πΊπΈ
TPI-Abuse
2026-09-16 05:26:00
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.194.255.128 (128.255.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.255.128 (128.255.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 01:25:57.164638 2026] [security2:error] [pid 25395:tid 25395] [client 35.194.255.128:35888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.homevalue.iainrealtor.com"] [uri "/.git/config"] [unique_id "aqooZTeWaMjMsswykLYYIAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 05:01:54
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.194.255.128 (128.255.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.255.128 (128.255.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 01:01:51.045000 2026] [security2:error] [pid 27076:tid 27076] [client 35.194.255.128:36216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.home.theyoungstrategist.com"] [uri "/.git/config"] [unique_id "aqoiv015XtX7wAgeimI-HwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-16 02:48:33
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.194.255.128 (128.255.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.255.128 (128.255.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 22:48:27.451201 2026] [security2:error] [pid 1814:tid 1814] [client 35.194.255.128:51190] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.home.ryanc.net"] [uri "/.git/config"] [unique_id "aqoDe2Tt-qjWPTIKBxw-FwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π΄
jad-abuse
2026-09-16 01:10:07
(4 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, env_probe, source_backup. Observed by 1 sensor(s); 166 hits.
show less
Web App Attack
π³π±
homeshowdomain.nl
2026-09-15 22:04:42
(4 days ago)
Auto-ban: >3000 req/min op 2026-09-15
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-09-15 21:07:40
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.194.255.128 (128.255.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.255.128 (128.255.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:07:35.784312 2026] [security2:error] [pid 31611:tid 31611] [client 35.194.255.128:60282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.homebuilt.michaelsabbey.org"] [uri "/.git/config"] [unique_id "aqmzlwSrJSpDXfi5E7fkUwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 20:14:13
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.194.255.128 (128.255.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.255.128 (128.255.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:14:08.341261 2026] [security2:error] [pid 29089:tid 29089] [client 35.194.255.128:38622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.home.agingworkforcenews.com"] [uri "/.git/config"] [unique_id "aqmnEKnGk20fG8jgpjojSQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 18:41:58
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.194.255.128 (128.255.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.255.128 (128.255.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:41:53.835072 2026] [security2:error] [pid 16141:tid 16141] [client 35.194.255.128:54058] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lphalloweenparty.joesteiner.com"] [uri "/.git/config"] [unique_id "aqmRcRmNz62sKNOlrd7uqQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 18:03:07
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.194.255.128 (128.255.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.255.128 (128.255.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:03:02.586608 2026] [security2:error] [pid 31255:tid 31255] [client 35.194.255.128:45454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.holtzheimer.buynorthwest.com"] [uri "/.git/config"] [unique_id "aqmIVu-KeyGO87ji4q-HEQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 16:47:24
(4 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
πͺπΈ
robotstxt
2026-09-15 12:44:03
(4 days ago)
35.194.255.128 - - [15/Sep/2026:12:43:11 +0000] "GET /.env HTTP/1.1" 403 15769 "-" "Mozilla/5.0 (Win ...
show more
35.194.255.128 - - [15/Sep/2026:12:43:11 +0000] "GET /.env HTTP/1.1" 403 15769 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.194.255.128"
35.194.255.128 - - [15/Sep/2026:12:43:13 +0000] "GET /.env.local HTTP/1.1" 403 15769 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.194.255.128"
35.194.255.128 - - [15/Sep/2026:12:43:15 +0000] "GET /.env.production HTTP/1.1" 403 15788 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.194.255.128"
35.194.255.128 - - [15/Sep/2026:12:43:16 +0000] "GET /.env.staging HTTP/1.1" 403 15788 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.194.255.128"
35.194.255.128 - - [15/Sep/2026:12:43:17 +0000] "GET /.env.development HTTP/1.1" 40
...
show less
Web App Attack
π³π±
Site.eu
2026-09-15 11:37:27
(4 days ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-09-15 07:35:43
(4 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
π³π±
Alt255
2026-09-15 06:31:10
(5 days ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.194.255.128 - - [15/Sep/2026:08:31:10 +0200] "GET /.git/config HTTP/1.1" 403 2145 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
π³π±
Alt255
2026-09-15 05:05:47
(5 days ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.194.255.128 - - [15/Sep/2026:07:05:46 +0200] "GET /.git/config HTTP/1.1" 301 596 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack