๐ฟ๐ฆ
conure.sh
2026-09-29 12:16:36
(1 day ago)
csagent: score 20.4: secrets grab x2, 404 noise floor x2; 1 domain(s) in 5s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 09:19:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.192.202.169 (169.202.192.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.202.169 (169.202.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 05:19:50.491198 2026] [security2:error] [pid 12103:tid 12103] [client 35.192.202.169:50310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "videos.mathewyoung.com"] [uri "/.git/config"] [unique_id "aruCtpOwq03QNUGbyeYgBgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-29 00:17:17
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.192.202.169 (US/United States/169. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.192.202.169 (US/United States/169.202.192.35.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐ซ๐ท
dynamix
2026-09-28 23:59:23
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-28 21:52:55
(1 day ago)
csagent: score 20.4: 404 noise floor x2, secrets grab x2; 1 domain(s) in 5s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 17:23:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.192.202.169 (169.202.192.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.202.169 (169.202.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 13:23:38.742650 2026] [security2:error] [pid 4317:tid 4317] [client 35.192.202.169:34270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "howelllands.com"] [uri "/.git/config"] [unique_id "arqimmK31C89gkawikmnFgAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 06:45:33
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.192.202.169 (169.202.192.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.202.169 (169.202.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 02:45:25.933474 2026] [security2:error] [pid 26097:tid 26097] [client 35.192.202.169:40138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "visionremota.info"] [uri "/.git/config"] [unique_id "aroNBT_qWGc7wzuRZEZvCwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-27 04:12:50
(3 days ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-26 20:18:27
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.192.202.169 (169.202.192.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.202.169 (169.202.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 16:18:20.639543 2026] [security2:error] [pid 24790:tid 24790] [client 35.192.202.169:33058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.arklatexds.com"] [uri "/.git/config"] [unique_id "argojJpyWzUFxwO3m8133QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-26 10:08:01
(4 days ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02 ...
show more
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02]
show less
Hacking
SQL Injection
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-09-25 01:04:32
(5 days ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/169.202.192.35.bc.googleuserconte ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/169.202.192.35.bc.googleusercontent.com
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-22 22:00:40
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-21.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 15:34:03
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.192.202.169 (169.202.192.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.202.169 (169.202.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:33:59.603793 2026] [security2:error] [pid 20489:tid 20489] [client 35.192.202.169:46116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.fairfieldfarms.net"] [uri "/.git/config"] [unique_id "arKf59rVMBNxetgPftQ8OQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-21 22:02:19
(1 week ago)
Auto-ban: >3000 req/min op 2026-09-21
Web App Attack
SSH
Hacking
๐จ๐ญ
zynex
2026-09-21 18:39:30
(1 week ago)
URL Probing: /server/.env
Web App Attack