πΊπΈ
TPI-Abuse
2026-10-04 23:47:48
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.204.80.29 (29.80.204.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.80.29 (29.80.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 19:47:42.818195 2026] [security2:error] [pid 23565:tid 23568] [client 35.204.80.29:60226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.iheb.org.aafm.us"] [uri "/.git/config"] [unique_id "asLlngtWze2kXzExOVNBrAAAAYE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-04 23:22:27
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.204.80.29 (29.80.204.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.80.29 (29.80.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 19:22:21.235430 2026] [security2:error] [pid 2607212:tid 2607267] [client 35.204.80.29:46094] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ihcsb.gryphix.com"] [uri "/.git/config"] [unique_id "asLfrTakSV7-e_pIt09tMQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
kosada.com
2026-10-04 23:17:13
(3 days ago)
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla ...
show more
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36")
show less
Web App Attack
π³π±
Alt255
2026-10-04 23:10:56
(3 days ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.204.80.29 - - [05/Oct/2026:01:10:38 +0200] "GET /.git/config HTTP/1.1" 404 80781 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-04 21:55:19
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.204.80.29 (29.80.204.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.80.29 (29.80.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 17:55:15.580631 2026] [security2:error] [pid 31562:tid 31577] [client 35.204.80.29:57152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.iguanablue.newleafpro.com"] [uri "/.git/config"] [unique_id "asLLQ1BsvSMW8gY7r2HnQAAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
altenglaner
2026-10-04 21:33:04
(3 days ago)
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ba ...
show more
Web scanner probing for sensitive files (.env, .git, backups) or path traversal. Reported by fail2ban.
show less
Hacking
Web App Attack
Anonymous
2026-10-04 21:20:02
(3 days ago)
suspicious request in access.log
Web App Attack
π³π±
Site.eu
2026-10-04 20:42:38
(3 days ago)
Excessive multi-domain requests
Brute-Force
ππ·
IgorS.zg.hr
2026-10-04 20:18:31
(3 days ago)
Web application attack detected by fail2ban
Hacking
Web App Attack
π«π·
masterguru
2026-10-04 19:54:46
(3 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
πΊπΈ
nyt
2026-10-04 18:53:38
(3 days ago)
Sensitive File Probe
Web App Attack
πΏπ¦
conure.sh
2026-10-04 18:32:17
(3 days ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 2s
Web App Attack
π³π±
homeshowdomain.nl
2026-09-22 22:04:14
(2 weeks ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-21.
show less
Web App Attack
SSH
Hacking
π³π±
homeshowdomain.nl
2026-09-21 22:03:29
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-09-21
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-09-21 12:02:06
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.204.80.29 (29.80.204.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.80.29 (29.80.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 08:02:01.035089 2026] [security2:error] [pid 22528:tid 22528] [client 35.204.80.29:36714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lavozdom.aguasolar.com"] [uri "/.git/config"] [unique_id "arEcuZU-a0_jWSFu-l_1yQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack