🇿🇦
conure.sh
2026-09-02 12:09:25
(2 days ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 06:28:22
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.225.64.42 (42.64.225.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.225.64.42 (42.64.225.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 02:28:15.465910 2026] [security2:error] [pid 26341:tid 26341] [client 35.225.64.42:57504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/config.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "baysidechiropractic.net"] [uri "/app/config/config.yml"] [unique_id "apfB_25XtTvJYt2ag7ej8QAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 05:29:58
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.225.64.42 (42.64.225.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.225.64.42 (42.64.225.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 01:29:51.288116 2026] [security2:error] [pid 27677:tid 27677] [client 35.225.64.42:44364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.thepianosmith.com"] [uri "/api/.git/config"] [unique_id "ape0T0qFzt_R9l0_SF-5ZAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 04:57:03
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.225.64.42 (42.64.225.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.225.64.42 (42.64.225.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 00:56:55.214986 2026] [security2:error] [pid 27617:tid 27617] [client 35.225.64.42:48898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.dunningtons.com"] [uri "/wordpress/.git/config"] [unique_id "apesl2adT-PrCm-EEeei2AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Vegascosmetics
2026-09-02 03:46:30
(3 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.git (Match: /.git)
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-02 03:36:03
(3 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇬🇧
consul.to
2026-09-02 02:36:22
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 00:41:56
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.225.64.42 (42.64.225.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.225.64.42 (42.64.225.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 20:41:48.795006 2026] [security2:error] [pid 4660:tid 4660] [client 35.225.64.42:43570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.haisten.net"] [uri "/site/.git/config"] [unique_id "apdwzBr8AoSYx9yfpdzYrAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 00:33:12
(3 days ago)
Bot / seems abusive / Apache connections: 23
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇷🇴
iulianh
2026-09-01 21:36:45
(3 days ago)
80,443
Brute-Force
SSH
🇧🇬
HighWay
2026-09-01 21:33:03
(3 days ago)
35.225.64.42 - - [01/Sep/2026:21:32:53 +0000] "GET /htdocs/.git/config HTTP/1.1" 403 5738 "-" "crusa ...
show more
35.225.64.42 - - [01/Sep/2026:21:32:53 +0000] "GET /htdocs/.git/config HTTP/1.1" 403 5738 "-" "crusader-worker/1.0"
35.225.64.42 - - [01/Sep/2026:21:32:53 +0000] "GET /var/www/.git/config HTTP/1.1" 403 5738 "-" "crusader-worker/1.0"
35.225.64.42 - - [01/Sep/2026:21:32:53 +0000] "GET /.git/config HTTP/1.1" 403 5738 "-" "crusader-worker/1.0"
...
show less
Port Scan
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-01 21:15:48
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-01 20:36:54
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.225.64.42 (42.64.225.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.225.64.42 (42.64.225.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 16:36:48.920105 2026] [security2:error] [pid 8441:tid 8441] [client 35.225.64.42:44226] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daveclick.com"] [uri "/backend/.git/config"] [unique_id "apc3YGAtk9a3fqsV-Bp-agAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 18:54:43
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.225.64.42 (42.64.225.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.225.64.42 (42.64.225.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 14:54:36.832605 2026] [security2:error] [pid 19816:tid 19816] [client 35.225.64.42:44274] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nematoads.com"] [uri "/www/.git/config"] [unique_id "apcfbFxWWAccpynXT_3uGgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-01 18:32:02
(3 days ago)
Multiple WAF Violations
Web App Attack