🇺🇸
TPI-Abuse
2026-09-11 10:32:31
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.228.2.221 (221.2.228.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.2.221 (221.2.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 06:32:24.441202 2026] [security2:error] [pid 10592:tid 10592] [client 35.228.2.221:60824] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ngm.office-on-the.net.anthonyanimalclinic.net"] [uri "/.git/config"] [unique_id "aqPYuFdZgLBOQ87bS6UpwwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇿🇦
conure.sh
2026-09-11 08:27:30
(4 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 1s
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 08:21:32
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.2.221 (221.2.228.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.2.221 (221.2.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 04:21:25.999650 2026] [security2:error] [pid 7205:tid 7205] [client 35.228.2.221:55606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nflelectronics.com.tlambert.us"] [uri "/.git/config"] [unique_id "aqO6Ba99xmrr1pe7UM8PvgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 07:52:16
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.2.221 (221.2.228.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.2.221 (221.2.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 03:52:10.621403 2026] [security2:error] [pid 3011:tid 3011] [client 35.228.2.221:34542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nfc.magodarman.com"] [uri "/.git/config"] [unique_id "aqOzKr2ZvcqI9-GAMttlUQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 07:43:03
(4 hours ago)
35.228.2.221 - - [11/Sep/2026:09:42:56 +0200] "GET /.git/config HTTP/1.1" 403 612 "-" "Mozilla/5.0 ( ...
show more
35.228.2.221 - - [11/Sep/2026:09:42:56 +0200] "GET /.git/config HTTP/1.1" 403 612 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.228.2.221 - - [11/Sep/2026:09:42:57 +0200] "GET /.env HTTP/1.1" 403 612 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.228.2.221 - - [11/Sep/2026:09:42:57 +0200] "GET /.env.local HTTP/1.1" 403 612 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.228.2.221 - - [11/Sep/2026:09:42:57 +0200] "GET /.env.production HTTP/1.1" 403 612 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.228.2.221 - - [11/Sep/2026:09:42:57 +0200] "GET /.env.staging HTTP/1.1" 403 612 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrom
...
show less
DDoS Attack
🇳🇱
Savvii
2026-09-11 07:29:57
(4 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
screwlooseit.com.au
2026-09-11 06:43:28
(5 hours ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
221.2.228.35.bc.googleusercontent.com
Web App Attack
🇫🇷
masterguru
2026-09-11 03:50:27
(8 hours ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-11 03:48:44
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.2.221 (221.2.228.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.2.221 (221.2.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 23:48:38.280435 2026] [security2:error] [pid 9939:tid 9939] [client 35.228.2.221:40370] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.nextlevelcharge.savingshvac.com"] [uri "/.git/config"] [unique_id "aqN6Fq8h8OVKHoY2_hLKcAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 00:50:07
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.2.221 (221.2.228.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.2.221 (221.2.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 20:49:59.761161 2026] [security2:error] [pid 1274:tid 1274] [client 35.228.2.221:57884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lorlandinc.indie100.com"] [uri "/.git/config"] [unique_id "aqNQN0mUE20OjQ1RcuLZMgAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 00:11:31
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.2.221 (221.2.228.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.2.221 (221.2.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 20:11:21.432309 2026] [security2:error] [pid 25726:tid 25726] [client 35.228.2.221:46856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lordcain.cain2016.org"] [uri "/.git/config"] [unique_id "aqNHKRhs0Grf8XepanQfvQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
yvoictra
2026-09-11 00:06:00
(12 hours ago)
Bloqueado automáticamente por CrowdSec. Escenario: crowdsecurity/http-sensitive-files
Web App Attack
Anonymous
2026-09-10 21:05:02
(15 hours ago)
suspicious request in access.log
Web App Attack
🇳🇱
Site.eu
2026-09-10 14:43:02
(21 hours ago)
Excessive multi-domain requests
Brute-Force
🇸🇪
vaia.cloud
2026-09-10 14:20:01
(22 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack