๐บ๐ธ
TPI-Abuse
2026-09-16 04:36:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.221.235.91 (91.235.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.235.91 (91.235.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 00:36:10.792208 2026] [security2:error] [pid 28145:tid 28163] [client 35.221.235.91:42338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.41bravo.workconfident.com"] [uri "/.git/config"] [unique_id "aqocukw83iIsP2vFvOya_QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Viveronese
2026-09-16 04:15:58
(1 day ago)
HTTP vulnerability scanning
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 03:21:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.221.235.91 (91.235.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.235.91 (91.235.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:21:53.978740 2026] [security2:error] [pid 3546:tid 3546] [client 35.221.235.91:54428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.4115.abecasis.com"] [uri "/.git/config"] [unique_id "aqoLUZMLyueewqsfMau0IAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-16 03:10:26
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 03:02:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.221.235.91 (91.235.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.235.91 (91.235.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:02:28.187635 2026] [security2:error] [pid 25241:tid 25241] [client 35.221.235.91:45382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.40svocaltrio.com.flashbackmusicmemories.com"] [uri "/.git/config"] [unique_id "aqoGxFDnoZomuUZH-CWergAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-16 00:00:30
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ฒ๐พ
Rizzy
2026-09-15 23:12:11
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 22:07:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.221.235.91 (91.235.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.235.91 (91.235.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:07:20.669410 2026] [security2:error] [pid 10110:tid 10155] [client 35.221.235.91:40134] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.3stepreviewforyou.docdalton.com"] [uri "/.git/config"] [unique_id "aqnBmEZN2yvv0-cWqNYSQQAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-15 22:01:29
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-15
Web App Attack
SSH
Hacking
๐ฉ๐ช
snhosting
2026-09-15 21:52:26
(1 day ago)
35.221.235.91 - - [15/Sep/2026:23:52:16 +0200] "GET /.git/config HTTP/1.1" 200 1628 "-" "Mozilla/5.0 ...
show more
35.221.235.91 - - [15/Sep/2026:23:52:16 +0200] "GET /.git/config HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.221.235.91 - - [15/Sep/2026:23:52:16 +0200] "GET /.env HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.221.235.91 - - [15/Sep/2026:23:52:16 +0200] "GET /.env.local HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.221.235.91 - - [15/Sep/2026:23:52:17 +0200] "GET /.env.production HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.221.235.91 - - [15/Sep/2026:23:52:17 +0200] "GET /.env.staging HTTP/1.1" 200 1628 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/5
...
show less
DNS Compromise
DNS Poisoning
Phishing
Email Spam
Brute-Force
Web App Attack
SSH
๐บ๐ธ
Lee Daniel
2026-09-15 21:29:39
(1 day ago)
35.221.235.91 - - [15/Sep/2026:17:29:38 -0400] "GET /.env HTTP/1.1" 403 6319 "-" "Mozilla/5.0 (Macin ...
show more
35.221.235.91 - - [15/Sep/2026:17:29:38 -0400] "GET /.env HTTP/1.1" 403 6319 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 17:24:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.221.235.91 (91.235.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.235.91 (91.235.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:24:50.523719 2026] [security2:error] [pid 11594:tid 11594] [client 35.221.235.91:43850] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.coteaching.marveldirectory.com"] [uri "/.git/config"] [unique_id "aql_YlF34uJVFtQ7A9HL3gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-15 16:33:02
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-15 15:23:36
(1 day ago)
Web scanning / probing for vulnerable paths | URL: /current/.env | Evidence: 35.221.235.91 - - [15/S ...
show more
Web scanning / probing for vulnerable paths | URL: /current/.env | Evidence: 35.221.235.91 - - [15/Sep/2026:17:21:58 +0200] \"GET /current/.env HTTP/1.1\" 404 120500 \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=TW | ASN: GOOGLE-CLOUD-PLATFORM | Country: TW
show less
Port Scan
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-15 14:53:56
(1 day ago)
Excessive 404/403 errors
Brute-Force