๐ฉ๐ช
big-cloud.nl
2026-09-29 05:54:44
(4 hours ago)
Try to access /.git/config
Web App Attack
๐ฉ๐ช
LRob
2026-09-28 21:32:31
(12 hours ago)
Secret file probe | method: GET | path: /.git/config, /.env, /.env.local | ua: Mozilla/5.0 (Macintos ...
show more
Secret file probe | method: GET | path: /.git/config, /.env, /.env.local | ua: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Hacking
Web App Attack
๐ซ๐ท
masterguru
2026-09-28 14:27:34
(19 hours ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.241.89.135 (HK/Hong Kong/135.89.24 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.241.89.135 (HK/Hong Kong/135.89.241.35.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-28 06:11:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.241.89.135 (135.89.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.89.135 (135.89.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 02:11:24.402107 2026] [security2:error] [pid 26637:tid 26637] [client 35.241.89.135:48630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web58.dnchosting.com"] [uri "/.git/config"] [unique_id "aroFDGKxhfTRzwWa_-y_qgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 05:53:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.241.89.135 (135.89.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.89.135 (135.89.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 01:53:18.056734 2026] [security2:error] [pid 18381:tid 18381] [client 35.241.89.135:47084] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web50.dnchosting.com"] [uri "/.git/config"] [unique_id "aroAzmBHoSR17og4TY1ipgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-09-28 05:39:44
(1 day ago)
35.241.89.135 - - [28/Sep/2026:07:39:42 +0200] "GET /.git/config HTTP/1.1" 404 458 "-" "Mozilla/5.0 ...
show more
35.241.89.135 - - [28/Sep/2026:07:39:42 +0200] "GET /.git/config HTTP/1.1" 404 458 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.241.89.135 - - [28/Sep/2026:07:39:43 +0200] "GET /.env HTTP/1.1" 404 458 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 05:36:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.241.89.135 (135.89.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.89.135 (135.89.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 01:36:27.925592 2026] [security2:error] [pid 32486:tid 32486] [client 35.241.89.135:41454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "web4.dnchosting.com"] [uri "/.git/config"] [unique_id "arn828v6edoBkmJPT8xnhgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Vert Paysage
2026-09-28 05:26:52
(1 day ago)
SecurityShield WAF: Signature WAF [CRS-942180] critical โ Detects basic SQL authentication bypass at ...
show more
SecurityShield WAF: Signature WAF [CRS-942180] critical โ Detects basic SQL authentication bypass attempts 1/3
show less
Hacking
๐ช๐ธ
robotstxt
2026-09-27 19:32:39
(1 day ago)
35.241.89.135 - - [27/Sep/2026:19:31:45 +0000] "POST / HTTP/1.1" 403 31 "-" "Mozilla/5.0 (Macintosh; ...
show more
35.241.89.135 - - [27/Sep/2026:19:31:45 +0000] "POST / HTTP/1.1" 403 31 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.241.89.135"
35.241.89.135 - - [27/Sep/2026:19:31:45 +0000] "POST / HTTP/1.1" 403 31 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.241.89.135"
35.241.89.135 - - [27/Sep/2026:19:31:46 +0000] "GET /.git/config HTTP/1.1" 403 31 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.241.89.135"
35.241.89.135 - - [27/Sep/2026:19:31:46 +0000] "GET /.env HTTP/1.1" 403 31 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.241.89.135"
35.241.89.135 - - [27/Sep/2026:19:31:47 +0000] "GET /.env.local HTTP/1.1" 403 31 "-" "Mozilla/5.0 (Maci
...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-09-26 23:10:58
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 20:32:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.241.89.135 (135.89.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.89.135 (135.89.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 16:32:04.127448 2026] [security2:error] [pid 19865:tid 19865] [client 35.241.89.135:37694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.battlestem.com"] [uri "/.git/config"] [unique_id "argrxE5BLdoUGni5aQn_sAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-25 21:14:31
(3 days ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
consul.to
2026-09-24 19:02:29
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
rh24
2026-09-22 18:33:16
(6 days ago)
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 35.241.89.135 (HK/Hong Kong/135.89.241.35 ...
show more
(secretscan) Secret-Scanner (env/git/ssh/credentials) from 35.241.89.135 (HK/Hong Kong/135.89.241.35.bc.googleusercontent.com)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 22:58:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.241.89.135 (135.89.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.89.135 (135.89.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:58:34.185241 2026] [security2:error] [pid 22169:tid 22169] [client 35.241.89.135:40590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.lexie.org"] [uri "/.git/config"] [unique_id "arG2mpGKwFVT50GfB-orNQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack