๐บ๐ธ
TPI-Abuse
2026-09-02 22:50:39
(8 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.200.132.88 (88.132.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.132.88 (88.132.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 18:50:32.592000 2026] [security2:error] [pid 23391:tid 23391] [client 35.200.132.88:56988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.erass.info.networkmediasoftware.com"] [uri "/.git/config"] [unique_id "apioOHrgm9a4UQ_11OoFdgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 22:05:06
(54 minutes ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-09-02 22:02:23
(56 minutes ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-01.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-09-02 21:22:07
(1 hour ago)
35.200.132.88 - - [02/Sep/2026:16:22:04 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Window ...
show more
35.200.132.88 - - [02/Sep/2026:16:22:04 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 35.200.132.88
35.200.132.88 - - [02/Sep/2026:16:22:04 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 35.200.132.88
35.200.132.88 - - [02/Sep/2026:16:22:04 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 35.200.132.88
35.200.132.88 - - [02/Sep/2026:16:22:04 -0500] "GET /.env.staging HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 35.200.132.88
35.200.132.88 - - [02/Sep/2026:16:22:05 -0500] "GET /.env.development HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWeb
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-02 20:26:36
(2 hours ago)
๐ฅ VERY AGGRESSIVE SCANNER probed over 100 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 20:14:42
(2 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.200.132.88 (88.132.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 35.200.132.88 (88.132.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 16:14:38.522104 2026] [security2:error] [pid 13181:tid 13181] [client 35.200.132.88:43394] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.equiprentalsales.crazycontrols.com"] [uri "/.git/config"] [unique_id "apiDriVmBfiig1ydCQ18XgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-02 18:19:30
(4 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - โ๏ธ Configuration File Access (Non Decay-Based) - โช๏ธ Excessive 30X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 17:50:22
(5 hours ago)
35.200.132.88 - - [02/Sep/2026:19:50:17 +0200] "GET /.git/config HTTP/1.1" 404 184 "-" "Mozilla/5.0 ...
show more
35.200.132.88 - - [02/Sep/2026:19:50:17 +0200] "GET /.git/config HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.200.132.88 - - [02/Sep/2026:19:50:17 +0200] "GET /.env HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.200.132.88 - - [02/Sep/2026:19:50:18 +0200] "GET /.env.local HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.200.132.88 - - [02/Sep/2026:19:50:18 +0200] "GET /.env.production HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.200.132.88 - - [02/Sep/2026:19:50:18 +0200] "GET /.env.staging HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-02 17:37:33
(5 hours ago)
Try to access /.git/config
Web App Attack
๐ฉ๐ช
itsolon
2026-09-02 15:19:28
(7 hours ago)
[02/Sep/2026:17:19:28 +0200] 178836236884.592962 35.200.132.88 44576 217.154.7.177 443
[02/Sep/2026: ...
show more
[02/Sep/2026:17:19:28 +0200] 178836236884.592962 35.200.132.88 44576 217.154.7.177 443
[02/Sep/2026:17:19:28 +0200] 178836236850.115101 35.200.132.88 44562 217.154.7.177 443
[02/Sep/2026:17:19:28 +0200] 178836236826.943142 35.200.132.88 44598 217.154.7.177 443
[02/Sep/2026:17:19:28 +0200] 178836236846.814590 35.200.132.88 44576 217.154.7.177 443
[02/Sep/2026:17:19:28 +0200] 178836236848.840057 35.200.132.88 44562 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-09-02 14:49:02
(8 hours ago)
Login credentials theft attempt
Hacking
๐ซ๐ท
Lunix
2026-09-02 14:03:35
(8 hours ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 13:17:27
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.132.88 (88.132.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.132.88 (88.132.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 09:17:20.771064 2026] [security2:error] [pid 10184:tid 10184] [client 35.200.132.88:59946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.epk.gmacguffin.com"] [uri "/.git/config"] [unique_id "apgh4ENwxqirt3UgLEEBMgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 12:44:52
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.132.88 (88.132.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.132.88 (88.132.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 08:44:45.027129 2026] [security2:error] [pid 13626:tid 13626] [client 35.200.132.88:51956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.epiphanybookstore.kathrynmcbride.com"] [uri "/.git/config"] [unique_id "apgaPXiwBMuSuqSlIxnjggAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-02 10:54:50
(12 hours ago)
Web attack/malicious scanning detected
Web App Attack