๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:00:17
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-08.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 16:30:26
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.237.198.190 (190.198.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.198.190 (190.198.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 12:30:21.227807 2026] [security2:error] [pid 3746:tid 3746] [client 35.237.198.190:52586] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "freight.michaelpmcgrath.com"] [uri "/.git/config"] [unique_id "aig_nTnJNW28m2dSMmRF4QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-06-09 15:52:08
(1 week ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.237.198.190 (US/United States/190. ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.237.198.190 (US/United States/190.198.237.35.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 15:49:44
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.237.198.190 (190.198.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.198.190 (190.198.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 11:49:38.129528 2026] [security2:error] [pid 10129:tid 10129] [client 35.237.198.190:36304] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cfcameron.cygnetsilks.com"] [uri "/.git/config"] [unique_id "aig2EhUoSTkPw2nPZqADagAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Blexyel
2026-06-09 14:00:58
(1 week ago)
35.237.198.190 - - [09/Jun/2026:16:00:57 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 ...
show more
35.237.198.190 - - [09/Jun/2026:16:00:57 +0200] "GET /.git/config HTTP/1.1" 404 120 "-" "Mozilla/5.0 (Linux; Android 9; SAMSUNG SM-G960F Build/PPR1.180610.011) AppleWebKit/537.36 (KHTML, like Gecko) SamsungBrowser/8.2 Chrome/63.0.3239.111 Mobile Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐ฌ๐ง
pinguin
2026-06-09 12:58:20
(1 week ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: LOG
Protocol: HTTP/1.1 (GET method)
Endpoint: /.git/config
UA: Mozilla/5.0 (Linux; Android 9; G8343 Build/47.2.A.10.107; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/76.0.3809.111 Mobile Safari/537.36 [FB_IAB/Orca-Android;FBAV/229.1.0.17.118;]
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-09 07:56:03
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.237.198.190 (190.198.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.198.190 (190.198.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 03:55:57.327423 2026] [security2:error] [pid 23725:tid 23725] [client 35.237.198.190:39714] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "piperwaite.com"] [uri "/.git/config"] [unique_id "aifHDQYA325amAcZ64iPMAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-06-09 07:05:29
(1 week ago)
Scraping with a high error ratio and request rate Requests to unauthorized or suspicious endpoints ( ...
show more
Scraping with a high error ratio and request rate Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
show less
Bad Web Bot
๐ฌ๐ง
Oakley
2026-06-09 06:04:01
(1 week ago)
(confirmed_bot_sig) Confirmed bot
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-09 05:20:33
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.237.198.190 (190.198.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.198.190 (190.198.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 01:20:26.394991 2026] [security2:error] [pid 25348:tid 25348] [client 35.237.198.190:37204] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "solucionesmercadeodigital.com"] [uri "/.git/config"] [unique_id "aieimp34rWiRLHd4FQI0NwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-09 05:05:39
(1 week ago)
Abuse Detected (1)
Brute-Force
Web App Attack
๐บ๐ธ
xxkodedxx
2026-06-09 05:02:05
(1 week ago)
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 2ร edge-block in 10 ...
show more
[Zorvexus edge-defense] Edge-block (probe URI / bad UA / hostile vhost)
Trigger: 2ร edge-block in 10m window.
Origin: US / AS396982 Google LLC
Active: 05:01:25โ05:01:27 UTC
Volume: 2 HTTP req
Probed: /.git/config
Status mix: 444ร2
Vhost fishing: vibrant-sanderson.67-217-240-72.plesk.page
UA: "Mozilla/5.0 (Linux; Android 9; G8343 Build/47.2.A.10.107; wv) AppleWebKit/537.36 (KHTML, like Gecko) Version/4.0 Chrome/76.0.3809.111 Mobile Safari/537.36 [F..."
Auto-banned 30d. zorvexus-banner.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 04:52:00
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.237.198.190 (190.198.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.198.190 (190.198.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 00:51:56.477671 2026] [security2:error] [pid 11481:tid 11481] [client 35.237.198.190:43154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jnpmarinesolutions.com"] [uri "/.git/config"] [unique_id "aieb7AjwXv9HvON8tn12MwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 04:14:30
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.237.198.190 (190.198.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.198.190 (190.198.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 00:14:25.283489 2026] [security2:error] [pid 21686:tid 21686] [client 35.237.198.190:49820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tulsatvmemories.com"] [uri "/.git/config"] [unique_id "aieTISUhNKLhttShf00ENwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 03:56:59
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.237.198.190 (190.198.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.198.190 (190.198.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 23:56:54.211942 2026] [security2:error] [pid 1727:tid 1727] [client 35.237.198.190:53652] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mrbaystreet.com"] [uri "/.git/config"] [unique_id "aiePBv6xUZbKMy0_sZCjzAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack