๐บ๐ธ
TPI-Abuse
2026-09-24 05:18:08
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.220.252.62 (62.252.220.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.252.62 (62.252.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:18:00.566664 2026] [security2:error] [pid 7018:tid 7018] [client 35.220.252.62:57038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cthog.xyz"] [uri "/htdocs/.git/config"] [unique_id "arSyiGwfIb6EeRgEA1xeyAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 03:13:24
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.252.62 (62.252.220.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.252.62 (62.252.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 23:13:18.533412 2026] [security2:error] [pid 9429:tid 9429] [client 35.220.252.62:42946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.davidsonmanagement.net"] [uri "/app/.git/config"] [unique_id "arSVToj0XyzmaQrI6Q3xNAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-24 00:50:05
(5 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 00:48:52
(5 hours ago)
812 requests with url.path */.git/config
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-24 00:29:13
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.252.62 (62.252.220.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.252.62 (62.252.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:29:09.797595 2026] [security2:error] [pid 14911:tid 14911] [client 35.220.252.62:59462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.globalpackets.net"] [uri "/api/.git/config"] [unique_id "arRu1fUHkCsnoBpkOyQckQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-23 23:36:28
(6 hours ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.220.252.62 - - [24/Sep/2026:01:36:13 +0200] "GET /backend/.git/config HTTP/1.1" 403 6298 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-23 22:12:53
(8 hours ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /htdocs/.git/config (+11 more) | 2026-09-23 22:12 UTC
show less
Hacking
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-23 21:59:57
(8 hours ago)
Auto-ban: >3000 req/min op 2026-09-23
Web App Attack
SSH
Hacking
Anonymous
2026-09-23 17:18:50
(13 hours ago)
[server.tmg.gr] httpd-config-scan: sites=www.cardiology.eumedline.eu; logs=/var/log/httpd/domains/eu ...
show more
[server.tmg.gr] httpd-config-scan: sites=www.cardiology.eumedline.eu; logs=/var/log/httpd/domains/eumedline.eu.cardiology.log; samples=/site/.git/config | /wordpress/.git/config | /backend/.git/config
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 17:08:42
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.252.62 (62.252.220.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.252.62 (62.252.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 13:08:35.847603 2026] [security2:error] [pid 16818:tid 16818] [client 35.220.252.62:51872] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "capassoart.com"] [uri "/wordpress/.git/config"] [unique_id "arQHk8iV0v-ikRlrRGCoMAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 16:40:20
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.252.62 (62.252.220.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.252.62 (62.252.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 12:40:14.677663 2026] [security2:error] [pid 8274:tid 8274] [client 35.220.252.62:45408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "caleb.calebdavison.com"] [uri "/wordpress/.git/config"] [unique_id "arQA7pWKN3cY7QDiUwcfLQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-23 16:29:03
(14 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-23 14:50:02
(15 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 14:06:21
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.220.252.62 (62.252.220.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.220.252.62 (62.252.220.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 10:06:15.221556 2026] [security2:error] [pid 9157:tid 9157] [client 35.220.252.62:51960] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bonvivantorganics.com"] [uri "/public/.git/config"] [unique_id "arPc13ve30tOEnexmy2OKQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
Ribeye375
2026-09-23 05:49:26
(1 day ago)
HIPS web-exfiltration - Block tcp/0:65535
Web App Attack