Anonymous
2026-09-02 09:22:51
(6 minutes ago)
35.228.219.27 - - [02/Sep/2026:17:22:51 +0800] "GET /.git/config HTTP/1.1" 301 236 "-" "Mozilla/5.0 ...
show more
35.228.219.27 - - [02/Sep/2026:17:22:51 +0800] "GET /.git/config HTTP/1.1" 301 236 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-02 08:50:10
(39 minutes ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-02 08:46:49
(42 minutes ago)
35.228.219.27 - - [02/Sep/2026:10:46:46 +0200] "GET /.env.docker HTTP/1.1" 404 510 "-" "Mozilla/5.0 ...
show more
35.228.219.27 - - [02/Sep/2026:10:46:46 +0200] "GET /.env.docker HTTP/1.1" 404 510 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.228.219.27 - - [02/Sep/2026:10:46:46 +0200] "GET /.env.live HTTP/1.1" 404 510 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.228.219.27 - - [02/Sep/2026:10:46:46 +0200] "GET /.env.preprod HTTP/1.1" 404 510 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.228.219.27 - - [02/Sep/2026:10:46:46 +0200] "GET /.env.uat HTTP/1.1" 404 510 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.228.219.27 - - [02/Sep/2026:10:46:46 +0200] "GET /.env.dist HTTP/1.1" 404 510 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chr
show less
Web App Attack
Hacking
๐ซ๐ท
masterguru
2026-09-02 08:35:42
(54 minutes ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-02 08:22:39
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.228.219.27 (27.219.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.219.27 (27.219.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 04:22:31.794496 2026] [security2:error] [pid 14273:tid 14273] [client 35.228.219.27:42568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.novoventanet.scala-global.com"] [uri "/.git/config"] [unique_id "apfcx-Dd-E-8l267wEmhhgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 06:05:07
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.219.27 (27.219.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.219.27 (27.219.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 02:05:00.536311 2026] [security2:error] [pid 5542:tid 5542] [client 35.228.219.27:48022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.noviasaltovacio.com.spyasociados.com"] [uri "/.git/config"] [unique_id "ape8jKnPll8VtvxhrmWyIwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 05:45:12
(3 hours ago)
Bot / seems abusive / Apache connections: 27
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 03:35:33
(5 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐จ๐ฟ
ddw
2026-09-02 03:09:03
(6 hours ago)
ModSecurity detection - Rules: 930130(Restricted File Access Attempt)
Web App Attack
Anonymous
2026-09-02 02:45:03
(6 hours ago)
suspicious request in access.log
Web App Attack
๐ซ๐ท
masterguru
2026-09-02 02:33:58
(6 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐ฉ๐ช
LRob
2026-09-02 00:36:28
(8 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+3 more) | 2026-09-02 00:36 UTC
show less
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-01 22:57:20
(10 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฌ๐ง
Yosi
2026-09-01 22:24:53
(11 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-01 22:04:33
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.219.27 (27.219.228.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.219.27 (27.219.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 18:04:25.789326 2026] [security2:error] [pid 16505:tid 16505] [client 35.228.219.27:60740] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.notrucking.nodepot.com"] [uri "/.git/config"] [unique_id "apdL6Tr4jUDoiwCUNuTE8gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack