🇿🇦
conure.sh
2026-09-11 12:08:30
(54 minutes ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 1s
Web App Attack
🇩🇪
FD-IX
2026-09-11 11:20:54
(1 hour ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 10:27:33
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.198.64.158 (158.64.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.64.158 (158.64.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 06:27:25.678783 2026] [security2:error] [pid 5545:tid 5628] [client 35.198.64.158:35600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.heavenlyhopechest.crowns.org"] [uri "/.git/config"] [unique_id "aqPXjX33YY2HG3pXnHq6sQAAAVc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 09:56:55
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.198.64.158 (158.64.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.64.158 (158.64.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 05:56:51.327142 2026] [security2:error] [pid 24482:tid 24482] [client 35.198.64.158:60906] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.heatspecs.steambalancing.com"] [uri "/.git/config"] [unique_id "aqPQY-bIiUZGyqsURRay4gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 08:48:30
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.198.64.158 (158.64.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.64.158 (158.64.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 04:48:26.360857 2026] [security2:error] [pid 3860:tid 3860] [client 35.198.64.158:49242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.heatherbargeron.com.michaelholdengc.com"] [uri "/.git/config"] [unique_id "aqPAWuflTElx6C5sbtW9-QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 07:58:18
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.198.64.158 (158.64.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.64.158 (158.64.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 03:58:11.595914 2026] [security2:error] [pid 22031:tid 22031] [client 35.198.64.158:43088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.heartstonemanor.buffaloweddingdeejay.com"] [uri "/.git/config"] [unique_id "aqO0kyvSqLeruFDQeQQ2aQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 06:13:04
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.198.64.158 (158.64.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.64.158 (158.64.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 02:12:58.173054 2026] [security2:error] [pid 814626:tid 814672] [client 35.198.64.158:39458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.heartfailuredev.howiek.com"] [uri "/.git/config"] [unique_id "aqOb6giwnukAyojzI9vCEQAAAJY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
🇨🇭 Hosting
2026-09-11 05:10:26
(7 hours ago)
Automated WAF report: 400-500 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
🇧🇪
taivas.nl
2026-09-11 04:33:02
(8 hours ago)
Many_bad_calls
Web App Attack
🇧🇪
taivas.nl
2026-09-11 03:32:12
(9 hours ago)
Bad_requests
Bad Web Bot
🇩🇪
big-cloud.nl
2026-09-11 03:23:58
(9 hours ago)
Try to access /.git/config
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 03:20:34
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.198.64.158 (158.64.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.64.158 (158.64.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 23:20:28.458007 2026] [security2:error] [pid 8272:tid 8272] [client 35.198.64.158:39132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.healthy4youllc.starrmail.net"] [uri "/.git/config"] [unique_id "aqNzfMEN6jpFOzY3ACtdHwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-11 03:18:59
(9 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 02:26:04
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.198.64.158 (158.64.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.64.158 (158.64.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 22:25:58.210472 2026] [security2:error] [pid 2625:tid 2625] [client 35.198.64.158:47768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.healthpointphysicians.co.helpkccare.org"] [uri "/.git/config"] [unique_id "aqNmtmo5GFI9nY8zsHvcSAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
konseptit
2026-09-10 23:18:17
(13 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.198.64.158 (DE/Germany/158.64.198.35 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.198.64.158 (DE/Germany/158.64.198.35.bc.googleusercontent.com)
show less
SQL Injection