π¨π
TheCoon
2026-06-10 13:30:01
(2 months ago)
Automated: Credential theft attempt - JSON bomb served
Web App Attack
Hacking
π³π±
homeshowdomain.nl
2026-06-09 21:59:48
(2 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
π©πͺ
dklueh79
2026-06-09 15:27:34
(2 months ago)
Probe for vulnerabilities. Path attempted: /.git/config
Web App Attack
π³πΏ
Antinson
2026-06-09 13:56:24
(2 months ago)
Scraping with a high error ratio and request rate Requests to unauthorized or suspicious endpoints ( ...
show more
Scraping with a high error ratio and request rate Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-06-09 12:55:14
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 35.205.185.187 (187.185.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.185.187 (187.185.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 08:55:08.144703 2026] [security2:error] [pid 18945:tid 18945] [client 35.205.185.187:38340] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "canarysuites.com"] [uri "/.git/config"] [unique_id "aigNLEMcJLG8aR0nhGspqAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-06-09 11:23:33
(2 months ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 09:41:29
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 35.205.185.187 (187.185.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.185.187 (187.185.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 05:41:22.084126 2026] [security2:error] [pid 5458:tid 5458] [client 35.205.185.187:41808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "eantonie.com"] [uri "/.git/config"] [unique_id "aiffwksS0rncA1aUBzIQLgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 09:20:01
(2 months ago)
suspicious request in access.log
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 09:16:36
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 35.205.185.187 (187.185.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.185.187 (187.185.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 05:16:30.835673 2026] [security2:error] [pid 19658:tid 19658] [client 35.205.185.187:43454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.christadvent.com.keyston.net"] [uri "/.git/config"] [unique_id "aifZ7qdlmL4NGYocDmTDxQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 08:19:26
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 35.205.185.187 (187.185.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.185.187 (187.185.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 04:19:22.260297 2026] [security2:error] [pid 5598:tid 5598] [client 35.205.185.187:46550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arroceraomoa.com"] [uri "/.git/config"] [unique_id "aifMioCxFM-1Ll_HhCEkQgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 06:08:51
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 35.205.185.187 (187.185.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.185.187 (187.185.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 02:08:43.803410 2026] [security2:error] [pid 8755:tid 8755] [client 35.205.185.187:47228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ktnwassociatesinc.com"] [uri "/.git/config"] [unique_id "aiet6-tJCwPcHA1PJg-GJgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 05:50:29
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 35.205.185.187 (187.185.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.185.187 (187.185.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 01:50:26.036699 2026] [security2:error] [pid 14765:tid 14765] [client 35.205.185.187:42784] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "killeenbarrelsandtotes.com"] [uri "/.git/config"] [unique_id "aiepomwk6J9rHXKy534ptwAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 04:22:25
(2 months ago)
(mod_security) mod_security (id:949110) triggered by 35.205.185.187 (187.185.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 35.205.185.187 (187.185.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 00:22:22.059686 2026] [security2:error] [pid 3153:tid 3153] [client 35.205.185.187:33156] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "taxijunkremoval.com"] [uri "/.git/config"] [unique_id "aieU_gcWAQDmWDFzzySHAQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-09 02:31:21
(2 months ago)
(mod_security) mod_security (id:210492) triggered by 35.205.185.187 (187.185.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.185.187 (187.185.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 22:31:14.349199 2026] [security2:error] [pid 22683:tid 22683] [client 35.205.185.187:37392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yongmeihu.com"] [uri "/.git/config"] [unique_id "aid68jF1X-GbXHkgKQm9RAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
voormedia
2026-06-09 02:02:28
(2 months ago)
Accessed trap at '/.git/config'
Web App Attack