๐บ๐ธ
TPI-Abuse
2026-10-09 19:05:37
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.207.122.10 (10.122.207.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.207.122.10 (10.122.207.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:05:31.880518 2026] [security2:error] [pid 12025:tid 12025] [client 35.207.122.10:54586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.feaverslane.com"] [uri "/.git/config"] [unique_id "ask6-9zp0EQ0Si9Dos2ZOwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
clauss
2026-10-09 10:09:58
(16 hours ago)
35.207.122.10 - - [09/Oct/2026:13:09:57 +0300] "GET /.git/config HTTP/1.1" 401 36 "-" "Mozilla/5.0 ( ...
show more
35.207.122.10 - - [09/Oct/2026:13:09:57 +0300] "GET /.git/config HTTP/1.1" 401 36 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.207.122.10 - - [09/Oct/2026:13:09:57 +0300] "GET /.env.local HTTP/1.1" 401 36 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 08:32:57
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.207.122.10 (10.122.207.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.207.122.10 (10.122.207.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 04:32:53.103989 2026] [security2:error] [pid 9990:tid 9990] [client 35.207.122.10:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.empoweruamerica.org"] [uri "/.git/config"] [unique_id "asimtdWNP0ct2CCFaZ7lSQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-10-09 02:53:24
(23 hours ago)
[FriOct0904:53:17.6745522026][security2:error][pid3235120:tid3235133][client35.207.122.10:0]ModSecur ...
show more
[FriOct0904:53:17.6745522026][security2:error][pid3235120:tid3235133][client35.207.122.10:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpcalendars.ecosuber.com\"][uri\"/.env.bak\"][unique_id\"ashXHW1C8qYD6T9tmOmmVQAAAAE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 16:34:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.207.122.10 (10.122.207.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.207.122.10 (10.122.207.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 12:34:40.479813 2026] [security2:error] [pid 19488:tid 19488] [client 35.207.122.10:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.distro.media"] [uri "/.git/config"] [unique_id "asfGIKpMJk5yOlfHa3SlogAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 14:47:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.207.122.10 (10.122.207.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.207.122.10 (10.122.207.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 10:47:01.443230 2026] [security2:error] [pid 31909:tid 31909] [client 35.207.122.10:36070] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.diarrheawolves.com"] [uri "/.git/config"] [unique_id "ases5Yr3MJrwBHdkNnTTNwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-10-08 14:10:52
(1 day ago)
[ThuOct0816:10:50.3415132026][security2:error][pid2466877:tid2466899][client35.207.122.10:0]ModSecur ...
show more
[ThuOct0816:10:50.3415132026][security2:error][pid2466877:tid2466899][client35.207.122.10:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpcalendars.dgtime.ch\"][uri\"/.env.bak\"][unique_id\"asekatCkiLyxXKlFS7Q_fQAAAAc\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 12:01:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.207.122.10 (10.122.207.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.207.122.10 (10.122.207.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 08:01:23.176261 2026] [security2:error] [pid 15641:tid 15641] [client 35.207.122.10:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.dentguyvt.com"] [uri "/.git/config"] [unique_id "aseGE_afhEQexQ4cSizDNgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 11:42:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.207.122.10 (10.122.207.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.207.122.10 (10.122.207.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 07:41:58.497124 2026] [security2:error] [pid 32650:tid 32650] [client 35.207.122.10:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.demondomain.com"] [uri "/.git/config"] [unique_id "aseBhnoxemp2H35m4T5NXQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-10-08 09:04:18
(1 day ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 1s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 08:56:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.207.122.10 (10.122.207.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.207.122.10 (10.122.207.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 04:56:08.814217 2026] [security2:error] [pid 24565:tid 24565] [client 35.207.122.10:57842] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.davidsonmanagement.net"] [uri "/.git/config"] [unique_id "asdaqD1KqoB-GOoiJfw-SwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 07:16:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.207.122.10 (10.122.207.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.207.122.10 (10.122.207.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 03:16:27.729063 2026] [security2:error] [pid 22254:tid 22254] [client 35.207.122.10:41524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.damonmarks.com"] [uri "/.git/config"] [unique_id "asdDS1leWcnxaDp-A1LB1wAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-10-08 02:08:58
(2 days ago)
[ThuOct0804:08:51.8405572026][security2:error][pid1680767:tid1680891][client35.207.122.10:0]ModSecur ...
show more
[ThuOct0804:08:51.8405572026][security2:error][pid1680767:tid1680891][client35.207.122.10:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"cpcalendars.creazione-siti-web-ticino.ch\"][uri\"/.env.bak\"][unique_id\"asb7M6K5vNxulZ9-ymMmjQAAAQ0\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:13:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.207.122.10 (10.122.207.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.207.122.10 (10.122.207.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:13:05.383613 2026] [security2:error] [pid 27626:tid 27696] [client 35.207.122.10:38650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.cookmanufacturinggroup.com"] [uri "/.git/config"] [unique_id "asbSAfgS1v2pFZ0bcAY5aQAAANU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
rubixstudios
2026-10-07 23:10:02
(2 days ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack