🇳🇱
homeshowdomain.nl
2026-09-04 21:59:19
(3 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-03.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 21:44:01
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.205.198.52 (52.198.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.198.52 (52.198.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:43:53.527031 2026] [security2:error] [pid 5416:tid 5416] [client 35.205.198.52:47448] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.synercom.org"] [uri "/html/.git/config"] [unique_id "aps7maO9DCpklY8vbzW2WQAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 21:33:59
(3 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.205.198.52 (BE/Belgium/52.198.205.35.bc.goog ...
show more
(mod_security) mod_security (id:949110) triggered by 35.205.198.52 (BE/Belgium/52.198.205.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:27:18
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.205.198.52 (52.198.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.198.52 (52.198.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:27:10.094934 2026] [security2:error] [pid 9130:tid 9130] [client 35.205.198.52:44556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.gegkal.com"] [uri "/src/.git/config"] [unique_id "aps3rqBzK-7RuLdVq5JlQAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 21:25:42
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 18:40:48
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.205.198.52 (52.198.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.198.52 (52.198.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 14:40:41.419372 2026] [security2:error] [pid 27267:tid 27267] [client 35.205.198.52:42294] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "geno-med.com.easternimport.com"] [uri "/www/.git/config"] [unique_id "apsQqVJy89kHitAm1TjdLQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
yvoictra
2026-09-04 09:07:14
(16 hours ago)
35.205.198.52 - - [04/Sep/2026:11:07:14 +0200] "GET /public/.git/config HTTP/1.1" 404 14 "-" "crusad ...
show more
35.205.198.52 - - [04/Sep/2026:11:07:14 +0200] "GET /public/.git/config HTTP/1.1" 404 14 "-" "crusader-worker/1.0"
35.205.198.52 - - [04/Sep/2026:11:07:14 +0200] "GET /www/.git/config HTTP/1.1" 404 14 "-" "crusader-worker/1.0"
35.205.198.52 - - [04/Sep/2026:11:07:14 +0200] "GET /api/.git/config HTTP/1.1" 404 14 "-" "crusader-worker/1.0"
35.205.198.52 - - [04/Sep/2026:11:07:14 +0200] "GET /wordpress/.git/config HTTP/1.1" 404 14 "-" "crusader-worker/1.0"
35.205.198.52 - - [04/Sep/2026:11:07:14 +0200] "GET /var/www/.git/config HTTP/1.1" 404 14 "-" "crusader-worker/1.0"
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:27:10
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.205.198.52 (52.198.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.198.52 (52.198.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:27:05.814876 2026] [security2:error] [pid 2466:tid 2466] [client 35.205.198.52:57196] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.winchesterbayvacationrentals.com"] [uri "/app/.git/config"] [unique_id "appyyTE50NH7dKipOqsTFAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 05:36:26
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.205.198.52 (52.198.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.198.52 (52.198.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:36:17.862066 2026] [security2:error] [pid 3554:tid 3554] [client 35.205.198.52:41940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theledman.com"] [uri "/html/.git/config"] [unique_id "appY0T1C_2YlSBVXlUEo5gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Marc
2026-09-04 03:35:23
(21 hours ago)
35.205.198.52 - - [04/Sep/2026:05:35:23 +0200] "GET /htdocs/.git/config HTTP/1.1" 404 4617 "-" "crus ...
show more
35.205.198.52 - - [04/Sep/2026:05:35:23 +0200] "GET /htdocs/.git/config HTTP/1.1" 404 4617 "-" "crusader-worker/1.0" 35.205.198.52 - - [04/Sep/2026:05:35:23 +0200] "GET /src/.git/config HTTP/1.1" 404 4617 "-" "crusader-worker/1.0" 35.205.198.52 - - [04/Sep/2026:05:35:23 +0200] "GET /www/.git/config HTTP/1.1" 404 4616 "-" "crusader-worker/1.0"
show less
Brute-Force
🇫🇷
✨
2026-09-04 01:05:12
(1 day ago)
Domain : uktt.info
Rule : config
2026-09-04 01:03:25 ***hidden-privacy*** GET /var/www/.git/config - ...
show more
Domain : uktt.info
Rule : config
2026-09-04 01:03:25 ***hidden-privacy*** GET /var/www/.git/config - 443 - 35.205.198.52 HTTP/1.1 crusader-worker/1.0 - uktt.info 404 8 0 1330 100 14 - -
show less
Hacking
SQL Injection
🇺🇦
URAN Publishing Service
2026-09-03 17:53:22
(1 day ago)
[03/Sep/2026:20:53:22 +0300] -- 35.205.198.52 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[03/Sep/2026:20:53:22 +0300] -- 35.205.198.52 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 16:18:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.205.198.52 (52.198.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.198.52 (52.198.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 12:18:24.942610 2026] [security2:error] [pid 5998:tid 5998] [client 35.205.198.52:45104] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.abecasis.com"] [uri "/src/.git/config"] [unique_id "apmd0OemUif57blzxon1KwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
leo1305
2026-09-03 15:34:01
(1 day ago)
CrowdSec detection | scenario: http-probing
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 09:31:42
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.205.198.52 (52.198.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.198.52 (52.198.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 05:31:38.184901 2026] [security2:error] [pid 15524:tid 15524] [client 35.205.198.52:37208] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "900west.com"] [uri "/.git/config"] [unique_id "apk-enLgi1KQv7CIiTLRbQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack