🇺🇸
TPI-Abuse
2026-09-11 06:20:26
(39 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.199.67.133 (133.67.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.67.133 (133.67.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 02:20:22.267293 2026] [security2:error] [pid 814626:tid 814666] [client 35.199.67.133:58858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.icemakerparts.com.faimreps.com"] [uri "/.git/config"] [unique_id "aqOdpgiwnukAyojzI9vDkQAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-11 06:19:53
(39 minutes ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 05:37:09
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.199.67.133 (133.67.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.67.133 (133.67.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 01:37:01.017094 2026] [security2:error] [pid 10381:tid 10395] [client 35.199.67.133:44758] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.icecc.com.aafm.us"] [uri "/.git/config"] [unique_id "aqOTfbLQtLc70pUu02U55QAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 05:13:57
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.199.67.133 (133.67.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.67.133 (133.67.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 01:13:49.888358 2026] [security2:error] [pid 31013:tid 31013] [client 35.199.67.133:39770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ice.premaindustrial.com"] [uri "/.git/config"] [unique_id "aqOODRZsolvHIPiSfOV3UwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇽
octageeks.com
2026-09-11 04:13:43
(2 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
🇺🇸
kosada.com
2026-09-11 03:25:18
(3 hours ago)
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla ...
show more
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36")
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 03:11:30
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.67.133 (133.67.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.67.133 (133.67.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 23:11:24.522242 2026] [security2:error] [pid 1712304:tid 1712304] [client 35.199.67.133:55480] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ic1.ic1.biz"] [uri "/.git/config"] [unique_id "aqNxXA9V0KxqudvC9xDIcQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
netman
2026-09-11 02:27:29
(4 hours ago)
HTTP: 35.199.67.133 blocked because of 100 failures
...
DDoS Attack
Web App Attack
🇺🇸
Rocky Mountain Bioengineering Symposium
2026-09-11 02:20:46
(4 hours ago)
35.199.67.133 - - [10/Sep/2026:20:20:45 -0600] "GET /.git/config HTTP/1.1" 301 509 "-" "Mozilla/5.0 ...
show more
35.199.67.133 - - [10/Sep/2026:20:20:45 -0600] "GET /.git/config HTTP/1.1" 301 509 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 00:43:46
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.67.133 (133.67.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.67.133 (133.67.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 20:43:38.682897 2026] [security2:error] [pid 20148:tid 20148] [client 35.199.67.133:56710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.elessenlabz.com.lucid-events.com"] [uri "/.git/config"] [unique_id "aqNOutaf7g2qF9c1rGGQ_wAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
Bay13
2026-09-10 22:42:57
(8 hours ago)
CrowdSec:custom/modsecurity
Web App Attack
🇸🇪
vaia.cloud
2026-09-10 22:05:04
(8 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-10 22:01:18
(8 hours ago)
Auto-ban: >3000 req/min op 2026-09-10
Web App Attack
SSH
Hacking
🇬🇧
consul.to
2026-09-10 20:57:01
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 16:59:33
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.67.133 (133.67.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.67.133 (133.67.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 12:59:30.100717 2026] [security2:error] [pid 20862:tid 20862] [client 35.199.67.133:39934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.headcasebabies.digbie.com"] [uri "/.git/config"] [unique_id "aqLh8hFY3zfssemWxDW4HQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack