π³π±
homeshowdomain.nl
2026-06-09 22:01:19
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
πΊπΈ
Starburst SysOp Team
2026-06-09 11:43:05
(1 week ago)
(mod_security-custom) mod_security (id:210492) triggered by 35.194.70.36 (US/United States/District ...
show more
(mod_security-custom) mod_security (id:210492) triggered by 35.194.70.36 (US/United States/District of Columbia/Washington D.C./36.70.194.35.bc.googleusercontent.com/[AS396982 GOOGLE-CLOUD-PLATFORM]): 1 in the last 3600 secs (0-srv1)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-06-09 07:13:45
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.194.70.36 (36.70.194.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.70.36 (36.70.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 03:13:39.738518 2026] [security2:error] [pid 28876:tid 28876] [client 35.194.70.36:38660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "natchezbicycle.com"] [uri "/.git/config"] [unique_id "aie9I01mqtL7j141svMcUQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 06:35:16
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.194.70.36 (36.70.194.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.70.36 (36.70.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 02:35:11.565148 2026] [security2:error] [pid 29223:tid 29223] [client 35.194.70.36:52216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dusty-buggz.aisoftwaretools.com"] [uri "/.git/config"] [unique_id "aie0H6FglxyQfnEYLjR_uwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 06:16:10
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.194.70.36 (36.70.194.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.70.36 (36.70.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 02:16:04.218633 2026] [security2:error] [pid 32227:tid 32245] [client 35.194.70.36:53788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hauntingofkeystone.omegaoak.com"] [uri "/.git/config"] [unique_id "aievpPa5UXggZdSOF1VFwwAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Nexia
2026-06-09 05:55:48
(1 week ago)
[SENTINEL-HQ] Threat detected on geekverse.market: π CRITICAL Sentinel Trap: /.git/config
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 05:36:56
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.194.70.36 (36.70.194.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.70.36 (36.70.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 01:36:52.705026 2026] [security2:error] [pid 884:tid 908] [client 35.194.70.36:44032] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cynosureirrigation.com.cynosureinternetservices.com"] [uri "/.git/config"] [unique_id "aiemdKorEBdy5KvI9LI7hgAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 05:06:07
(1 week ago)
Trying to access config files
Web App Attack
π¨π
4server
2026-06-09 04:43:32
(1 week ago)
[TueJun0906:43:29.1148582026][security2:error][pid3565195:tid3565473][client35.194.70.36:0]ModSecuri ...
show more
[TueJun0906:43:29.1148582026][security2:error][pid3565195:tid3565473][client35.194.70.36:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"364\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.avvnicolaurbani.ch.81-17-25-250.cpanel.site\"][uri\"/.git/config\"][unique_id\"aieZ8dLBKOchiKElqvsvbQAAAIM\"]
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 04:28:41
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.194.70.36 (36.70.194.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.70.36 (36.70.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 00:28:36.794211 2026] [security2:error] [pid 19782:tid 19782] [client 35.194.70.36:45056] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "diament.diamenty.info"] [uri "/.git/config"] [unique_id "aieWdIIwrhysPfoDJQ2hoQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 04:17:48
(1 week ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
π«π·
masterguru
2026-06-09 04:00:12
(1 week ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.194.70.36 (US/United States/36.70. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.194.70.36 (US/United States/36.70.194.35.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-06-09 02:58:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.194.70.36 (36.70.194.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.70.36 (36.70.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 22:58:07.290332 2026] [security2:error] [pid 8945:tid 8945] [client 35.194.70.36:40350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.empoweringyou.edgeimprov.com"] [uri "/.git/config"] [unique_id "aieBPzKSM5_EBl2YG0R0rwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 00:20:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.194.70.36 (36.70.194.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.70.36 (36.70.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 20:20:34.710333 2026] [security2:error] [pid 10409:tid 10409] [client 35.194.70.36:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.pixacast.com"] [uri "/.git/config"] [unique_id "aidcUqjvH8D-D5dlLxNeqAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-06-08 22:05:58
(1 week ago)
Auto-ban: >3000 req/min op 2026-06-08
Web App Attack
SSH
Hacking