๐บ๐ธ
TPI-Abuse
2026-09-26 15:50:06
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.194.191 (191.194.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.194.191 (191.194.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:50:01.780412 2026] [security2:error] [pid 10179:tid 10179] [client 35.240.194.191:46156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.pcsyportatiles.com"] [uri "/.git/config"] [unique_id "arfpqZ7RAMCxONYaPd-AtgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 15:04:49
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.194.191 (191.194.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.194.191 (191.194.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:04:42.722191 2026] [security2:error] [pid 2567:tid 2567] [client 35.240.194.191:57522] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.p-co.com"] [uri "/.git/config"] [unique_id "arffCqs-7QZCO6nbTlmXEAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-25 22:00:25
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-25
Web App Attack
SSH
Hacking
๐ท๐ด
clauss
2026-09-25 05:37:14
(2 days ago)
35.240.194.191 - - [25/Sep/2026:08:37:13 +0300] "GET /phpinfo.php HTTP/2.0" 301 0 "-" "Mozilla/5.0 ( ...
show more
35.240.194.191 - - [25/Sep/2026:08:37:13 +0300] "GET /phpinfo.php HTTP/2.0" 301 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.240.194.191 - - [25/Sep/2026:08:37:14 +0300] "GET /phpinfo.php HTTP/2.0" 404 24890 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐ซ๐ท
masterguru
2026-09-25 04:14:20
(2 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 18:34:35
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.194.191 (191.194.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.194.191 (191.194.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:34:30.661391 2026] [security2:error] [pid 26849:tid 26849] [client 35.240.194.191:57490] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "budinger.org"] [uri "/.git/config"] [unique_id "arVtNgeTYGaVqK1sb16DtwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Sonoflet
2026-09-24 17:58:42
(2 days ago)
CrowdSec detection | scenario: http-probing
Port Scan
Web App Attack
๐ฉ๐ช
Holger
2026-09-24 15:42:10
(2 days ago)
Bruteforce WebAttack
Brute-Force
Web App Attack
๐ฉ๐ช
snhosting
2026-09-24 13:03:37
(2 days ago)
35.240.194.191 - - [24/Sep/2026:15:03:27 +0200] "POST / HTTP/1.1" 404 844 "-" "Mozilla/5.0 (Macintos ...
show more
35.240.194.191 - - [24/Sep/2026:15:03:27 +0200] "POST / HTTP/1.1" 404 844 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.240.194.191 - - [24/Sep/2026:15:03:27 +0200] "POST / HTTP/1.1" 404 844 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.240.194.191 - - [24/Sep/2026:15:03:27 +0200] "POST / HTTP/1.1" 404 844 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.240.194.191 - - [24/Sep/2026:15:03:27 +0200] "GET /.git/config HTTP/1.1" 422 496 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.240.194.191 - - [24/Sep/2026:15:03:28 +0200] "POST / HTTP/1.1" 404 844 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
DNS Compromise
DNS Poisoning
Phishing
Email Spam
Brute-Force
Web App Attack
SSH
๐ซ๐ท
N3ilawx
2026-09-24 03:20:42
(3 days ago)
Fail2Ban detect something wrong with this ip 35.240.194.191 - GET - 404 - [24/Sep/2026:05:20:38 +020 ...
show more
Fail2Ban detect something wrong with this ip 35.240.194.191 - GET - 404 - [24/Sep/2026:05:20:38 +0200]
35.240.194.191 - GET - 404 - [24/Sep/2026:05:20:39 +0200]
35.240.194.191 - GET - 404 - [24/Sep/2026:05:20:39 +0200]
35.240.194.191 - GET - 404 - [24/Sep/2026:05:20:40 +0200]
35.240.194.191 - GET - 404 - [24/Sep/2026:05:20:40 +0200]
35.240.194.191 - GET - 404 - [24/Sep/2026:05:20:40 +0200]
35.240.194.191 - GET - 404 - [24/Sep/2026:05:20:41 +0200]
35.240.194.191 - GET - 404 - [24/Sep/2026:05:20:41 +0200]
35.240.194.191 - GET - 404 - [24/Sep/2026:05:20:41 +0200]
35.240.194.191 - GET - 404 - [24/Sep/2026:05:20:41 +0200]
...
show less
Brute-Force
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-09-24 02:42:34
(3 days ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
191.194.240.35.bc.googleusercontent.com
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 02:38:54
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.194.191 (191.194.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.194.191 (191.194.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:38:47.173583 2026] [security2:error] [pid 3982:tid 3982] [client 35.240.194.191:59514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "armenianpress.am"] [uri "/.git/config"] [unique_id "arSNN0et3Plo7b7E5-15NgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-24 00:25:10
(3 days ago)
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-23 22:00:41
(3 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-22.
show less
Web App Attack
SSH
Hacking
๐ช๐ธ
robotstxt
2026-09-23 10:06:06
(3 days ago)
35.240.194.191 - - [23/Sep/2026:10:05:28 +0000] "GET /.env HTTP/1.1" 403 16911 "-" "Mozilla/5.0 (Mac ...
show more
35.240.194.191 - - [23/Sep/2026:10:05:28 +0000] "GET /.env HTTP/1.1" 403 16911 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.240.194.191"
35.240.194.191 - - [23/Sep/2026:10:05:29 +0000] "GET /.env.local HTTP/1.1" 403 16911 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.240.194.191"
35.240.194.191 - - [23/Sep/2026:10:05:29 +0000] "GET /.env.production HTTP/1.1" 403 16911 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.240.194.191"
35.240.194.191 - - [23/Sep/2026:10:05:30 +0000] "GET /.env.staging HTTP/1.1" 403 16911 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.240.194.191"
35.240.194.191 - - [23/Sep/2026:10:05:30 +0000] "GET /.env.
...
show less
Web App Attack