🇧🇪
Ivo Vynckier
2026-09-02 09:39:00
(48 minutes ago)
35.204.224.195 - - [02/Sep/2026:09:21:21 +0200] "GET /.git/config HTTP/1.1" 403 177 "-" "Mozilla/5.0 ...
show more
35.204.224.195 - - [02/Sep/2026:09:21:21 +0200] "GET /.git/config HTTP/1.1" 403 177 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.204.224.195 - - [02/Sep/2026:09:21:21 +0200] "GET /.env HTTP/1.1" 403 177 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.204.224.195 - - [02/Sep/2026:09:21:21 +0200] "GET /.env.local HTTP/1.1" 403 177 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 09:24:22
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.204.224.195 (195.224.204.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.224.195 (195.224.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 05:24:16.146191 2026] [security2:error] [pid 28404:tid 28404] [client 35.204.224.195:36476] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.howwegothere.info.digifonics.com"] [uri "/.git/config"] [unique_id "apfrQORYC76IFel2Caa-eQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 09:05:08
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.204.224.195 (195.224.204.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.224.195 (195.224.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 05:05:01.296238 2026] [security2:error] [pid 11812:tid 11812] [client 35.204.224.195:56038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.howtokeepgoodemployeescom.indie100.com"] [uri "/.git/config"] [unique_id "apfmvURwZbEVXg_LRfa5sAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-02 08:49:27
(1 hour ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 1s
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 08:43:03
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.204.224.195 (195.224.204.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.224.195 (195.224.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 04:42:58.755314 2026] [security2:error] [pid 2362728:tid 2363015] [client 35.204.224.195:58768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.howsyourlife.aussiepens.com"] [uri "/.git/config"] [unique_id "apfhku0EZOUxwuwXU7YxngAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
Lazarus
2026-09-02 08:25:15
(2 hours ago)
HTTP probe.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 08:06:53
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.204.224.195 (195.224.204.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.224.195 (195.224.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 04:06:46.168813 2026] [security2:error] [pid 11865:tid 11865] [client 35.204.224.195:60682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.howelllands.swhinc.net"] [uri "/.git/config"] [unique_id "apfZFrgOPL592YPYVsAfpAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Mainpine
2026-09-02 07:45:04
(2 hours ago)
probing for vulnerable web apps
Web App Attack
🇸🇪
vaia.cloud
2026-09-02 07:20:02
(3 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
Anonymous
2026-09-02 07:11:51
(3 hours ago)
Blocked by ModSec and CSF
Port Scan
Anonymous
2026-09-02 07:08:11
(3 hours ago)
Bot / seems abusive / Apache connections: 46
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-02 06:44:13
(3 hours ago)
Try to access /.git/config
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-02 05:06:01
(5 hours ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01]
Hacking
SQL Injection
Web App Attack
🇬🇧
consul.to
2026-09-02 04:21:11
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇬🇧
thetomtaylor.co.uk
2026-09-02 04:08:01
(6 hours ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice02,wa01,wa02]
Hacking
SQL Injection
Web App Attack