๐บ๐ธ
TPI-Abuse
2026-09-24 01:47:21
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.179.47 (47.179.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.179.47 (47.179.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:47:16.302285 2026] [security2:error] [pid 8076:tid 8076] [client 35.240.179.47:41616] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.candlecrawler.trade"] [uri "/src/.git/config"] [unique_id "arSBJBjO9LC6KAjxvYBu4AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 00:53:38
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.179.47 (47.179.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.179.47 (47.179.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:53:31.589452 2026] [security2:error] [pid 23176:tid 23176] [client 35.240.179.47:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.ndanetworks.com"] [uri "/src/.git/config"] [unique_id "arR0i1O0crisoRPE-EEaKAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-24 00:40:06
(12 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 00:09:51
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.179.47 (47.179.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.179.47 (47.179.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:09:45.487202 2026] [security2:error] [pid 3210407:tid 3210407] [client 35.240.179.47:54036] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.catherineseress.com"] [uri "/backend/.git/config"] [unique_id "arRqSRI5EJOvNoLfBb6d7AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 22:04:17
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.179.47 (47.179.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.179.47 (47.179.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 18:04:13.560927 2026] [security2:error] [pid 9892:tid 9892] [client 35.240.179.47:42466] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cobbwebb.net"] [uri "/htdocs/.git/config"] [unique_id "arRM3fWQPTvBJmM9At3NzQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
cwytech
2026-09-23 22:04:16
(14 hours ago)
Fleet-wide ban from the Ghostfleet ๐ป. Triggered by scenario: cwy/http-honeypath-sniper-crit.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 21:06:35
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.179.47 (47.179.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.179.47 (47.179.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:06:32.179445 2026] [security2:error] [pid 2342:tid 2342] [client 35.240.179.47:40218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clintcurrin.com"] [uri "/htdocs/.git/config"] [unique_id "arQ_WCd9SqTzdKcaHCgsvwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-23 20:47:40
(15 hours ago)
csagent: score 20.5: secrets grab x2, 404 noise floor x2; 1 domain(s) in 0s
Web App Attack
๐ฉ๐ช
LRob
2026-09-23 19:20:10
(17 hours ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.git/config (+11 more) | 2026-09-23 19:20 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:11:54
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.179.47 (47.179.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.179.47 (47.179.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:11:48.519913 2026] [security2:error] [pid 31265:tid 31340] [client 35.240.179.47:34006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chanyin.org"] [uri "/var/www/.git/config"] [unique_id "arQkdAbPZnet3t_e0es2mQAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:38:21
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.179.47 (47.179.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.179.47 (47.179.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:38:18.049047 2026] [security2:error] [pid 13132:tid 13132] [client 35.240.179.47:44856] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cedricwillems.be"] [uri "/src/.git/config"] [unique_id "arQcmt5lbJr5-OZxwvDu8gAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-23 18:09:56
(18 hours ago)
[23/Sep/2026:21:09:55 +0300] -- 35.240.179.47 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[23/Sep/2026:21:09:55 +0300] -- 35.240.179.47 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:07:06
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.179.47 (47.179.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.179.47 (47.179.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:07:01.529622 2026] [security2:error] [pid 21828:tid 21828] [client 35.240.179.47:54408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cchockeyhistory.org"] [uri "/app/.git/config"] [unique_id "arQVRfPqaN17ZXhmxNN-9AAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 17:04:05
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.179.47 (47.179.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.179.47 (47.179.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 13:04:02.157992 2026] [security2:error] [pid 5254:tid 5254] [client 35.240.179.47:45004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "candlesandwoodcrafts.com"] [uri "/htdocs/.git/config"] [unique_id "arQGgocVb3uad-cc3F9UuwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-23 16:00:11
(20 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack