๐บ๐ธ
TPI-Abuse
2026-09-17 05:01:54
(47 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.195.197.176 (176.197.195.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.197.176 (176.197.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 01:01:49.306298 2026] [security2:error] [pid 18886:tid 18886] [client 35.195.197.176:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cloudex.link"] [uri "/.git/config"] [unique_id "aqt0PQIqX8rQd0yq39jUBQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 02:13:44
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.195.197.176 (176.197.195.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.197.176 (176.197.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:13:37.334264 2026] [security2:error] [pid 15088:tid 15088] [client 35.195.197.176:32816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.clientes.mpservice.com.sv"] [uri "/.git/config"] [unique_id "aqtM0eDCoThmK3P96ABPlAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-16 22:02:12
(7 hours ago)
Auto-ban: >3000 req/min op 2026-09-16
Web App Attack
SSH
Hacking
๐ณ๐ฑ
Site.eu
2026-09-16 16:52:28
(12 hours ago)
Excessive 404/403 errors
Brute-Force
๐ณ๐ฑ
Alt255
2026-09-16 16:47:40
(13 hours ago)
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35. ...
show more
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35.195.197.176 - - \[16/Sep/2026:18:47:34 +0200\] "GET /.git/config HTTP/1.1" 301 544 "-" "Mozilla/5.0 \(X11\; Linux x86_64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-16 16:05:02
(13 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 14:08:39
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.195.197.176 (176.197.195.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.197.176 (176.197.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 10:08:33.843097 2026] [security2:error] [pid 19407:tid 19436] [client 35.195.197.176:40138] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.buy-directv.com.exede-sales.com"] [uri "/.git/config"] [unique_id "aqqi4Q_LulmWyAkLxId_5QAAAQA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-16 14:03:03
(15 hours ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.195.197.176 - - [16/Sep/2026:16:03:00 +0200] "GET /.git/config HTTP/1.1" 301 520 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-16 13:43:11
(16 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:15:01
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.195.197.176 (176.197.195.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.197.176 (176.197.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:14:56.633836 2026] [security2:error] [pid 28800:tid 28800] [client 35.195.197.176:53574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.busybconstruction.ewingmissouri.com"] [uri "/.git/config"] [unique_id "aqqWULhgWg5Y1tmR6wkXlQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-16 12:45:04
(17 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+2 more) | 2026-09-16 12:45 UTC
show less
Hacking
Web App Attack
Anonymous
2026-09-16 11:33:33
(18 hours ago)
CPOWCO WEBEXPLOIT 35.195.197.176 (176.197.195.35.bc.googleusercontent.com)
Web App Attack
Anonymous
2026-09-16 09:45:48
(20 hours ago)
[email.tmg.gr] httpd-config-scan: sites=www.cdn.tmg.gr; logs=/var/log/httpd/domains/cdn.tmg.gr.log; ...
show more
[email.tmg.gr] httpd-config-scan: sites=www.cdn.tmg.gr; logs=/var/log/httpd/domains/cdn.tmg.gr.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-09-16 09:24:35
(20 hours ago)
Remote Command Execution: Unix Shell Expression Found. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\ ...
show more
Remote Command Execution: Unix Shell Expression Found. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})| (932130-131)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-16 09:05:06
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.195.197.176 (176.197.195.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.197.176 (176.197.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 05:04:58.650321 2026] [security2:error] [pid 28908:tid 28908] [client 35.195.197.176:37410] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cdn.customdesignsbybjp.com"] [uri "/.git/config"] [unique_id "aqpbutX8c2xsToXA6zP6bwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack