๐จ๐ญ
4server
2026-09-11 15:51:30
(4 minutes ago)
[FriSep1117:51:23.9768452026][security2:error][pid3798371:tid3798591][client35.221.121.65:0]ModSecur ...
show more
[FriSep1117:51:23.9768452026][security2:error][pid3798371:tid3798591][client35.221.121.65:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.mdd-network.ch.81-17-25-250.cpanel.site\"][uri\"/.git/config\"][unique_id\"aqQjey6EABr5oWV4ezbTugAAAYo\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 14:44:21
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.221.121.65 (65.121.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.121.65 (65.121.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 10:44:18.276840 2026] [security2:error] [pid 24888:tid 24888] [client 35.221.121.65:59936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.md-ehr.drxcontent.com"] [uri "/.git/config"] [unique_id "aqQTwoAKkbZ9q3ggGRDvlQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
JaRoNL
2026-09-11 14:43:42
(1 hour ago)
35.221.121.65 - - [11/Sep/2026:16:43:41 +0200] "GET /.git/config HTTP/1.1" 301 357 "-" "Mozilla/5.0 ...
show more
35.221.121.65 - - [11/Sep/2026:16:43:41 +0200] "GET /.git/config HTTP/1.1" 301 357 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 14:06:25
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.221.121.65 (65.121.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.121.65 (65.121.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 10:06:17.427338 2026] [security2:error] [pid 6991:tid 6991] [client 35.221.121.65:54502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mctmtrade.com.easternimport.com"] [uri "/.git/config"] [unique_id "aqQK2Zrq6BBkRvkwD_LdjwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-11 13:28:56
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
cwytech
2026-09-11 12:52:25
(3 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: crowdsecurity/http-sensitive-files.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 12:40:27
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.121.65 (65.121.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.121.65 (65.121.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 08:40:23.963332 2026] [security2:error] [pid 1818790:tid 1819584] [client 35.221.121.65:34718] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mcp.fnaandpartners.com"] [uri "/.git/config"] [unique_id "aqP2t2gCXBINm1kzV-jHrgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-11 12:08:46
(3 hours ago)
csagent: score 19.9: secrets grab x2; 1 domain(s) in 2s
Web App Attack
๐บ๐ธ
MatCat
2026-09-11 10:05:09
(5 hours ago)
Banned by fail2ban: gitea
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 09:07:10
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.121.65 (65.121.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.121.65 (65.121.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 05:07:05.447719 2026] [security2:error] [pid 13542:tid 13542] [client 35.221.121.65:49558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mcgmcg.com.coolingsprings.org"] [uri "/.git/config"] [unique_id "aqPEuYndifoOVbIHDUQMXQAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-09-11 08:58:08
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.121.65 (JP/Japan/65.121.221.35.bc.google ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.121.65 (JP/Japan/65.121.221.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-11 08:06:36
(7 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 08:05:13
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.121.65 (65.121.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.121.65 (65.121.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 04:05:06.001428 2026] [security2:error] [pid 1768:tid 1768] [client 35.221.121.65:37962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mcdonalds.jbaydeliveries.com"] [uri "/.git/config"] [unique_id "aqO2Mk5hZZYVqrQ9b8EqigAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 06:17:34
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.121.65 (65.121.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.121.65 (65.121.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 02:17:28.018402 2026] [security2:error] [pid 18040:tid 18040] [client 35.221.121.65:43258] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mcbrude.com"] [uri "/.git/config"] [unique_id "aqOc-O-5Z_AsCTco3tGu4wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mcarthey
2026-09-11 05:52:01
(10 hours ago)
Automated honeypot report from mcarthey.com. 4 hits across 2 bait families (dotenv, git-config) in t ...
show more
Automated honeypot report from mcarthey.com. 4 hits across 2 bait families (dotenv, git-config) in the last 24h. Full log: https://mcarthey.com/Shame
show less
Bad Web Bot
Web App Attack