🇺🇸
TPI-Abuse
2026-09-15 13:31:38
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.95.31 (31.95.228.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.95.31 (31.95.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 09:31:33.528365 2026] [security2:error] [pid 1019122:tid 1019122] [client 35.228.95.31:50642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "interior-cosmetics.com"] [uri "/.git/config"] [unique_id "aqlIte_-9vpBk6LLRlxdUQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-15 11:14:41
(6 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-15 11:14 UTC
show less
Hacking
Web App Attack
🇳🇱
middelkoopcc
2026-09-15 11:12:11
(6 hours ago)
2026-09-15 13:10:00 GET /.git/config [404] && 2026-09-15 13:10:01 GET /.env [404] && 2026-09-15 13:1 ...
show more
2026-09-15 13:10:00 GET /.git/config [404] && 2026-09-15 13:10:01 GET /.env [404] && 2026-09-15 13:10:04 GET /.env.bak [404] && 120 more within 20 minutes
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 09:26:00
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.95.31 (31.95.228.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.95.31 (31.95.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 05:25:55.504127 2026] [security2:error] [pid 21047:tid 21047] [client 35.228.95.31:42844] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intergeovial.com"] [uri "/.git/config"] [unique_id "aqkPI431UAOGoeP7IoXYlgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 08:44:40
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.95.31 (31.95.228.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.95.31 (31.95.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 04:44:32.752218 2026] [security2:error] [pid 29625:tid 29625] [client 35.228.95.31:48810] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "intergalactichuman.com"] [uri "/.git/config"] [unique_id "aqkFcPBPsAbk8yppzMfJwwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 07:54:38
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.95.31 (31.95.228.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.95.31 (31.95.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 03:54:30.034310 2026] [security2:error] [pid 1702:tid 1702] [client 35.228.95.31:56230] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "interforce.com"] [uri "/.git/config"] [unique_id "aqj5thyKIkJeIkWZiSnXBQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 07:20:02
(10 hours ago)
suspicious request in access.log
Web App Attack
🇳🇱
Site.eu
2026-09-15 06:18:02
(11 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-15 05:53:23
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.95.31 (31.95.228.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.95.31 (31.95.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 01:53:16.577079 2026] [security2:error] [pid 18448:tid 18448] [client 35.228.95.31:60442] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daddysmilkclub.com"] [uri "/.git/config"] [unique_id "aqjdTPFawZJRlYH4qWAswgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-15 05:11:18
(12 hours ago)
Try to access /.git/config
Web App Attack
🇧🇷
SOC Blue Team
2026-09-14 11:25:56
(1 day ago)
IPs get by Hunting on SIEM
Phishing
Web Spam
Port Scan
Hacking
🇺🇸
CBJ
2026-09-14 10:02:32
(1 day ago)
fail2ban: apache-proxy
...
Web App Attack
Anonymous
2026-09-14 10:01:54
(1 day ago)
Fail2Ban Log Report 35.228.95.31 - [14/Sep/2026:12:01:52 +0200] "\x16\x03\x01\x00M\x01\x00\x00I\x03\ ...
show more
Fail2Ban Log Report 35.228.95.31 - [14/Sep/2026:12:01:52 +0200] "\x16\x03\x01\x00M\x01\x00\x00I\x03\x03\xB3\xCA\xAC\x9F\xA79\xE4a\xBF\xBCx&\xED\x9A\xD6x\x5C \xAB\xEE\x7F9\xE4\x8E\xE9_\xF6S\x8E\xEA\xB9~ \xC7\x9C5,\x84\xD0\xA486\x08L\xA4N\xD3\xD2\xC9\xDB\xE3\xF1\xCC" 403 146 "-" "-" "-" "-"
...
show less
Port Scan
Hacking
🇩🇪
Lino Project
2026-09-14 09:54:16
(1 day ago)
35.228.95.31 - - [14/Sep/2026:11:54:13 +0200] "\x16\x03\x01" 400 392 "-" "-"
...
Blog Spam
🇳🇴
jad-abuse
2026-09-14 09:52:03
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: tls_scann ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: tls_scanner. Observed by 1 sensor(s); 2 hits.
show less
Port Scan
Bad Web Bot