Anonymous
2026-09-02 11:00:00
(14 hours ago)
Automated web attack from 35.229.139.138 against our web server.
25 malicious requests on 2026-09-02 ...
show more
Automated web attack from 35.229.139.138 against our web server.
25 malicious requests on 2026-09-02 (UTC), denied with HTTP 403.
Sample request: GET /.git/config
Probed for: .git repository files.
User-Agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36".
rDNS 138.139.229.35.bc.googleusercontent.com; AS396982 GOOGLE-CLOUD-PLATFORM.
All timestamps are UTC.
show less
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-02 10:58:11
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.139.138 (138.139.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.139.138 (138.139.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 06:58:03.624243 2026] [security2:error] [pid 3259:tid 3286] [client 35.229.139.138:34392] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lasertagandgames.com"] [uri "/.git/config"] [unique_id "apgBO0yyq0IXAYWgql7wVAAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 10:37:25
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.139.138 (138.139.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.139.138 (138.139.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 06:37:19.911125 2026] [security2:error] [pid 28766:tid 28766] [client 35.229.139.138:19250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kittensquid.com"] [uri "/.git/config"] [unique_id "apf8X5XpCbqCceW0wJDXYQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 10:20:59
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.139.138 (138.139.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.139.138 (138.139.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 06:20:54.197719 2026] [security2:error] [pid 6849:tid 6849] [client 35.229.139.138:31438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "oaklands1.com"] [uri "/.git/config"] [unique_id "apf4hv1wR-mLBfuR2VpduAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 09:55:06
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.139.138 (138.139.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.139.138 (138.139.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 05:54:58.878224 2026] [security2:error] [pid 949:tid 1122] [client 35.229.139.138:60378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maxelon.com"] [uri "/.git/config"] [unique_id "apfycudWNQLMBPVvkwWZdgAAAJA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Epimetheus
2026-09-02 09:44:05
(15 hours ago)
Unauthorized access attempts:
[GET] /.git/config
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) App ...
show more
Unauthorized access attempts:
[GET] /.git/config
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36
show less
Web App Attack
π³π±
homeshowdomain.nl
2026-09-01 21:59:17
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-31.
show less
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-09-01 09:19:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.139.138 (138.139.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.139.138 (138.139.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:19:18.352957 2026] [security2:error] [pid 23241:tid 23241] [client 35.229.139.138:64922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "colodist.com"] [uri "/.git/config"] [unique_id "apaYlokNzklamjvoPmy2KwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 04:51:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.139.138 (138.139.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.139.138 (138.139.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 00:51:37.841259 2026] [security2:error] [pid 21063:tid 21063] [client 35.229.139.138:33482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "citystreetsalon.com"] [uri "/.git/config"] [unique_id "apZZ2TJNXkYn8Gby5CH-EQAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
big-cloud.nl
2026-09-01 04:29:49
(1 day ago)
Try to access /.git/config
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 03:59:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.139.138 (138.139.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.139.138 (138.139.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:59:09.805345 2026] [security2:error] [pid 6580:tid 6580] [client 35.229.139.138:13154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "briancastle.com"] [uri "/.git/config"] [unique_id "apZNja5pbe51OMu0oPc90wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 22:58:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.139.138 (138.139.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.139.138 (138.139.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 18:58:13.372810 2026] [security2:error] [pid 23219:tid 23219] [client 35.229.139.138:42724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "maeandtheguys.com"] [uri "/.git/config"] [unique_id "apYHBc6TMBqtaZioIOELcgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-08-31 21:59:51
(2 days ago)
Auto-ban: >3000 req/min op 2026-08-31
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-08-31 18:38:38
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.229.139.138 (138.139.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.139.138 (138.139.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 14:38:32.935689 2026] [security2:error] [pid 32386:tid 32386] [client 35.229.139.138:39310] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "velocitymech.com"] [uri "/.git/config"] [unique_id "apXKKIpmwO_0W4nsI-egzQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-31 18:09:19
(2 days ago)
35.229.139.138 - - [01/Sep/2026:02:09:19 +0800] "GET /.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 ...
show more
35.229.139.138 - - [01/Sep/2026:02:09:19 +0800] "GET /.git/config HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack