Anonymous
2026-09-06 06:54:50
(42 minutes ago)
Multiple Git Repository Information Disclosure attempt.
Hacking
🇺🇸
TPI-Abuse
2026-09-06 00:43:10
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.4.19 (19.4.237.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.4.19 (19.4.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 20:43:06.125537 2026] [security2:error] [pid 22262:tid 22262] [client 35.237.4.19:53400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vn-hakunabtanaguan.biz"] [uri "/www/.git/config"] [unique_id "apy3GjAY4bKX9PxamRoDJgAAAGw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-05 21:15:19
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.237.4.19 (19.4.237.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.4.19 (19.4.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:15:11.459532 2026] [security2:error] [pid 30926:tid 30926] [client 35.237.4.19:45422] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "krankybitchguitars.com"] [uri "/app/.git/config"] [unique_id "apyGX1VB03psqhzntXZn8QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇴
jad-abuse
2026-09-05 13:34:53
(18 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, scanner_ua. Observed by 1 sensor(s); 24 hits.
show less
Web App Attack
🇧🇾
lns.bz
2026-09-05 08:48:17
(22 hours ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
mnsf
2026-09-04 23:06:04
(1 day ago)
Too many Status 40X (12)
Scanning/Probing (24)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 22:52:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.4.19 (19.4.237.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.4.19 (19.4.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 18:52:29.298583 2026] [security2:error] [pid 20584:tid 20584] [client 35.237.4.19:45382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "relay2.semisysteme.com"] [uri "/www/.git/config"] [unique_id "aptLrfnsjFuXuzgHc5HbxgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Petros Stefanakis
2026-09-04 22:21:30
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 35.237.4.19 (US/United States/19.4.237. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.237.4.19 (US/United States/19.4.237.35.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-04 21:55:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.4.19 (19.4.237.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.4.19 (19.4.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:55:12.445518 2026] [security2:error] [pid 2097:tid 2097] [client 35.237.4.19:37062] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.elegantweddinginvitations.net"] [uri "/src/.git/config"] [unique_id "aps-QOy6AgdAYpu7on4laAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Teufel100
2026-09-04 21:53:53
(1 day ago)
Bruteforce gegen Einstellungsdateien wie .env oder .git
Brute-Force
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:25:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.4.19 (19.4.237.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.4.19 (19.4.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:25:27.150192 2026] [security2:error] [pid 7926:tid 7926] [client 35.237.4.19:60626] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.randyshelly.com"] [uri "/www/.git/config"] [unique_id "aps3Rwdl1j9CLXIo6FkapwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 19:52:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.4.19 (19.4.237.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.4.19 (19.4.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 15:52:41.810838 2026] [security2:error] [pid 22246:tid 22261] [client 35.237.4.19:42144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "veganfiestas.com.teritemme.com"] [uri "/api/.git/config"] [unique_id "apshiYzTykwJ83eSX2QPTwAAAU0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
Origon
2026-09-04 18:45:48
(1 day ago)
http-sensitive-files - IP: 35.237.4.19 - time="2026-09-04T20:45:47+02:00" level=info msg="(555f66b4 ...
show more
http-sensitive-files - IP: 35.237.4.19 - time="2026-09-04T20:45:47+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 35.237.4.19 (US/396982) : 4h ban on Ip 35.237.4.19" module=db
show less
Web App Attack
🇩🇪
sfmet-admin
2026-09-04 17:23:40
(1 day ago)
35.237.4.19 - - [04/Sep/2026:17:23:39 +0000] "GET /.git/config HTTP/2.0" 444 0 "-" "crusader-worker/ ...
show more
35.237.4.19 - - [04/Sep/2026:17:23:39 +0000] "GET /.git/config HTTP/2.0" 444 0 "-" "crusader-worker/1.0"
...
show less
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 15:33:34
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking