35.185.60.252 - - [05/Sep/2026:10:24:32 +0000] "GET /app/.git/config HTTP/1.1" 301 162 "-" "crusader-worker/1.0"
show less
Brute-Force
Bad Web Bot
Web App Attack