🇫🇷
masterguru
2026-09-07 15:26:34
(9 minutes ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 13:47:54
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.236.120.153 (153.120.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.120.153 (153.120.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 09:47:49.584471 2026] [security2:error] [pid 31726:tid 31726] [client 35.236.120.153:54154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.oldsite.soudertonbigred.org"] [uri "/.git/config"] [unique_id "ap7AhY9AROcl1oJNyBFEDgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-07 13:45:37
(1 hour ago)
(mod_security) mod_security (id:949110) triggered by 35.236.120.153 (US/United States/153.120.236.35 ...
show more
(mod_security) mod_security (id:949110) triggered by 35.236.120.153 (US/United States/153.120.236.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 13:03:16
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.120.153 (153.120.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.120.153 (153.120.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 09:03:10.292194 2026] [security2:error] [pid 1207:tid 1207] [client 35.236.120.153:33564] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.oldnvn.tonynvn.me"] [uri "/.git/config"] [unique_id "ap62DhcbqT01IZhIrqnyqAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-07 11:37:05
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇸🇪
vaia.cloud
2026-09-07 11:35:02
(4 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 11:31:24
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.120.153 (153.120.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.120.153 (153.120.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 07:31:18.414080 2026] [security2:error] [pid 22545:tid 22545] [client 35.236.120.153:55014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.odysseydogasporlari.com.handankoc.net"] [uri "/.git/config"] [unique_id "ap6ghjFF9Dm96i2TtciN_QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
oja
2026-09-07 10:40:05
(4 hours ago)
Aggressive web scanner
Web App Attack
🇷🇴
iulianh
2026-09-07 10:34:02
(5 hours ago)
80,443
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-07 09:45:17
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.120.153 (153.120.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.120.153 (153.120.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:45:09.813644 2026] [security2:error] [pid 3369:tid 3369] [client 35.236.120.153:34892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.old.renju.net"] [uri "/.git/config"] [unique_id "ap6HpegCPCkAeQEyanGOCQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 09:05:24
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.120.153 (153.120.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.120.153 (153.120.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:05:18.833794 2026] [security2:error] [pid 17972:tid 17972] [client 35.236.120.153:34458] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.old.mightyhoop.com"] [uri "/.git/config"] [unique_id "ap5-TgMQX7c7Y_T17c1lSQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-07 08:51:48
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇧🇪
cmbplf
2026-09-07 08:50:06
(6 hours ago)
142 requests with url.path *.php.bak
Brute-Force
Bad Web Bot
Anonymous
2026-09-07 08:37:04
(6 hours ago)
Bot / scanning and/or hacking attempts: GET /i.php HTTP/1.1, GET /.env.remote HTTP/1.1, GET /pi.php ...
show more
Bot / scanning and/or hacking attempts: GET /i.php HTTP/1.1, GET /.env.remote HTTP/1.1, GET /pi.php HTTP/1.1, GET /php.php HTTP/1.1, GET /.env.staging HTTP/1.1, GET /info.php HTTP/1.1, GET /.env.test HTTP/1.1, GET /.env.development HTTP/1.1, GET /.env.bak HTTP/1.1, GET /pinfo.php HTTP/1.1, GET /.git/config HTTP/1.1, GET /phpinfo.php HTTP/1.1, GET /.env.local HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 08:34:29
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.120.153 (153.120.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.120.153 (153.120.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:34:23.710084 2026] [security2:error] [pid 30354:tid 30354] [client 35.236.120.153:46270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.odinscelestialtrust.org.rejuvenationsystems.com"] [uri "/.git/config"] [unique_id "ap53D9uoVbcqi7ep8ofpuwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack