๐ซ๐ท
abuseipdb.amaze321
2026-07-28 18:39:02
(35 minutes ago)
Automated reconnaissance: repeated requests for sensitive/non-existent paths.
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-28 18:27:35
(47 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.227.35.85 (85.35.227.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.35.85 (85.35.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 14:27:29.392472 2026] [security2:error] [pid 1253173:tid 1253173] [client 35.227.35.85:59776] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "threewild.com"] [uri "/.git/config"] [unique_id "amj0kW3Kn5MgyxBmupzKrgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-07-28 18:22:13
(52 minutes ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure. Observed by 1 sensor(s); 2 hits.
show less
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-07-28 18:10:06
(1 hour ago)
(mod_security) mod_security (id:949110) triggered by 35.227.35.85 (US/United States/85.35.227.35.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 35.227.35.85 (US/United States/85.35.227.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 18:08:43
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.227.35.85 (85.35.227.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.35.85 (85.35.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 14:08:36.301682 2026] [security2:error] [pid 2519486:tid 2519486] [client 35.227.35.85:37660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thorhauer.com"] [uri "/.git/config"] [unique_id "amjwJB07moebYcoU-kMj4gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-07-28 18:05:25
(1 hour ago)
Abuse Detected (14)
Brute-Force
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-07-28 17:55:40
(1 hour ago)
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 35.227.35.85 - - [28/Jul/202 ...
show more
Plesk Fail2Ban jail: Plesk-Web-Exploits. Evidence: default-10-0-0-4:443 35.227.35.85 - - [28/Jul/2026:20:55:39 +0300] "GET /.git/config HTTP/1.1" 403 2426 "-" "-"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 17:53:25
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.227.35.85 (85.35.227.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.35.85 (85.35.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 13:53:19.586799 2026] [security2:error] [pid 3561683:tid 3561683] [client 35.227.35.85:45550] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thn.bz"] [uri "/.git/config"] [unique_id "amjsj652jye_000pcYtFtQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-07-28 17:48:56
(1 hour ago)
cloudlinux2 fail2ban: 2026-07-28 19:43:55,276 fail2ban.filter [1917]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-07-28 19:43:55,276 fail2ban.filter [1917]: INFO [plesk-modsecurity] Found 103.73.101.103 - 2026-07-28 19:43:55cloudlinux2 fail2ban: 2026-07-28 19:43:54,108 fail2ban.filter [1917]: INFO [plesk-modsecurity] Found 91.74.70.56 - 2026-07-28 19:43:54cloudlinux2 fail2ban: 2026-07-28 19:43:55,349 fail2ban.filter [1917]: INFO [recidive] Found 103.73.101.103 - 2026-07-28 19:43:55cloudlinux2 fail2ban: 2026-07-28 19:43:55,343 fail2ban.actions [1917]: NOTICE [plesk-modsecurity] Ban 103.73.101.103cloudlinux2 fail2ban: 2026-07-28 19:44:17,641 fail2ban.filter [1917]: INFO [plesk-wordpress] Found 196.245.149.236 - 2026-07-28 19:44:16cloudlinux2 fail2ban: 2026-07-28 19:44:54,908 fail2ban.filter [1917]: INFO [plesk-modsecurity] Found 35.227.35.85 - 2026-07-28 19:44:54cloudlinux2 fail2ban: 2026-07-28 19:44:59,823 fail2ban.filter [1917]: INFO [plesk-wordpress] Found 185.165.29.159 - 2026-07-28 19:44:59cloudlinux2 fail2ban: 2026-07
show less
Web App Attack
๐ฉ๐ช
Blexyel
2026-07-28 17:44:42
(1 hour ago)
35.227.35.85 - - [28/Jul/2026:19:44:40 +0200] "GET /.git/config HTTP/1.1" 404 14 "-" "-"
...
Brute-Force
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-07-28 17:32:07
(1 hour ago)
Try to access /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 17:30:09
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.227.35.85 (85.35.227.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.35.85 (85.35.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 13:30:01.556720 2026] [security2:error] [pid 2101346:tid 2101346] [client 35.227.35.85:53402] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thinksite.net"] [uri "/.git/config"] [unique_id "amjnGUBYSqfnsqtI7uHspgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 17:08:44
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.35.85 (85.35.227.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.35.85 (85.35.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 13:08:36.201473 2026] [security2:error] [pid 1880425:tid 1880425] [client 35.227.35.85:56570] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theyoungstrategist.com"] [uri "/.git/config"] [unique_id "amjiFEi7MuQFDMbjFpOAvAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-28 16:51:46
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.35.85 (85.35.227.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.35.85 (85.35.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 28 12:51:39.368229 2026] [security2:error] [pid 2087217:tid 2087217] [client 35.227.35.85:45472] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thewhispertwins.com"] [uri "/.git/config"] [unique_id "amjeG3Nl-PFchATWDPCxZwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-07-28 16:50:13
(2 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack