πΊπΈ
TPI-Abuse
2026-09-23 00:23:05
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.191.3 (3.191.192.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.191.3 (3.191.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 20:22:51.504840 2026] [security2:error] [pid 12243:tid 12243] [client 35.192.191.3:56508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thehandyfamily.net"] [uri "/.git/config"] [unique_id "arMb25WD2dNcLCJVitnPMAAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
BlueWire Hosting
2026-09-22 23:33:13
(13 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
π©πͺ
LRob
2026-09-22 23:12:53
(14 hours ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.git/config | 2026-09-22 23:12 UTC
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 23:11:24
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.191.3 (3.191.192.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.191.3 (3.191.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 19:11:20.557741 2026] [security2:error] [pid 6432:tid 6432] [client 35.192.191.3:47474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thegoldreserve.com"] [uri "/.git/config"] [unique_id "arMLGMX2E8xCnFwbtUkKmwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 22:51:07
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.191.3 (3.191.192.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.191.3 (3.191.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:50:59.909522 2026] [security2:error] [pid 30561:tid 30561] [client 35.192.191.3:35198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thegamblefamily.com"] [uri "/.git/config"] [unique_id "arMGU3BZxhEFsneJhtgs5AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 22:31:55
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.191.3 (3.191.192.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.191.3 (3.191.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:31:49.713953 2026] [security2:error] [pid 1425164:tid 1425164] [client 35.192.191.3:55432] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thefleetnetwork.com.thesweetfam.com"] [uri "/.git/config"] [unique_id "arMB1XV9rZapPgB-S3dm8gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 22:14:52
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.191.3 (3.191.192.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.191.3 (3.191.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:14:49.342075 2026] [security2:error] [pid 19336:tid 19357] [client 35.192.191.3:35150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theextraordinaryoffice.monopostoyachts.com"] [uri "/.git/config"] [unique_id "arL92e3FQGqxD8ZsCrLuhQAAAUk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-09-22 21:59:40
(15 hours ago)
Auto-ban: >3000 req/min op 2026-09-22
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-09-22 21:50:38
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.191.3 (3.191.192.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.191.3 (3.191.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:50:30.985168 2026] [security2:error] [pid 21041:tid 21041] [client 35.192.191.3:46736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thedreamcatchers.eu"] [uri "/.git/config"] [unique_id "arL4Jg89RTr5TSIhCtSytQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 21:33:20
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.191.3 (3.191.192.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.191.3 (3.191.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:33:15.352576 2026] [security2:error] [pid 23031:tid 23031] [client 35.192.191.3:48738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "the.dental"] [uri "/.git/config"] [unique_id "arL0G3OdnXphTv-MzWFu1gAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
thesimonmanuel
2026-09-22 21:21:13
(16 hours ago)
35.192.191.3 - - [23/Sep/2026:02:51:13 +0530] "GET /.git/config HTTP/1.1" 403 117 "-" "-"
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 21:13:57
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.191.3 (3.191.192.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.191.3 (3.191.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:13:51.746819 2026] [security2:error] [pid 2721:tid 2721] [client 35.192.191.3:56366] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thecrimsonpirate.com"] [uri "/.git/config"] [unique_id "arLvjyvuIRor9YOS4YRlQAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 20:57:20
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.191.3 (3.191.192.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.191.3 (3.191.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:57:15.763358 2026] [security2:error] [pid 21647:tid 21647] [client 35.192.191.3:58354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thecommonsenseeconomist.banis-associates.com"] [uri "/.git/config"] [unique_id "arLrq5cJzp_iIpOZajo7qgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack