π³π±
homeshowdomain.nl
2026-09-24 21:59:02
(17 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-23.
show less
Web App Attack
SSH
Hacking
πΏπ¦
conure.sh
2026-09-24 12:01:43
(1 day ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
Anonymous
2026-09-24 09:45:02
(1 day ago)
suspicious request in access.log
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-24 08:15:16
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.238.183.176 (176.183.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.183.176 (176.183.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 04:15:11.621023 2026] [security2:error] [pid 21139:tid 21139] [client 35.238.183.176:59936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dcsteven.com"] [uri "/wordpress/.git/config"] [unique_id "arTcD4_Un2U8-LKc8GOHIwAAADc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-09-24 08:10:02
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-24 07:01:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.238.183.176 (176.183.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.183.176 (176.183.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:01:10.342239 2026] [security2:error] [pid 27158:tid 27158] [client 35.238.183.176:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "crown.365soft.top"] [uri "/var/www/.git/config"] [unique_id "arTKtkiuj_t7geXWNoOQOQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-09-24 04:18:54
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-24 00:39:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.238.183.176 (176.183.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.183.176 (176.183.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:39:46.153103 2026] [security2:error] [pid 4531:tid 4531] [client 35.238.183.176:41978] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "compformation.com"] [uri "/html/.git/config"] [unique_id "arRxUofkZ4ZQcHHk_UMGgwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-24 00:14:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.238.183.176 (176.183.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.183.176 (176.183.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:14:51.240266 2026] [security2:error] [pid 29007:tid 29042] [client 35.238.183.176:39728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.cookmanufacturinggroup.com"] [uri "/wordpress/.git/config"] [unique_id "arRre8E9OGW31ZBKJnZs0gAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-23 21:41:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.238.183.176 (176.183.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.183.176 (176.183.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:41:24.781153 2026] [security2:error] [pid 10049:tid 10049] [client 35.238.183.176:57922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cmc4president.homebuilt.org"] [uri "/www/.git/config"] [unique_id "arRHhCyg6FSSYVUuib7fCAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-09-23 21:22:48
(1 day ago)
This address swept through a list of pages that do not exist on our site within seconds β a scanner ...
show more
This address swept through a list of pages that do not exist on our site within seconds β a scanner working through its wordlist of exploitable paths. Blocked; please check the machine behind it for a scanner or malware. | method: GET | path: /var/www/.git/config (+11 more) | 2026-09-23 21:22 UTC
show less
Port Scan
Web App Attack
πΊπ¦
URAN Publishing Service
2026-09-23 18:47:46
(1 day ago)
[23/Sep/2026:21:47:45 +0300] -- 35.238.183.176 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[23/Sep/2026:21:47:45 +0300] -- 35.238.183.176 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
π©πͺ
yitzhaq
2026-09-23 15:01:48
(2 days ago)
35.238.183.176 - - [23/Sep/2026:17:01:45 +0200] "GET /.git/config HTTP/1.1" 403 4522 "-" "crusader-w ...
show more
35.238.183.176 - - [23/Sep/2026:17:01:45 +0200] "GET /.git/config HTTP/1.1" 403 4522 "-" "crusader-worker/1.0"
35.238.183.176 - - [23/Sep/2026:17:01:45 +0200] "GET /htdocs/.git/config HTTP/1.1" 404 4520 "-" "crusader-worker/1.0"
35.238.183.176 - - [23/Sep/2026:17:01:45 +0200] "GET /api/.git/config HTTP/1.1" 404 4520 "-" "crusader-worker/1.0"
35.238.183.176 - - [23/Sep/2026:17:01:45 +0200] "GET /wordpress/.git/config HTTP/1.1" 404 4519 "-" "crusader-worker/1.0"
35.238.183.176 - - [23/Sep/2026:17:01:45 +0200] "GET /site/.git/config HTTP/1.1" 404 4519 "-" "crusader-worker/1.0"
35.238.183.176 - - [23/Sep/2026:17:01:45 +0200] "GET /public/.git/config HTTP/1.1" 404 4521 "-" "crusader-worker/1.0"
35.238.183.176 - - [23/Sep/2026:17:01:45 +0200] "GET /app/.git/config HTTP/1.1" 404 4521 "-" "crusader-worker/1.0"
35.238.183.176 - - [23/Sep/2026:17:01:45 +0200] "GET /www/.git/config HTTP/1.1" 404 4521 "-" "crusader-worker/1.0"
35.238.183.176 - - [23/Sep/2026:17:01:45 +0200] "GET /src/.git/config H
show less
Web App Attack
Hacking
πΏπ¦
conure.sh
2026-09-23 13:38:40
(2 days ago)
csagent: score 20.5: 404 noise floor x2, secrets grab x2; 1 domain(s) in 0s
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-23 11:28:38
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.238.183.176 (176.183.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.183.176 (176.183.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 07:28:33.462811 2026] [security2:error] [pid 6109:tid 6122] [client 35.238.183.176:51884] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bestthingieveratelocations.com"] [uri "/www/.git/config"] [unique_id "arO34Rn__XM-lNCL5dYt5AAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack