🇳🇱
homeshowdomain.nl
2026-09-10 21:59:11
(2 days ago)
Auto-ban: >3000 req/min op 2026-09-10
Web App Attack
SSH
Hacking
🇺🇸
mnsf
2026-09-10 18:05:18
(2 days ago)
Abuse Detected (12)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 17:16:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.177.254 (254.177.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.177.254 (254.177.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 13:16:39.171433 2026] [security2:error] [pid 22899:tid 22899] [client 35.243.177.254:60014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bluemarineboats.com.greenlight.us"] [uri "/.git/config"] [unique_id "aqLl9-J_HhOo4G9BtdV6vwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
kumiko
2026-09-10 17:08:08
(2 days ago)
[2026-09-10 20:08:07] Probing for dotfiles
"GET /.git/config HTTP/1.1" 403
Bad Web Bot
Web App Attack
🇩🇪
kkw
2026-09-10 16:48:41
(2 days ago)
[REDACTED] 35.243.177.254 - - [10/Sep/2026:18:48:40 +0200] "GET /.git/config HTTP/1.1" 200 5545 "-" ...
show more
[REDACTED] 35.243.177.254 - - [10/Sep/2026:18:48:40 +0200] "GET /.git/config HTTP/1.1" 200 5545 "-" "-"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-10 16:45:35
(2 days ago)
[ssd5.kdns.gr] httpd-config-scan: sites=www.blossombeauty.gr; logs=/var/log/httpd/domains/blossombea ...
show more
[ssd5.kdns.gr] httpd-config-scan: sites=www.blossombeauty.gr; logs=/var/log/httpd/domains/blossombeauty.gr.log; samples=/.git/config
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 16:43:08
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.177.254 (254.177.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.177.254 (254.177.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 12:43:01.880235 2026] [security2:error] [pid 11848:tid 11848] [client 35.243.177.254:53456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blosoms.org"] [uri "/.git/config"] [unique_id "aqLeFb5mfOWRKYbll_E5YQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-10 16:38:56
(2 days ago)
cloudlinux2 fail2ban: 2026-09-10 18:34:24,259 fail2ban.actions [1892]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-10 18:34:24,259 fail2ban.actions [1892]: NOTICE [plesk-modsecurity] Unban 49.144.173.69cloudlinux2 fail2ban: 2026-09-10 18:34:43,614 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 119.63.138.184 - 2026-09-10 18:34:43cloudlinux2 fail2ban: 2026-09-10 18:35:04,450 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 35.243.177.254 - 2026-09-10 18:35:04cloudlinux2 fail2ban: 2026-09-10 18:35:27,214 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 24.202.19.8 - 2026-09-10 18:35:27cloudlinux2 fail2ban: 2026-09-10 18:35:50,145 fail2ban.filter [1892]: INFO [plesk-modsecurity] Found 119.63.138.184 - 2026-09-10 18:35:50cloudlinux2 fail2ban: 2026-09-10 18:36:00,391 fail2ban.actions [1892]: NOTICE [plesk-modsecurity] Unban 34.26.224.77cloudlinux2 fail2ban: 2026-09-10 18:36:12,417 fail2ban.actions [1892]: NOTICE [plesk-modsecurity] Ban 119.63.138.184cloudlinux2 fail2ban: 2026-09-10 18:36:12,108 fail2ban.filter
show less
FTP Brute-Force
🇺🇸
TPI-Abuse
2026-09-10 16:22:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.177.254 (254.177.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.177.254 (254.177.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 12:22:38.312472 2026] [security2:error] [pid 28380:tid 28380] [client 35.243.177.254:33678] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.yeswedeliver.org"] [uri "/.git/config"] [unique_id "aqLZTkh9Ldqp5lNPqEE-rAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-10 16:07:02
(2 days ago)
Automated web scanner. Requested suspicious paths: /.git/config. UTC: 2026-09-10 16:04:10.
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 16:05:51
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.177.254 (254.177.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.177.254 (254.177.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 12:05:47.758404 2026] [security2:error] [pid 9782:tid 9782] [client 35.243.177.254:51154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.tracybur.net"] [uri "/.git/config"] [unique_id "aqLVW5Br7e1yEE-yool6jQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-10 15:46:17
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.177.254 (254.177.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.177.254 (254.177.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 11:46:11.028109 2026] [security2:error] [pid 3599:tid 3599] [client 35.243.177.254:40538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blogs.melton.space"] [uri "/.git/config"] [unique_id "aqLQw5EgxRa2iyvNLW_PKQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
abuse-opdc
2026-09-10 15:21:03
(2 days ago)
Malicious HTTP requests matching injection/exploit signatures.
Web App Attack
Brute-Force
🇺🇸
TPI-Abuse
2026-09-10 15:10:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.243.177.254 (254.177.243.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.243.177.254 (254.177.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 11:10:09.185794 2026] [security2:error] [pid 5756:tid 5756] [client 35.243.177.254:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.nyemdr.com"] [uri "/.git/config"] [unique_id "aqLIUX6DBqkzkvipvnKnTwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
OceanTreasure
2026-09-10 15:08:53
(2 days ago)
tcp/443; Git configuration exposure attempt: "GET /.git/config" @ 2026-09-10T15:08:53Z [proxy]
Web App Attack