🇺🇸
TPI-Abuse
2026-09-05 01:58:56
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.153.139 (139.153.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.153.139 (139.153.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 21:58:51.297707 2026] [security2:error] [pid 26499:tid 26499] [client 35.237.153.139:56126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "johnandre.org"] [uri "/html/.git/config"] [unique_id "apt3W4S7ilpXKxTb1U2cSgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-04 22:50:02
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 21:59:36
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-03.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 21:34:04
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.153.139 (139.153.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.153.139 (139.153.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:34:00.418259 2026] [security2:error] [pid 14964:tid 14964] [client 35.237.153.139:57684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.wolter-hausser.com"] [uri "/src/.git/config"] [unique_id "aps5SHu3vkhCep6wpzz1UAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 20:24:22
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇯🇵
sayzard
2026-09-04 15:59:42
(1 day ago)
35.237.153.139 - - [05/Sep/2026:00:59:41 +0900] "GET /.git/config HTTP/1.1" 404 22 "-" "crusader-wor ...
show more
35.237.153.139 - - [05/Sep/2026:00:59:41 +0900] "GET /.git/config HTTP/1.1" 404 22 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-04 14:47:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.153.139 (139.153.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.153.139 (139.153.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:47:01.441426 2026] [security2:error] [pid 14108:tid 14108] [client 35.237.153.139:57546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "email.otraes.com"] [uri "/htdocs/.git/config"] [unique_id "aprZ5epC62FV-kmf_5WooAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-04 12:05:09
(2 days ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
🇬🇧
cg-design.co.uk
2026-09-04 07:39:55
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 35.237.153.139 (US/United States/139.15 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.237.153.139 (US/United States/139.153.237.35.bc.googleusercontent.com)
show less
SQL Injection
🇩🇪
Jarda_H
2026-09-04 05:49:09
(2 days ago)
http-sensitive-files
Web App Attack
🇳🇱
Site.eu
2026-09-04 05:32:27
(2 days ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-04 05:32:07
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.153.139 (139.153.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.153.139 (139.153.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 01:32:00.121818 2026] [security2:error] [pid 25085:tid 25085] [client 35.237.153.139:36256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.jaspercity.com"] [uri "/src/.git/config"] [unique_id "appX0CUdcnZStGF7Se2IGgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-04 04:09:40
(2 days ago)
35.237.153.139 - - [04/Sep/2026:00:09:40 -0400] "GET /htdocs/.git/config HTTP/1.1" 404 5798 "-" "cru ...
show more
35.237.153.139 - - [04/Sep/2026:00:09:40 -0400] "GET /htdocs/.git/config HTTP/1.1" 404 5798 "-" "crusader-worker/1.0"
35.237.153.139 - - [04/Sep/2026:00:09:40 -0400] "GET /.git/config HTTP/1.1" 404 5798 "-" "crusader-worker/1.0"
35.237.153.139 - - [04/Sep/2026:00:09:40 -0400] "GET /app/.git/config HTTP/1.1" 404 5798 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 03:41:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.153.139 (139.153.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.153.139 (139.153.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 23:41:37.021978 2026] [security2:error] [pid 22350:tid 22350] [client 35.237.153.139:48116] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "805.productions"] [uri "/wordpress/.git/config"] [unique_id "apo98WLUDQa9tJpCKc1gEwAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 02:28:22
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.237.153.139 (139.153.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.153.139 (139.153.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 22:28:15.102467 2026] [security2:error] [pid 3589:tid 3589] [client 35.237.153.139:35434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ad1soundstudio.darkalleyproductions.com"] [uri "/.git/config"] [unique_id "aposv94oH0A8tXSDWOdH0gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack