🇩🇪
SCHAPPY
2026-09-06 04:21:24
(21 hours ago)
Brute-force attack to identify web exploits
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 02:23:15
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.169.120 (120.169.228.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.169.120 (120.169.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 22:23:09.404273 2026] [security2:error] [pid 5426:tid 5426] [client 35.228.169.120:44242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "randeen.com"] [uri "/src/.git/config"] [unique_id "apzOjRmYr-HSe2b63bcGYwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 00:24:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.228.169.120 (120.169.228.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.169.120 (120.169.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:24:21.206894 2026] [security2:error] [pid 8722:tid 8722] [client 35.228.169.120:46484] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webped.batw.net"] [uri "/wordpress/.git/config"] [unique_id "apyytUOW3M4cQoxpXGPvqwAAAIA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 22:11:54
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.228.169.120 (120.169.228.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.169.120 (120.169.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 18:11:48.345684 2026] [security2:error] [pid 11627:tid 11627] [client 35.228.169.120:33488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.portelizabeth.jbaycabs.com"] [uri "/.git/config"] [unique_id "apyTpOOMJ6VwJzpX3ETJHQAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Operator873
2026-09-05 21:49:27
(1 day ago)
2026/09/05 16:49:24 [error] 972340#0: *4190143 access forbidden by rule, client: 35.228.169.120, ser ...
show more
2026/09/05 16:49:24 [error] 972340#0: *4190143 access forbidden by rule, client: 35.228.169.120, server: [OBFUSCATED], request: "GET /html/.git/config HTTP/1.1", host: "[OBFUSCATED]"
2026/09/05 16:49:24 [error] 972340#0: *4190143 access forbidden by rule, client: 35.228.169.120, server: [OBFUSCATED], request: "GET /html/.git/config HTTP/1.1", host: "[OBFUSCATED]"
2026/09/05 16:49:24 [error] 972341#0: *4190144 access forbidden by rule, client: 35.228.169.120, server: [OBFUSCATED], request: "GET /app/.git/config HTTP/1.1", host: "[OBFUSCATED]"
2026/09/05 16:49:24 [error] 972341#0: *4190144 access forbidden by rule, client: 35.228.169.120, server: [OBFUSCATED], request: "GET /app/.git/config HTTP/1.1", host: "[OBFUSCATED]"
2026/09/05 16:49:24 [error] 972340#0: *4190145 access forbidden by rule, client: 35.228.169.120, server: [OBFUSCATED], request: "GET /.git/config HTTP/1.1", host: "[OBFUSCATED]"
...
show less
Brute-Force
Web App Attack
🇺🇸
IndigoRidge
2026-09-05 21:46:32
(1 day ago)
[05/Sep/2026:17:46:31.691737 --0400] apyNtypoDWFq8ni5eHpwRQAAAMw 35.228.169.120 58080 205.233.18.17 ...
show more
[05/Sep/2026:17:46:31.691737 --0400] apyNtypoDWFq8ni5eHpwRQAAAMw 35.228.169.120 58080 205.233.18.17 7081
[05/Sep/2026:17:46:31.691923 --0400] apyNtw25qZDSiHcFNQRLzAAAAEY 35.228.169.120 58094 205.233.18.17 7081
[05/Sep/2026:17:46:31.692918 --0400] apyNtw25qZDSiHcFNQRLzQAAAE0 35.228.169.120 58108 205.233.18.17 7081
[05/Sep/2026:17:46:31.695084 --0400] apyNtx3ViE1vjLY9AfopkgAAA48 35.228.169.120 58122 205.233.18.17 7081
[05/Sep/2026:17:46:31.695522 --0400] apyNt@nkF3EQX2VX6UlfawAAAJE 35.228.169.120 58134 205.233.18.17 7081
...
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-05 21:44:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.228.169.120 (120.169.228.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.169.120 (120.169.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:44:13.248376 2026] [security2:error] [pid 23420:tid 23420] [client 35.228.169.120:34766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.landeagle.com"] [uri "/var/www/.git/config"] [unique_id "apyNLSBmlcs-qlIJZ9zFCwAAAFw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇬
nayumi
2026-09-05 07:37:36
(1 day ago)
CrowdSec detection: crowdsecurity/http-probing | Service: http, http, http, http, http, http, http, ...
show more
CrowdSec detection: crowdsecurity/http-probing | Service: http, http, http, http, http, http, http, http, http, http, http
show less
Web App Attack
🇳🇴
jad-abuse
2026-09-05 01:18:02
(2 days ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, scanner_ua. Observed by 1 sensor(s); 24 hits.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 23:02:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.228.169.120 (120.169.228.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.169.120 (120.169.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 19:02:44.929582 2026] [security2:error] [pid 28372:tid 28372] [client 35.228.169.120:43038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "register-yacht-dubai.com"] [uri "/htdocs/.git/config"] [unique_id "aptOFO0q1OeBIEO_ss5rBAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:39:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.228.169.120 (120.169.228.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.169.120 (120.169.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:39:02.027648 2026] [security2:error] [pid 29663:tid 29663] [client 35.228.169.120:41142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.zohartours.com"] [uri "/app/.git/config"] [unique_id "aps6dgcDnoEwA4LEp3wMKgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 20:37:02
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.228.169.120 (120.169.228.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.169.120 (120.169.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 16:36:55.093170 2026] [security2:error] [pid 4856:tid 4856] [client 35.228.169.120:45826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dinogirl.com"] [uri "/app/.git/config"] [unique_id "apsr5_K4EnegZ0Wn3BS_GgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 19:04:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.228.169.120 (120.169.228.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.169.120 (120.169.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 15:04:48.453895 2026] [security2:error] [pid 19219:tid 19219] [client 35.228.169.120:35940] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.astariafilms.com"] [uri "/app/.git/config"] [unique_id "apsWUOv9D9wzufQsMDtMHwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 17:15:02
(2 days ago)
suspicious request in access.log
Web App Attack
🇫🇷
dynamix
2026-09-04 16:59:21
(2 days ago)
Multiple WAF Violations
Web App Attack