🇺🇸
TPI-Abuse
2026-09-07 06:36:26
(28 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.220.142.13 (13.142.220.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.142.13 (13.142.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:36:19.304450 2026] [security2:error] [pid 16691:tid 16691] [client 35.220.142.13:53428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.iame-ubeu.johnandramonadunn.com"] [uri "/.git/config"] [unique_id "ap5bY3NicFKloOO40B4_kQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 04:14:06
(2 hours ago)
Multiple, malicious web requests detected
Port Scan
Hacking
🇺🇸
TPI-Abuse
2026-09-07 04:02:18
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.142.13 (13.142.220.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.142.13 (13.142.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 00:02:10.386946 2026] [security2:error] [pid 25273:tid 25375] [client 35.220.142.13:44130] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.iheb.org.aafm.us"] [uri "/.git/config"] [unique_id "ap43Qg-v8jLfElhPvSs99gAAAUQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-09-07 03:36:13
(3 hours ago)
Repeated exploit attempts, for example: /.env.production /.env (HTTP/1.1 port 443, user agent: "Mozi ...
show more
Repeated exploit attempts, for example: /.env.production /.env (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36")
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 02:22:42
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.142.13 (13.142.220.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.142.13 (13.142.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 22:22:36.887569 2026] [security2:error] [pid 18632:tid 18652] [client 35.220.142.13:44646] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.iguanablue.newleafpro.com"] [uri "/.git/config"] [unique_id "ap4f7LioqdKhRHDUEw02zwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
EGP Abuse Dept
2026-09-07 01:53:28
(5 hours ago)
Scanning for web/db/file exploits on www.igrotech.nl
SQL Injection
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-07 00:42:51
(6 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
🇫🇷
masterguru
2026-09-07 00:36:03
(6 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇺🇸
nyt
2026-09-06 23:50:51
(7 hours ago)
Sensitive File Probe
Web App Attack
🇨🇭
backslash
2026-09-06 21:48:00
(9 hours ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
🇳🇱
Site.eu
2026-09-06 19:21:05
(11 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-06 18:54:16
(12 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇳🇱
Site.eu
2026-09-06 17:54:06
(13 hours ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 17:00:44
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.142.13 (13.142.220.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.142.13 (13.142.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 13:00:36.839277 2026] [security2:error] [pid 20708:tid 20708] [client 35.220.142.13:41198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ifi.gabosoftware.com"] [uri "/.git/config"] [unique_id "ap2cNPLoXN-QwXuA4igG6QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
marten_o
2026-09-06 16:43:09
(14 hours ago)
35.220.142.13 - - [06/Sep/2026:18:43:08 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 500 576 "-" "Mozilla/ ...
show more
35.220.142.13 - - [06/Sep/2026:18:43:08 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 500 576 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 326 774
...
show less
Web App Attack