🇨🇭
4server
2026-09-03 08:59:09
(1 hour ago)
[ThuSep0310:59:04.0808872026][security2:error][pid3617050:tid3617238][client35.205.173.27:0]ModSecur ...
show more
[ThuSep0310:59:04.0808872026][security2:error][pid3617050:tid3617238][client35.205.173.27:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"hosting-ticino-svizzera.com\"][uri\"/html/.git/config\"][unique_id\"apk22JqqtIxtxeinpKFBigAAAQQ\"]
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 02:02:40
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.205.173.27 (27.173.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.173.27 (27.173.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 22:02:33.760122 2026] [security2:error] [pid 22805:tid 22805] [client 35.205.173.27:41130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.camouflagebikinis.com"] [uri "/backend/.git/config"] [unique_id "apjVOUrx24q3JApc5Iy7kAAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 01:47:38
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.205.173.27 (27.173.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.173.27 (27.173.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 21:47:35.097108 2026] [security2:error] [pid 25268:tid 25268] [client 35.205.173.27:32838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.zeet.es"] [uri "/wordpress/.git/config"] [unique_id "apjRtzUvOFdEjNNp5PbpSgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-02 23:40:47
(11 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /public/.git/config (+11 more) | 2026-09-02 23:40 UTC
show less
Hacking
Web App Attack
🇫🇷
SpaceHost-Server
2026-09-02 22:23:07
(12 hours ago)
Brute-Force
Web App Attack
🇮🇪
AutosOnShow
2026-09-02 22:19:04
(12 hours ago)
blocked for webapp attack | path requested: /.git/config | seen at 2026-09-02 22:18:31.849 |
Web App Attack
🇳🇱
tpjg
2026-09-02 20:55:36
(13 hours ago)
Automated: 15 requests with error status in 120s window from 35.205.173.27.
Evidence: /site/.git/con ...
show more
Automated: 15 requests with error status in 120s window from 35.205.173.27.
Evidence: /site/.git/config:301,/html/.git/config:301,/backend/.git/config:301,/htdocs/.git/config:404,/api/.git/config:404,/public/.git/config:404,/www/.git/config:404,/wordpress/.git/config:404,/var/www/.git/config:404,/site/.git/config:404,/app/.git/config:404,/src/.git/config:404,/.git/config:404,/backend/.git/config:404,/html/.git/config:404
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 19:20:10
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.205.173.27 (27.173.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.173.27 (27.173.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 15:20:02.128133 2026] [security2:error] [pid 26926:tid 26926] [client 35.205.173.27:60940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "greatwesternfirearms.deubellzebub.com"] [uri "/api/.git/config"] [unique_id "aph24pr2Okn98ZIkq6B1HwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 13:03:32
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.205.173.27 (27.173.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.173.27 (27.173.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 09:03:25.945487 2026] [security2:error] [pid 22788:tid 22788] [client 35.205.173.27:42308] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lifebooksource.teamspiro.com"] [uri "/backend/.git/config"] [unique_id "apgenfPjJafej6GZLYcNqwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-02 06:06:21
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.205.173.27 (BE/Belgium/27.173.205. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.205.173.27 (BE/Belgium/27.173.205.35.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-02 06:04:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.205.173.27 (27.173.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.173.27 (27.173.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 02:04:49.904859 2026] [security2:error] [pid 27471:tid 27476] [client 35.205.173.27:54256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.azproshows.com"] [uri "/htdocs/.git/config"] [unique_id "ape8gZADqdVK4fdVbLYcWwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
macrob
2026-09-02 05:24:16
(1 day ago)
2026/09/02 05:24:15 [error] 2938917#2938917: *546818614 access forbidden by rule, client: 35.205.173 ...
show more
2026/09/02 05:24:15 [error] 2938917#2938917: *546818614 access forbidden by rule, client: 35.205.173.27, server: fn.binixo.es, request: "GET /.git/config HTTP/2.0", host: "mail2.fastcredit.net.ua"
2026/09/02 05:24:15 [error] 2938917#2938917: *546818615 access forbidden by rule, client: 35.205.173.27, server: fn.binixo.es, request: "GET /src/.git/config HTTP/2.0", host: "mail2.fastcredit.net.ua"
2026/09/02 05:24:15 [error] 2938917#2938917: *546818614 access forbidden by rule, client: 35.205.173.27, server: fn.binixo.es, request: "GET /app/.git/config HTTP/2.0", host: "mail2.fastcredit.net.ua"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 03:42:13
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.205.173.27 (27.173.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.173.27 (27.173.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 23:42:05.784545 2026] [security2:error] [pid 8702:tid 8702] [client 35.205.173.27:57818] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "donshotrodshop.net"] [uri "/wordpress/.git/config"] [unique_id "apebDQ7RSD1eiKR6p0lzNwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-02 02:07:29
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 01:06:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.205.173.27 (27.173.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.173.27 (27.173.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 21:06:38.390665 2026] [security2:error] [pid 11795:tid 11795] [client 35.205.173.27:51464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.pundtlaw.com"] [uri "/public/.git/config"] [unique_id "apd2nmH-iJ_qGpevvpqRCQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack