๐จ๐ญ
TheCoon
2026-06-02 04:00:02
(3 months ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-05-28 22:01:09
(3 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-27.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-27 07:44:50
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 35.196.60.91 (91.60.196.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.60.91 (91.60.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 03:44:43.093064 2026] [security2:error] [pid 16872:tid 17009] [client 35.196.60.91:37408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.creativefamily.net"] [uri "/.git/config"] [unique_id "ahag66HQ3dVlL_t5sfaCZQAAApc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Kreapptivo
2026-05-27 07:41:49
(3 months ago)
[27/May/2026:09:41:46 +0200] Web-Request: "GET /.git/config", User-Agent: "Mozilla/5.0 (Linux; Andro ...
show more
[27/May/2026:09:41:46 +0200] Web-Request: "GET /.git/config", User-Agent: "Mozilla/5.0 (Linux; Android 9; Pixel 2 XL) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/77.0.3865.18 Mobile Safari/537.36"
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
markawes
2026-05-27 06:26:57
(3 months ago)
[markis] Auto banned by Fail2Ban. Reason: Malicious web scan / attempted access to sensitive paths. ...
show more
[markis] Auto banned by Fail2Ban. Reason: Malicious web scan / attempted access to sensitive paths. Evidence:
35.196.60.91 - - [27/May/2026:06:26:03 +0100] "GET /.git/config HTTP/1.1" 404 3061 "-" "Mozilla/4.0 (compatible; MSIE 6.0; Windows CE; IEMobile 7.11) Sprint:PPC6800"
35.196.60.91 - - [27/May/2026:07:10:45 +0100] "GET /.git/config HTTP/1.1" 404 3070 "-" "Mozilla/5.0 (compatible; YandexNews/4.0; +http://yandex.com/bots)"
35.196.60.91 - - [27/May/2026:07:26:56 +0100] "GET /.git/config HTTP/1.1" 404 3063 "-" "Mozilla/5.0 (Linux; Android 9; SM-G950F) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/75.0.3770.143 Mobile Safari/537.36"
show less
Port Scan
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 05:46:04
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 35.196.60.91 (91.60.196.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.60.91 (91.60.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 01:45:58.444697 2026] [security2:error] [pid 6707:tid 6707] [client 35.196.60.91:41924] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.bryanthebusinessmanager.com"] [uri "/.git/config"] [unique_id "ahaFFq10LFV7jS2oRqZjewAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-05-27 01:15:39
(3 months ago)
Attempted access to sensitive endpoint (/.git/config) detected. Automated scan or unauthorized probi ...
show more
Attempted access to sensitive endpoint (/.git/config) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 23:18:29
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 35.196.60.91 (91.60.196.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.60.91 (91.60.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 19:18:25.943452 2026] [security2:error] [pid 27987:tid 27987] [client 35.196.60.91:42238] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.niksautobodyandsales.com"] [uri "/.git/config"] [unique_id "ahYqQWW_nQv4SDSnWZ709QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 22:49:11
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 35.196.60.91 (91.60.196.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.60.91 (91.60.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 18:49:06.456759 2026] [security2:error] [pid 3320:tid 3320] [client 35.196.60.91:32820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.cashforjunkcars.info"] [uri "/.git/config"] [unique_id "ahYjYii8qnyLpmX-oqs9WQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 22:18:48
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 35.196.60.91 (91.60.196.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.60.91 (91.60.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 18:18:43.040913 2026] [security2:error] [pid 29118:tid 29118] [client 35.196.60.91:39148] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thesiteworks.com"] [uri "/.git/config"] [unique_id "ahYcQ3pXcwOeGGbzxaZM2QAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 20:51:47
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 35.196.60.91 (91.60.196.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.60.91 (91.60.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 16:51:42.300247 2026] [security2:error] [pid 23196:tid 23196] [client 35.196.60.91:49336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.mainstreetofficesuites.com"] [uri "/.git/config"] [unique_id "ahYH3rvlLVUhKZcnODSrDQAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack