๐บ๐ธ
TPI-Abuse
2026-09-02 05:14:03
(31 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.238.92.28 (28.92.238.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.92.28 (28.92.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 01:13:56.301992 2026] [security2:error] [pid 15842:tid 15842] [client 35.238.92.28:60372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.coloradofingerprinting.com"] [uri "/app/.git/config"] [unique_id "apewlPykdOTsAaUn8Acv9AAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 02:56:55
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.238.92.28 (28.92.238.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.92.28 (28.92.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 22:56:50.782539 2026] [security2:error] [pid 2803:tid 2803] [client 35.238.92.28:35878] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drhoss.com"] [uri "/var/www/.git/config"] [unique_id "apeQckngR8WS7bKr3SSAQQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-02 00:20:06
(5 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-02 00:17:01
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.238.92.28 (28.92.238.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.92.28 (28.92.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 20:16:55.726032 2026] [security2:error] [pid 28331:tid 28331] [client 35.238.92.28:40040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gewgawdesigns.com"] [uri "/.git/config"] [unique_id "apdq9y9ATkSKagEFpOZ-MQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
David Ferneding
2026-09-01 20:48:30
(8 hours ago)
Blocked by UFW (TCP on 80)
Source port: 33874
TTL: 59
Packet length: 60
TOS: 0x00
This report (for ...
show more
Blocked by UFW (TCP on 80)
Source port: 33874
TTL: 59
Packet length: 60
TOS: 0x00
This report (for 35.238.92.28) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 18:52:08
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.238.92.28 (28.92.238.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.92.28 (28.92.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 14:52:00.375628 2026] [security2:error] [pid 16711:tid 16711] [client 35.238.92.28:51400] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/config.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.austintrauma.com"] [uri "/app/config/config.yml"] [unique_id "apce0J8FIDgGmL3nxdNXQwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
spot
2026-09-01 15:04:45
(14 hours ago)
35.238.92.28 - - [01/Sep/2026:16:04:44 +0100] "GET /backend/.git/config HTTP/1.1" 404 4656 "-" "crus ...
show more
35.238.92.28 - - [01/Sep/2026:16:04:44 +0100] "GET /backend/.git/config HTTP/1.1" 404 4656 "-" "crusader-worker/1.0"
...
show less
Web App Attack
Hacking
๐บ๐ธ
mnsf
2026-09-01 14:05:07
(15 hours ago)
Scanning/Probing (24)
Brute-Force
Web App Attack
๐บ๐ธ
leasj
2026-09-01 13:46:12
(15 hours ago)
Observed Scanned 12 known-sensitive endpoint(s), e.g.: /wordpress/.git/config, /src/.git/config, /ht ...
show more
Observed Scanned 12 known-sensitive endpoint(s), e.g.: /wordpress/.git/config, /src/.git/config, /htdocs/.git/config, /www/.git/config, /backend/.git/config.
show less
Hacking
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-01 13:18:57
(16 hours ago)
cloudlinux2 fail2ban: 2026-09-01 15:14:27,293 fail2ban.filter [1605]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-01 15:14:27,293 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.238.92.28 - 2026-09-01 15:14:27cloudlinux2 fail2ban: 2026-09-01 15:14:27,275 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.238.92.28 - 2026-09-01 15:14:27cloudlinux2 fail2ban: 2026-09-01 15:14:27,229 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.238.92.28 - 2026-09-01 15:14:27cloudlinux2 fail2ban: 2026-09-01 15:14:27,248 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.238.92.28 - 2026-09-01 15:14:27cloudlinux2 fail2ban: 2026-09-01 15:14:27,239 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.238.92.28 - 2026-09-01 15:14:27cloudlinux2 fail2ban: 2026-09-01 15:14:27,257 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.238.92.28 - 2026-09-01 15:14:27cloudlinux2 fail2ban: 2026-09-01 15:14:27,202 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 35.238.92.28 - 2026-09-01 15:14:27cl
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-01 10:23:53
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.238.92.28 (28.92.238.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.92.28 (28.92.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:23:46.939023 2026] [security2:error] [pid 25770:tid 25770] [client 35.238.92.28:35006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "quicksmogsandiego.smogsandiego.com"] [uri "/var/www/.git/config"] [unique_id "apanskP6Czars5xZ1ZBjrgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SwinT
2026-09-01 09:00:03
(20 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ซ๐ท
dynamix
2026-09-01 07:10:59
(22 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 02:25:39
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.238.92.28 (28.92.238.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.92.28 (28.92.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 22:25:33.621275 2026] [security2:error] [pid 17525:tid 17525] [client 35.238.92.28:51696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "epetsure.co"] [uri "/var/www/.git/config"] [unique_id "apY3ncnHd6cfKctTJ-AizQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-29 23:28:27
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.238.92.28 (28.92.238.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.238.92.28 (28.92.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 29 19:28:22.485446 2026] [security2:error] [pid 1529269:tid 1529405] [client 35.238.92.28:51774] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "browbrew.com"] [uri "/wordpress/.git/config"] [unique_id "apNrFhrw4yIIQMokubiBlgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack