Anonymous
2026-09-02 21:49:15
(4 hours ago)
35.189.23.148 - - [02/Sep/2026:21:49:14 +0000] "GET /.git/config HTTP/1.1" 404 31975 "-" "Mozilla/5. ...
show more
35.189.23.148 - - [02/Sep/2026:21:49:14 +0000] "GET /.git/config HTTP/1.1" 404 31975 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 20:55:02
(5 hours ago)
suspicious request in access.log
Web App Attack
π©πͺ
LRob
2026-09-02 20:38:56
(5 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+1 more) | 2026-09-02 20:38 UTC
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 19:20:28
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.23.148 (148.23.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.23.148 (148.23.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 15:20:22.666238 2026] [security2:error] [pid 19664:tid 19664] [client 35.189.23.148:55150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.asermaq.cl.tecnoconce.com"] [uri "/.git/config"] [unique_id "aph29nWOYNy1JaeZf1J51AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 18:17:10
(7 hours ago)
35.189.23.148 - - [02/Sep/2026:20:17:05 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows N ...
show more
35.189.23.148 - - [02/Sep/2026:20:17:05 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.189.23.148 - - [02/Sep/2026:20:17:05 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.189.23.148 - - [02/Sep/2026:20:17:05 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.189.23.148 - - [02/Sep/2026:20:17:05 +0200] "GET /.git/config HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.189.23.148 - - [02/Sep/2026:20:17:06 +0200] "GET /.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.189.23.148 - - [02/Sep/2026:2
...
show less
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-09-02 18:14:18
(8 hours ago)
20 attempts against mh-misbehave-ban on kiwi
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 15:10:16
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.23.148 (148.23.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.23.148 (148.23.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 11:10:12.973206 2026] [security2:error] [pid 11355:tid 11355] [client 35.189.23.148:40668] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.bins.mcbrearty.org"] [uri "/.git/config"] [unique_id "apg8VBETVkE1-zkwFJCc_wAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Octopuce
2026-09-02 14:16:45
(12 hours ago)
Aggressive web search of vulnerable pages: / /.env /.env.local /app/.env /apps/.env ...
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 12:49:03
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.23.148 (148.23.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.23.148 (148.23.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 08:48:55.257432 2026] [security2:error] [pid 31124:tid 31124] [client 35.189.23.148:42208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.binfieldresources.keyston.net"] [uri "/.git/config"] [unique_id "apgbN1sg_TMiRx3_iGC8YQAAAJQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 12:17:05
(13 hours ago)
Bot / scanning and/or hacking attempts: GET /.env1 HTTP/1.1, GET /.env_copy HTTP/1.1, GET /.env.dock ...
show more
Bot / scanning and/or hacking attempts: GET /.env1 HTTP/1.1, GET /.env_copy HTTP/1.1, GET /.env.docker HTTP/1.1, GET /.env.txt HTTP/1.1, GET /.env~ HTTP/1.1, GET /.env2 HTTP/1.1, GET /.env.live HTTP/1.1
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 11:47:08
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.23.148 (148.23.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.23.148 (148.23.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 07:47:01.504002 2026] [security2:error] [pid 20577:tid 20577] [client 35.189.23.148:41684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.binasplace.thinkingepic.com"] [uri "/.git/config"] [unique_id "apgMtbHpWyi6wdzisNlp3wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
marten_o
2026-09-02 10:45:54
(15 hours ago)
35.189.23.148 - - [02/Sep/2026:12:45:53 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 404 236 "-" "Mozilla/ ...
show more
35.189.23.148 - - [02/Sep/2026:12:45:53 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 309 458
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 07:18:57
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.23.148 (148.23.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.23.148 (148.23.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 03:18:53.543942 2026] [security2:error] [pid 7553:tid 7553] [client 35.189.23.148:59784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.billswilliams.com.bacpool.com"] [uri "/.git/config"] [unique_id "apfN3Yu5EvqZfCgLKnDtGwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
π¨π Hosting
2026-09-02 05:10:29
(21 hours ago)
Automated WAF report: 200-300 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 03:47:30
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.189.23.148 (148.23.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.23.148 (148.23.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 23:47:24.419526 2026] [security2:error] [pid 7626:tid 7637] [client 35.189.23.148:59576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.billgiegold.uoexpanse.com"] [uri "/.git/config"] [unique_id "apecTIirWuGhjOlxi7lCqQAAAYg"]
show less
Brute-Force
Bad Web Bot
Web App Attack