🇳🇴
jad-abuse
2026-09-07 16:21:26
(39 minutes ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, env_probe, source_backup. Observed by 1 sensor(s); 352 hits.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 15:45:43
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.236.170.231 (231.170.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.170.231 (231.170.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 11:45:39.519120 2026] [security2:error] [pid 19461:tid 19461] [client 35.236.170.231:40772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.outlawstoashes.com.galaxyretro.com"] [uri "/.git/config"] [unique_id "ap7cI-0RI9b4boASAeVHfgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 14:27:26
(2 hours ago)
35.236.170.231 - - [07/Sep/2026:22:27:26 +0800] "GET /.git/config HTTP/1.1" 404 360 "-" "Mozilla/5.0 ...
show more
35.236.170.231 - - [07/Sep/2026:22:27:26 +0800] "GET /.git/config HTTP/1.1" 404 360 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-07 12:51:48
(4 hours ago)
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b ...
show more
Remote Command Execution: Unix Command Injection (command without evasion). Pattern match "(?i)(?:b (932235-195)
show less
Hacking
🇸🇪
vaia.cloud
2026-09-07 12:40:04
(4 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 12:36:52
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.170.231 (231.170.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.170.231 (231.170.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 08:36:44.860611 2026] [security2:error] [pid 28922:tid 28922] [client 35.236.170.231:35114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.packersandribsbbq.blackjobsnetwork.com"] [uri "/.git/config"] [unique_id "ap6v3IqdhP0x85tBTt7VvAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-07 12:12:31
(4 hours ago)
Try to access /.git/config
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 11:43:10
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.170.231 (231.170.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.170.231 (231.170.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 07:43:02.958103 2026] [security2:error] [pid 28911:tid 28911] [client 35.236.170.231:44892] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pack88.mvscouts.org"] [uri "/.git/config"] [unique_id "ap6jRtE7amhBsIwBSD98swAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
SLSLLC
2026-09-07 11:32:15
(5 hours ago)
35.236.170.231 - - [07/Sep/2026:11:32:15 +0000] "GET /.env HTTP/2.0" 403 1881 "-" "Mozilla/5.0 (Wind ...
show more
35.236.170.231 - - [07/Sep/2026:11:32:15 +0000] "GET /.env HTTP/2.0" 403 1881 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 11:23:49
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.170.231 (231.170.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.170.231 (231.170.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 07:23:41.909336 2026] [security2:error] [pid 11677:tid 11677] [client 35.236.170.231:59708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.outbackriviera.maffiniandbearce.com"] [uri "/.git/config"] [unique_id "ap6evRdHq0r7iKhh--WChgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
masterguru
2026-09-07 09:01:50
(7 hours ago)
Remote Command Execution: Unix Shell Expression Found. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\ ...
show more
Remote Command Execution: Unix Shell Expression Found. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})| (932130-169)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-07 07:26:31
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.170.231 (231.170.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.170.231 (231.170.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:26:25.364869 2026] [security2:error] [pid 3321:tid 3321] [client 35.236.170.231:33270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ourhumanfamily.clayrivers.com"] [uri "/.git/config"] [unique_id "ap5nIdB1-qnLURd4Dqlm1gAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-07 06:41:12
(10 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇮🇩
Burayot
2026-09-06 22:10:20
(18 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.236.170.231 (TW/Taiwan/231.170.23 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.236.170.231 (TW/Taiwan/231.170.236.35.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
🇺🇸
mnsf
2026-09-06 22:05:22
(18 hours ago)
Scanning/Probing (12)
Brute-Force
Web App Attack