🇺🇸
dot.mg
2026-09-07 09:29:03
(1 hour ago)
Bad behaviour
Web Spam
🇺🇸
TPI-Abuse
2026-09-07 08:27:33
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.156.209 (209.156.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.156.209 (209.156.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:27:28.347090 2026] [security2:error] [pid 27994:tid 27994] [client 35.220.156.209:36852] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.idledog.abbeygardensllandudno.com"] [uri "/.git/config"] [unique_id "ap51cMlHxKVmZ68XKZWoGwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
Not Fake
2026-09-07 05:51:05
(4 hours ago)
$f2bV_matches
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 03:28:00
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.156.209 (209.156.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.156.209 (209.156.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 23:27:53.557684 2026] [security2:error] [pid 17371:tid 17371] [client 35.220.156.209:43872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.imc23.net.independentmusicconference.com"] [uri "/.git/config"] [unique_id "ap4vOW193o2sggiWuaggUwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
andypiper
2026-09-07 01:00:49
(9 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇫🇷
masterguru
2026-09-07 00:15:22
(10 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 22:46:56
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.156.209 (209.156.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.156.209 (209.156.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:46:47.575186 2026] [security2:error] [pid 22073:tid 22073] [client 35.220.156.209:56546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.imaginationbyme.com.swhinc.net"] [uri "/.git/config"] [unique_id "ap3tVy716h8HkpBLmirwuwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-06 22:01:24
(12 hours ago)
Auto-ban: >3000 req/min op 2026-09-06
Web App Attack
SSH
Hacking
🇫🇷
Stara
2026-09-06 21:27:41
(13 hours ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
SSH
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 21:20:09
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.220.156.209 (209.156.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.220.156.209 (209.156.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:20:05.702378 2026] [security2:error] [pid 19530:tid 19530] [client 35.220.156.209:47400] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.imageries.quickasawink.org|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.imageries.quickasawink.org"] [uri "/.env.bak"] [unique_id "ap3ZBTt5iiE8g2MGgBQNmQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
polycoda
2026-09-06 20:34:11
(14 hours ago)
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based ...
show more
AutoBlock: 🎯 Vulnerability Scanner (Non Decay-Based) - ⚙️ Configuration File Access (Non Decay-Based) - ↪️ Excessive 30X Errors (Decay-Based)
show less
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 19:38:39
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.156.209 (209.156.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.156.209 (209.156.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:38:31.951481 2026] [security2:error] [pid 27270:tid 27270] [client 35.220.156.209:46996] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.imabee.andrsn.com"] [uri "/.git/config"] [unique_id "ap3BNwtDJLbhuQnn2W_1iwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
Inartis
2026-09-06 18:33:09
(16 hours ago)
35.220.156.209 - - [06/Sep/2026:20:33:08 +0200] "GET /.git/config HTTP/1.1" 404 418 "-" "Mozilla/5.0 ...
show more
35.220.156.209 - - [06/Sep/2026:20:33:08 +0200] "GET /.git/config HTTP/1.1" 404 418 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-06 18:09:17
(16 hours ago)
29.671 requests in 1 hour (3mos5d19h)
Brute-Force
Bad Web Bot
Anonymous
2026-09-06 17:57:25
(16 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack