๐ณ๐ฑ
Savvii
2026-09-11 18:17:41
(1 hour ago)
20 attempts against mh-misbehave-ban on pyrus
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 14:23:35
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.162.160 (160.162.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.162.160 (160.162.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 10:23:29.165813 2026] [security2:error] [pid 2628:tid 2628] [client 35.220.162.160:52038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.magiccarpentry.com.citystreetsalon.com"] [uri "/.git/config"] [unique_id "aqQO4dqwY7R0atTT2XVwSAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 13:54:52
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.162.160 (160.162.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.162.160 (160.162.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 09:54:44.904444 2026] [security2:error] [pid 32619:tid 32619] [client 35.220.162.160:60064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.magicalgirlcrafts.com.ketsuri.com"] [uri "/.git/config"] [unique_id "aqQIJKP_eSEaZdALEbtiqwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 13:21:42
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.162.160 (160.162.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.162.160 (160.162.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 09:21:35.029202 2026] [security2:error] [pid 10116:tid 10116] [client 35.220.162.160:44734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.magiapedia.magodarman.com"] [uri "/.git/config"] [unique_id "aqQAX6ykf6ylvDWvfb5iFwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
JaRoNL
2026-09-11 12:46:05
(7 hours ago)
35.220.162.160 - - \[10/Sep/2026:22:41:41 +0200\] "GET /.git/config HTTP/1.1" 301 620 "-" "Mozilla/5 ...
show more
35.220.162.160 - - \[10/Sep/2026:22:41:41 +0200\] "GET /.git/config HTTP/1.1" 301 620 "-" "Mozilla/5.0 \(X11\; Linux x86_64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/131.0.0.0 Safari/537.36"
35.220.162.160 - - \[10/Sep/2026:22:41:41 +0200\] "GET /.env HTTP/1.1" 301 620 "-" "Mozilla/5.0 \(X11\; Linux x86_64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/131.0.0.0 Safari/537.36"
35.220.162.160 - - \[10/Sep/2026:22:41:41 +0200\] "GET /.env.local HTTP/1.1" 301 620 "-" "Mozilla/5.0 \(X11\; Linux x86_64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-11 12:19:58
(7 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฟ๐ฆ
conure.sh
2026-09-11 12:08:46
(7 hours ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 2s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 12:08:32
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.162.160 (160.162.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.162.160 (160.162.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 08:08:24.195336 2026] [security2:error] [pid 23220:tid 23220] [client 35.220.162.160:51950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.magento.fritsknuf.com"] [uri "/.git/config"] [unique_id "aqPvOGx6yc3Z85_OiFBAnQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 10:48:13
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.162.160 (160.162.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.162.160 (160.162.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 06:48:09.164935 2026] [security2:error] [pid 480:tid 480] [client 35.220.162.160:42592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.magazine.angelabcomics.com"] [uri "/.git/config"] [unique_id "aqPcafkj59Cot0oGfBOSvwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
palla89
2026-09-11 10:02:38
(9 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.220.162.160 (HK/Hong Kong/160.162.22 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.220.162.160 (HK/Hong Kong/160.162.220.35.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
paissangroup
2026-09-11 08:29:56
(11 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-11 08:26:05
(11 hours ago)
Bot / scanning and/or hacking attempts: GET /.env.development HTTP/1.1, GET /.env.docker HTTP/1.1, G ...
show more
Bot / scanning and/or hacking attempts: GET /.env.development HTTP/1.1, GET /.env.docker HTTP/1.1, GET /.env.example HTTP/1.1, GET /.env.dev HTTP/1.1, GET /.env.stage HTTP/1.1, POST / HTTP/1.1, GET /.env.old HTTP/1.1, GET /.env.sample HTTP/1.1, GET /.env.backup HTTP/1.1, GET /.env.ci HTTP/1.1, GET /.env.bak HTTP/1.1, GET /.env HTTP/1.1, GET /.env.prod HTTP/1.1
show less
Hacking
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-11 07:47:10
(12 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-11 06:43:10
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.162.160 (160.162.220.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.162.160 (160.162.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 02:43:02.696170 2026] [security2:error] [pid 19182:tid 19208] [client 35.220.162.160:60482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.madring.click.venezuelaguia.com"] [uri "/.git/config"] [unique_id "aqOi9j16FaP53i3hIAqfcQAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
myintarweb
2026-09-11 05:14:53
(14 hours ago)
35.220.162.160 - - [11/Sep/2026:06:14:52 +0100] 443 "GET /.git/config HTTP/1.1" 301 1732 "-" "Mozill ...
show more
35.220.162.160 - - [11/Sep/2026:06:14:52 +0100] 443 "GET /.git/config HTTP/1.1" 301 1732 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Hacking
Bad Web Bot
Web App Attack