๐ณ๐ฑ
homeshowdomain.nl
2026-08-28 21:59:34
(4 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-27.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
billfor
2026-08-27 19:45:22
(5 days ago)
35.203.89.107 - - [27/Aug/2026:15:45:19 -0400] "GET /.git/config HTTP/1.1" 404 146 "-" "crusader-wor ...
show more
35.203.89.107 - - [27/Aug/2026:15:45:19 -0400] "GET /.git/config HTTP/1.1" 404 146 "-" "crusader-worker/1.0"
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-08-27 18:04:49
(5 days ago)
[27/Aug/2026:21:04:49 +0300] -- 35.203.89.107 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[27/Aug/2026:21:04:49 +0300] -- 35.203.89.107 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:46:46
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.203.89.107 (107.89.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.89.107 (107.89.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:46:42.601868 2026] [security2:error] [pid 4955:tid 4955] [client 35.203.89.107:43286] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.erkan.net"] [uri "/backend/.git/config"] [unique_id "apB4Apbh4VZn2n2yRIaGFAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:20:47
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.203.89.107 (107.89.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.89.107 (107.89.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:20:40.466941 2026] [security2:error] [pid 3238249:tid 3238409] [client 35.203.89.107:41152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "m3sxa.com"] [uri "/backend/.git/config"] [unique_id "apBx6E6JtIhrstwKm0y3ogAAAMg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Eric
2026-08-27 17:18:54
(5 days ago)
[Thu Aug 27 17:18:53.923927 2026] [security2:error] [pid 3545702:tid 3545702] [client 35.203.89.107: ...
show more
[Thu Aug 27 17:18:53.923927 2026] [security2:error] [pid 3545702:tid 3545702] [client 35.203.89.107:0] [client 35.203.89.107] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "pop-the-slots.com"] [uri "/public/.git/config"] [unique_id "apBxfXVIu7NspVqBKNoBkAAAAAQ"]
[Thu Aug 27 17:18:53.935593 2026] [security2:error] [pid 3569944:tid 3569944] [client 35.203.89.107:0] [client 35.203.89.107] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score:
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:00:18
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.203.89.107 (107.89.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.89.107 (107.89.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:00:14.408041 2026] [security2:error] [pid 11728:tid 11728] [client 35.203.89.107:58960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.acmax.com"] [uri "/backend/.git/config"] [unique_id "apBtHlByvpmCcNHd0qcRSwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 11:47:08
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.203.89.107 (107.89.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.89.107 (107.89.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 07:47:05.037535 2026] [security2:error] [pid 8390:tid 8390] [client 35.203.89.107:49942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hakanararat.com"] [uri "/.git/config"] [unique_id "apAjuQs2KTHcL9mbcPYP2gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 06:44:26
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.203.89.107 (107.89.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.89.107 (107.89.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 02:44:19.056305 2026] [security2:error] [pid 5286:tid 5397] [client 35.203.89.107:37472] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "advertisingfirm.org"] [uri "/.git/config"] [unique_id "ao_cw4zrtjvgeahAlyjo7AAAAgg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
diego
2026-08-27 06:18:49
(5 days ago)
[probe-44-49] 2026-08-27 06:00:07, Client: 35.203.89.107, Protocol: 6, Unauthorized activity to HTTP ...
show more
[probe-44-49] 2026-08-27 06:00:07, Client: 35.203.89.107, Protocol: 6, Unauthorized activity to HTTP: GET /backend/.git/config
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-08-27 05:05:09
(5 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 05:01:57
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.203.89.107 (107.89.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.89.107 (107.89.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 01:01:50.984699 2026] [security2:error] [pid 10900:tid 10900] [client 35.203.89.107:32788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "madandproud.com"] [uri "/.git/config"] [unique_id "ao_EvoqA7hjgeZVSs3iKWwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-08-27 03:00:11
(5 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 01:13:00
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.203.89.107 (107.89.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.89.107 (107.89.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 21:12:51.799747 2026] [security2:error] [pid 23849:tid 23849] [client 35.203.89.107:56556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.betnbet.ag"] [uri "/wordpress/.git/config"] [unique_id "ao-PE9WpcWGZ9GcdNk21cgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 22:22:44
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.203.89.107 (107.89.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.89.107 (107.89.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 18:22:35.803411 2026] [security2:error] [pid 14330:tid 14330] [client 35.203.89.107:49106] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "furbabieslivesmatter.com"] [uri "/backend/.git/config"] [unique_id "ao9nK2Dahc40eIGUy-IlCAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack