π³π±
homeshowdomain.nl
2026-10-06 21:59:58
(6 hours ago)
Auto-ban: >3000 req/min op 2026-10-06
Web App Attack
SSH
Hacking
πΊπΈ
TPI-Abuse
2026-10-06 21:24:43
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.239.125.39 (39.125.239.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.125.39 (39.125.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 17:24:35.613968 2026] [security2:error] [pid 11904:tid 11904] [client 35.239.125.39:51278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ava-world.com"] [uri "/.git/config"] [unique_id "asVnE_4KgZivv-XCUUYS1QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΉ
RenΓ© Hickersberger
2026-10-06 21:10:58
(6 hours ago)
malicious bot detected: violations="hit-honeypot"; user_agent=""
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 20:49:16
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.239.125.39 (39.125.239.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.125.39 (39.125.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 16:49:11.464778 2026] [security2:error] [pid 28938:tid 28938] [client 35.239.125.39:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.distro.media"] [uri "/.git/config"] [unique_id "asVexyEBF92XuSR_d7wWkwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
TheDjRider
2026-10-06 20:38:46
(7 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-10-06T20:38:44.472362699Z. Context: http_status=200
show less
Web App Attack
π©πͺ
Marco711
2026-10-06 20:32:24
(7 hours ago)
port/URL scanning
Port Scan
Web App Attack
π·π΄
clauss
2026-10-06 20:32:10
(7 hours ago)
35.239.125.39 - - [06/Oct/2026:23:30:10 +0300] "GET /.git/config HTTP/1.1" 200 314 "-" "-"
35.239.12 ...
show more
35.239.125.39 - - [06/Oct/2026:23:30:10 +0300] "GET /.git/config HTTP/1.1" 200 314 "-" "-"
35.239.125.39 - - [06/Oct/2026:23:32:09 +0300] "GET /.git/config HTTP/1.1" 200 314 "-" "-"
...
show less
Web App Attack
π©πͺ
tsZero
2026-10-06 20:27:37
(7 hours ago)
Scan example: path=/.git/config status=403
Hacking
π©πͺ
auridh
2026-10-06 20:22:14
(7 hours ago)
WAF block: crowdsecurity/vpatch-git-config from 35.239.125.39 ([REDACTED])
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 20:16:26
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.239.125.39 (39.125.239.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.125.39 (39.125.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 16:16:22.454955 2026] [security2:error] [pid 6357:tid 6357] [client 35.239.125.39:57980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aufflammen.com"] [uri "/.git/config"] [unique_id "asVXFu06sYMj-_Y4AGtA0AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
paissangroup
2026-10-06 20:11:57
(7 hours ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
kosada.com
2026-10-06 20:06:42
(7 hours ago)
Repeated exploit attempts, for example: /.git/config /.git/config (HTTP/1.1 port 443)
Web App Attack
πΊπ¦
URAN Publishing Service
2026-10-06 19:41:17
(8 hours ago)
[06/Oct/2026:22:41:16 +0300] -- 35.239.125.39 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[06/Oct/2026:22:41:16 +0300] -- 35.239.125.39 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-06 19:33:54
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.239.125.39 (39.125.239.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.125.39 (39.125.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 15:33:51.170666 2026] [security2:error] [pid 32267:tid 32267] [client 35.239.125.39:40680] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arofish.us"] [uri "/.git/config"] [unique_id "asVNH4-JBzjq0NugTNBb8wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
decode5921
2026-10-06 19:25:29
(8 hours ago)
Honeypot hit: GET /.git/config
Bad Web Bot
Web App Attack