๐บ๐ธ
TPI-Abuse
2026-09-23 21:55:35
(4 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.205.40.80 (80.40.205.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.40.80 (80.40.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:55:31.580727 2026] [security2:error] [pid 19498:tid 19498] [client 35.205.40.80:40666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cncservices.ws"] [uri "/api/.git/config"] [unique_id "arRK04aw6_vFymFOpht3ywAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
kkw
2026-09-23 20:07:30
(1 hour ago)
[REDACTED] 35.205.40.80 - - [23/Sep/2026:22:07:29 +0200] "GET /backend/.git/config HTTP/1.1" 404 455 ...
show more
[REDACTED] 35.205.40.80 - - [23/Sep/2026:22:07:29 +0200] "GET /backend/.git/config HTTP/1.1" 404 4555 "-" "crusader-worker/1.0"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-23 20:00:47
(1 hour ago)
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Endpoint: /src/.git/config
Timestamp: 2026-09-23T19:15:02Z
Ray ID: a3fbe0360b19d086
UA: crusader-worker/1.0
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-23 16:53:21
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.205.40.80 (80.40.205.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.40.80 (80.40.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 12:53:14.932014 2026] [security2:error] [pid 23244:tid 23244] [client 35.205.40.80:46216] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cameronbenefits.com"] [uri "/wordpress/.git/config"] [unique_id "arQD-vxcfUGq1oqHKMNDygAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 15:37:27
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.205.40.80 (80.40.205.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.40.80 (80.40.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 11:37:22.413795 2026] [security2:error] [pid 29485:tid 29485] [client 35.205.40.80:59810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "burningdownthevillger.com.tremulant.com"] [uri "/.git/config"] [unique_id "arPyMs0Ffvlz7ky7NP78kAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-23 11:11:05
(10 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
Anonymous
2026-09-23 10:59:58
(11 hours ago)
Web probing (48 hits in 24h) on beeldentuinrolduc.nl,default-vhost: sensitive-path scans and/or 404 ...
show more
Web probing (48 hits in 24h) on beeldentuinrolduc.nl,default-vhost: sensitive-path scans and/or 404 bursts. Reported by CRMON.
show less
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-23 10:54:03
(11 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
XICTRON
2026-09-23 09:55:06
(12 hours ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-23 08:10:02
(13 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ธ๐ช
nekopavel
2026-09-23 06:51:34
(15 hours ago)
35.205.40.80 - - [23/Sep/2026:08:51:32 +0200]"GET /site/.git/config HTTP/1.1" 404 146"-" autodiscove ...
show more
35.205.40.80 - - [23/Sep/2026:08:51:32 +0200]"GET /site/.git/config HTTP/1.1" 404 146"-" autodiscover.neko.chat "crusader-worker/1.0""0.001" "0.001""Brussels" "BE"
35.205.40.80 - - [23/Sep/2026:08:51:32 +0200]"GET /backend/.git/config HTTP/1.1" 404 146"-" autodiscover.neko.chat "crusader-worker/1.0""0.000" "0.001""Brussels" "BE"
35.205.40.80 - - [23/Sep/2026:08:51:32 +0200]"GET /htdocs/.git/config HTTP/1.1" 404 146"-" autodiscover.neko.chat "crusader-worker/1.0""0.001" "0.000""Brussels" "BE"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-23 06:10:10
(15 hours ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 05:06:41
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.205.40.80 (80.40.205.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.40.80 (80.40.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 01:06:37.952811 2026] [security2:error] [pid 890:tid 995] [client 35.205.40.80:41986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "atdotorg.org"] [uri "/.git/config"] [unique_id "arNeXYQ1mIPt79kvoK1jTgAAAVc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
infra-monitor
2026-09-23 05:00:09
(16 hours ago)
Automated ban via infra-monitor: mgmt-path-probe, suspicious-probe, crowdsecurity/http-probing, +1 m ...
show more
Automated ban via infra-monitor: mgmt-path-probe, suspicious-probe, crowdsecurity/http-probing, +1 more
show less
Port Scan
Web App Attack
Anonymous
2026-09-23 00:25:04
(21 hours ago)
suspicious request in access.log
Web App Attack