πΏπ¦
conure.sh
2026-09-02 07:55:43
(2 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 06:02:42
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.238.120.231 (231.120.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.120.231 (231.120.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 02:02:37.121647 2026] [security2:error] [pid 434:tid 434] [client 35.238.120.231:39462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.pintoresdecasascdmx.com"] [uri "/www/.git/config"] [unique_id "ape7_UAxIlDSOhBb94xK-AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
SysAdmin Dylan
2026-09-02 06:01:56
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.238.120.231 (US/United States/231.120.238.35 ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.120.231 (US/United States/231.120.238.35.bc.googleusercontent.com): 10 in the last 3600 secs
show less
Brute-Force
π¬π§
Aetherweb Ark
2026-09-02 05:56:05
(4 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.238.120.231 (US/United States/231.120.238.35 ...
show more
(mod_security) mod_security (id:949110) triggered by 35.238.120.231 (US/United States/231.120.238.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 05:41:36
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.238.120.231 (231.120.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.120.231 (231.120.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 01:41:29.254485 2026] [security2:error] [pid 11814:tid 11814] [client 35.238.120.231:41774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.stansmarshservices.com"] [uri "/site/.git/config"] [unique_id "ape3CXVaHtJOCuR-I3CnWQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
netclix.gr
2026-09-02 05:29:04
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.238.120.231 (US/United States/231.12 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.238.120.231 (US/United States/231.120.238.35.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-02 05:17:08
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.238.120.231 (231.120.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.120.231 (231.120.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 01:17:03.928069 2026] [security2:error] [pid 15847:tid 15847] [client 35.238.120.231:36324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.cajunfriedturkey.com"] [uri "/.git/config"] [unique_id "apexTwGYGIUtvmHNpfTf6gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
FD-IX
2026-09-02 05:15:50
(4 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-09-02 05:00:38
(4 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 04:58:08
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.238.120.231 (231.120.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.120.231 (231.120.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 00:58:01.682347 2026] [security2:error] [pid 2771:tid 2771] [client 35.238.120.231:34814] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.serpentstudios.com"] [uri "/site/.git/config"] [unique_id "apes2fmU_CoTiF38QVhjDAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 04:23:34
(5 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
π©πͺ
Viveronese
2026-09-02 00:59:24
(8 hours ago)
HTTP vulnerability scanning
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-02 00:43:48
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.238.120.231 (231.120.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.120.231 (231.120.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 20:43:43.383801 2026] [security2:error] [pid 5077:tid 5077] [client 35.238.120.231:37328] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globalaccessau.com.salsberggroup.com"] [uri "/var/www/.git/config"] [unique_id "apdxP-pejv9uU_vm5TzDOAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 22:39:19
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.238.120.231 (231.120.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.120.231 (231.120.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 18:39:15.476140 2026] [security2:error] [pid 24858:tid 24858] [client 35.238.120.231:44934] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "trainingbysteve.pages4you.com"] [uri "/html/.git/config"] [unique_id "apdUEz7_vVEVYL3QQqICYgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³πΏ
Antinson
2026-09-01 21:50:10
(12 hours ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot