πΊπΈ
TPI-Abuse
2026-08-27 18:50:27
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.68.180 (180.68.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.68.180 (180.68.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 14:50:23.125713 2026] [security2:error] [pid 31267:tid 31267] [client 35.203.68.180:52914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.desktop.joebankx.com"] [uri "/wordpress/.git/config"] [unique_id "apCG72zImtPPHJI55J3-6wAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
4server
2026-08-27 18:00:24
(3 hours ago)
[ThuAug2720:00:21.5364112026][security2:error][pid1522568:tid1522658][client35.203.68.180:0]ModSecur ...
show more
[ThuAug2720:00:21.5364112026][security2:error][pid1522568:tid1522658][client35.203.68.180:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"vulcanoricambi.ch.136-243-54-122.cpanel.site\"][uri\"/src/.git/config\"][unique_id\"apB7Ncn0amhGi7ocIHKPtAAAAMQ\"]
show less
Port Scan
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 17:05:29
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.68.180 (180.68.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.68.180 (180.68.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:05:22.470059 2026] [security2:error] [pid 8628:tid 8628] [client 35.203.68.180:43738] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "puoci.com"] [uri "/app/.git/config"] [unique_id "apBuUicWhD1xMDl6f4gHUQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 10:12:23
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.68.180 (180.68.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.68.180 (180.68.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 06:12:17.882209 2026] [security2:error] [pid 1831:tid 1831] [client 35.203.68.180:52696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cityslickerstomp.info"] [uri "/src/.git/config"] [unique_id "apANgfze60WmqNDaHQgtOAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-08-27 08:09:48
(13 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /var/www/.git/config (+11 more) | 2026-08-27 08:09 UTC
show less
Hacking
Web App Attack
π©πͺ
grassau.com
2026-08-27 08:08:39
(13 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.203.68.180 (CA/Canada/Quebec/Montrea ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.203.68.180 (CA/Canada/Quebec/Montreal/180.68.203.35.bc.googleusercontent.com)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-08-27 07:16:44
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.68.180 (180.68.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.68.180 (180.68.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 03:16:35.327153 2026] [security2:error] [pid 13126:tid 13126] [client 35.203.68.180:40700] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.kleens-uk.com"] [uri "/wordpress/.git/config"] [unique_id "ao_kU0whzsKjj3M5U39cBQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-27 04:40:07
(16 hours ago)
[ns65.kdns.gr] httpd-config-scan: sites=www.webmail.vrilissiabc.gr; logs=/var/log/httpd/domains/vril ...
show more
[ns65.kdns.gr] httpd-config-scan: sites=www.webmail.vrilissiabc.gr; logs=/var/log/httpd/domains/vrilissiabc.gr.log; samples=/htdocs/.git/config | /api/.git/config | /.git/config
show less
Hacking
Web App Attack
πΊπΈ
nyt
2026-08-27 03:04:15
(18 hours ago)
Sensitive File Probe
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 01:53:21
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.68.180 (180.68.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.68.180 (180.68.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 21:53:16.505535 2026] [security2:error] [pid 11963:tid 11982] [client 35.203.68.180:43868] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.be.peoplecomeup.net"] [uri "/www/.git/config"] [unique_id "ao-YjCbmX1IB3Uchq-MIKgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-08-27 00:59:05
(20 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-08-27 00:54:13
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.68.180 (180.68.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.68.180 (180.68.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 20:54:06.188432 2026] [security2:error] [pid 22349:tid 22349] [client 35.203.68.180:54060] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bostonmarathonstories.bostonlog.com"] [uri "/api/.git/config"] [unique_id "ao-Krte7QH1B1GkJ_qHU6AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
dynamix
2026-08-26 23:59:04
(21 hours ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
IndigoRidge
2026-08-26 23:27:16
(22 hours ago)
35.203.68.180 - - [26/Aug/2026:19:27:16 -0400] "GET /site/.git/config HTTP/1.0" 404 5765 "-" "crusad ...
show more
35.203.68.180 - - [26/Aug/2026:19:27:16 -0400] "GET /site/.git/config HTTP/1.0" 404 5765 "-" "crusader-worker/1.0"
35.203.68.180 - - [26/Aug/2026:19:27:16 -0400] "GET /backend/.git/config HTTP/1.0" 404 5765 "-" "crusader-worker/1.0"
35.203.68.180 - - [26/Aug/2026:19:27:16 -0400] "GET /.git/config HTTP/1.0" 404 5765 "-" "crusader-worker/1.0"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-26 23:21:12
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.68.180 (180.68.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.68.180 (180.68.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 19:21:06.022390 2026] [security2:error] [pid 6022:tid 6022] [client 35.203.68.180:40942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "henhousebbq.com"] [uri "/www/.git/config"] [unique_id "ao904hlNyOgyRcdf8haJ8gAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack