Anonymous
2026-09-30 04:50:02
(12 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 19:50:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.240.57.132 (132.57.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.57.132 (132.57.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 15:50:02.632615 2026] [security2:error] [pid 13512:tid 13512] [client 35.240.57.132:50502] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ipv6.robtown.com"] [uri "/.git/config"] [unique_id "arrE6jQkaQWelBUrA5orQQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 03:31:46
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.57.132 (132.57.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.57.132 (132.57.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 23:31:41.624951 2026] [security2:error] [pid 25917:tid 25917] [client 35.240.57.132:54558] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "backtosleep.com"] [uri "/.git/config"] [unique_id "arnfnQC20XHv92QkGzKcYAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-27 04:59:34
(3 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-26 20:47:37
(3 days ago)
[26/Sep/2026:16:47:36.381157 --0400] argvaFTntasAvzTz-2eQpwAAAQw 35.240.57.132 56676 205.233.18.17 7 ...
show more
[26/Sep/2026:16:47:36.381157 --0400] argvaFTntasAvzTz-2eQpwAAAQw 35.240.57.132 56676 205.233.18.17 7081
[26/Sep/2026:16:47:36.650332 --0400] argvaBtbf4cXLWIN-D7KVgAAABY 35.240.57.132 56706 205.233.18.17 7081
[26/Sep/2026:16:47:36.790812 --0400] argvaDrsVsW4pgACN3w8wQAAAco 35.240.57.132 56720 205.233.18.17 7081
[26/Sep/2026:16:47:36.919335 --0400] argvaBtbf4cXLWIN-D7KVwAAAAQ 35.240.57.132 56732 205.233.18.17 7081
[26/Sep/2026:16:47:37.041130 --0400] argvaRtbf4cXLWIN-D7KWAAAAAI 35.240.57.132 56748 205.233.18.17 7081
...
show less
Hacking
๐บ๐ธ
IndigoRidge
2026-09-26 20:03:38
(3 days ago)
35.240.57.132 - - [26/Sep/2026:16:03:28 -0400] "GET /.git/config HTTP/1.1" 404 44225 "-" "Mozilla/5. ...
show more
35.240.57.132 - - [26/Sep/2026:16:03:28 -0400] "GET /.git/config HTTP/1.1" 404 44225 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.240.57.132 - - [26/Sep/2026:16:03:29 -0400] "GET /.env HTTP/1.1" 404 44225 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.240.57.132 - - [26/Sep/2026:16:03:37 -0400] "GET /app/.env HTTP/1.1" 404 44225 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 15:31:30
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.57.132 (132.57.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.57.132 (132.57.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:31:24.173531 2026] [security2:error] [pid 21085:tid 21085] [client 35.240.57.132:52832] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.somewierdness.com"] [uri "/.git/config"] [unique_id "arflTG2wlfZZhsd0PV2jIgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-09-25 06:42:43
(5 days ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
Marcel Bachmann
2026-09-25 05:35:46
(5 days ago)
Automated web scanner detected by HAProxy Security Center. Node: HA01. Reason: Fail2ban HAProxy Scan ...
show more
Automated web scanner detected by HAProxy Security Center. Node: HA01. Reason: Fail2ban HAProxy Scanner
show less
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-25 05:33:33
(5 days ago)
Try to access /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 20:25:26
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.57.132 (132.57.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.57.132 (132.57.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 16:25:21.534876 2026] [security2:error] [pid 12934:tid 12934] [client 35.240.57.132:33500] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.blosoms.org"] [uri "/.git/config"] [unique_id "arWHMROhM1YlSNIC4cXJ4QAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 18:35:12
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.57.132 (132.57.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.57.132 (132.57.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:35:06.460508 2026] [security2:error] [pid 12971:tid 12971] [client 35.240.57.132:36454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.blackriverarc.org"] [uri "/.git/config"] [unique_id "arVtWkBlapr-EVhioJY-LwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 18:06:19
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.57.132 (132.57.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.57.132 (132.57.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:06:16.172185 2026] [security2:error] [pid 26542:tid 26542] [client 35.240.57.132:42314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.blackberrycircle.org"] [uri "/.git/config"] [unique_id "arVmmMGr2334XDXHfzoBigAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 17:48:34
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.57.132 (132.57.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.57.132 (132.57.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 13:48:27.419902 2026] [security2:error] [pid 2875:tid 2875] [client 35.240.57.132:49638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.bknj2.org"] [uri "/.git/config"] [unique_id "arVia-JK0wiOoQtoJDM3LQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-24 03:35:20
(6 days ago)
Excessive 404/403 errors
Brute-Force