๐บ๐ธ
TPI-Abuse
2026-09-28 14:35:25
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.5.147 (147.5.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.5.147 (147.5.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 10:35:19.994561 2026] [security2:error] [pid 23893:tid 23893] [client 35.200.5.147:43652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fundlevantateyanda.com"] [uri "/.git/config"] [unique_id "arp7Jxb9VJs1RfOvaVFh_QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-28 09:25:20
(7 hours ago)
Banned by Fail2Ban on server
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-28 08:24:08
(8 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 2s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 04:29:07
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.5.147 (147.5.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.5.147 (147.5.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 00:29:02.566354 2026] [security2:error] [pid 20281:tid 20415] [client 35.200.5.147:60970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cambridgebusinessschool.com.aafm.us"] [uri "/.git/config"] [unique_id "arntDruJwQTLJHlEwhMQVwAAAlY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-27 17:44:59
(23 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
masterguru
2026-09-27 17:29:03
(23 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-09-27 16:52:34
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 06:10:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.200.5.147 (147.5.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.5.147 (147.5.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 02:10:41.810527 2026] [security2:error] [pid 9097:tid 9119] [client 35.200.5.147:50694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cargosanibel.newleafpro.com"] [uri "/.git/config"] [unique_id "arizYYCn7qwIVvERz2_djgAAAU0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
tarlabs
2026-09-27 06:05:24
(1 day ago)
IP banned by Fail2Ban (traefik-404 jail)
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-26 23:37:38
(1 day ago)
35.200.5.147 - - [26/Sep/2026:19:37:37 -0400] "GET /.env HTTP/1.1" 403 6279 "-" "Mozilla/5.0 (Window ...
show more
35.200.5.147 - - [26/Sep/2026:19:37:37 -0400] "GET /.env HTTP/1.1" 403 6279 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 20:35:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.200.5.147 (147.5.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.5.147 (147.5.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 16:34:59.576114 2026] [security2:error] [pid 444:tid 444] [client 35.200.5.147:54042] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.dianogah.com"] [uri "/.git/config"] [unique_id "argsc141Tk-cSpatvDkoNAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-26 15:39:29
(2 days ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
๐ฆ๐บ
AWW-Admin
2026-09-26 10:33:22
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 35.200.5.147 (JP/Japan/147.5.200.35.bc. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.200.5.147 (JP/Japan/147.5.200.35.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-26 07:08:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.200.5.147 (147.5.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.5.147 (147.5.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 03:08:49.516908 2026] [security2:error] [pid 5653:tid 5653] [client 35.200.5.147:49052] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.coachsherinasalgado.michaelsabbey.org"] [uri "/.git/config"] [unique_id "ardvgW1d3aDvuMbpa7FIWgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
taivas.nl
2026-09-26 04:33:21
(2 days ago)
Many_bad_calls
Web App Attack