🇮🇹
[email protected]
2026-09-09 22:51:14
(2 days ago)
35.201.158.63 - - [09/Sep/2026:18:01:28 +0200] "GET /.git/config HTTP/1.1" 404 654 "-" "Mozilla/5.0 ...
show more
35.201.158.63 - - [09/Sep/2026:18:01:28 +0200] "GET /.git/config HTTP/1.1" 404 654 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Web App Attack
Hacking
Anonymous
2026-09-09 19:20:17
(3 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-09 18:20:31
(3 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
🇳🇴
jad-abuse
2026-09-09 18:10:17
(3 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, env_probe, source_backup, server_status. Observed by 1 sensor(s); 169 hits.
show less
Web App Attack
🇫🇷
Octopuce
2026-09-09 17:57:08
(3 days ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 16:44:05
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.201.158.63 (63.158.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.158.63 (63.158.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 12:43:58.261565 2026] [security2:error] [pid 12606:tid 12606] [client 35.201.158.63:58486] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intolifeproductions.com"] [uri "/.git/config"] [unique_id "aqGMzj9CcjyY-oiOXKsa4QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
[email protected]
2026-09-09 16:02:17
(3 days ago)
2026-09-09 18:01:27,924 fail2ban.actions [1184]: NOTICE [modsecurity-critical] Ban 35.201.15 ...
show more
2026-09-09 18:01:27,924 fail2ban.actions [1184]: NOTICE [modsecurity-critical] Ban 35.201.158.632026-09-09 18:01:37,161 fail2ban.actions [1184]: NOTICE [apache-scanner] Ban 35.201.158.63
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-09 14:13:32
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.201.158.63 (63.158.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.158.63 (63.158.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 10:13:27.977483 2026] [security2:error] [pid 5816:tid 5816] [client 35.201.158.63:32846] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mitchellamazing.com"] [uri "/.git/config"] [unique_id "aqFph15bPLlwbcKLrUSfvgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 13:53:57
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.201.158.63 (63.158.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.158.63 (63.158.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:53:51.295284 2026] [security2:error] [pid 18725:tid 18725] [client 35.201.158.63:45776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mitchell-hunt.com"] [uri "/.git/config"] [unique_id "aqFk79KJnxVZBo5VeoxiPQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 13:00:56
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.201.158.63 (63.158.201.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.158.63 (63.158.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 09:00:52.229629 2026] [security2:error] [pid 15388:tid 15388] [client 35.201.158.63:60272] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intnlc.org"] [uri "/.git/config"] [unique_id "aqFYhKk8ajn92Peg93oieQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-09 09:16:15
(3 days ago)
CloudLinux/Plesk alert - host=cloudlinux dominio=mitan.it ip=35.201.158.63 richieste=465 rischio=ALT ...
show more
CloudLinux/Plesk alert - host=cloudlinux dominio=mitan.it ip=35.201.158.63 richieste=465 rischio=ALTO score=19 motivi=molte_richieste,molte_uri_uniche,molti_404,path_sospetti,api,poco_statico,dinamico cat_id=21,19 periodo=10min
show less
Web App Attack
Bad Web Bot