๐บ๐ธ
TPI-Abuse
2026-09-04 00:53:23
(21 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.247.251.222 (222.251.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.251.222 (222.251.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 20:53:16.722083 2026] [security2:error] [pid 17997:tid 17997] [client 35.247.251.222:32830] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "feathersolar.com"] [uri "/app/.git/config"] [unique_id "apoWfGPJIRVmSDmgz2zcTQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-04 00:46:37
(28 minutes ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
๐ฉ๐ช
raph
2026-09-03 20:03:24
(5 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 18:33:17
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.251.222 (222.251.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.251.222 (222.251.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 14:33:13.965546 2026] [security2:error] [pid 12065:tid 12065] [client 35.247.251.222:47324] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "memelearning.net"] [uri "/site/.git/config"] [unique_id "apm9adITschzxL7dRSNzKgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-09-03 18:09:28
(7 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-03 16:33:02
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฉ๐ช
Vegascosmetics
2026-09-03 16:28:34
(8 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.git (Match: /.git)
show less
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-03 13:45:19
(11 hours ago)
Observed scanned 12 known-sensitive endpoint(s), e.g.: /.git/config, /api/.git/config, /app/.git/con ...
show more
Observed scanned 12 known-sensitive endpoint(s), e.g.: /.git/config, /api/.git/config, /app/.git/config, /backend/.git/config, /htdocs/.git/config, /html/.git/config
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 12:14:50
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.251.222 (222.251.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.251.222 (222.251.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 08:14:44.712553 2026] [security2:error] [pid 17787:tid 17787] [client 35.247.251.222:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.365soft.top"] [uri "/www/.git/config"] [unique_id "aplktBSeRYzassDgt8YEsgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
YF
2026-09-03 08:30:51
(16 hours ago)
Git config exposure probe
Web App Attack
๐ฌ๐ง
consul.to
2026-09-03 08:02:47
(17 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-09-03 07:34:59
(17 hours ago)
[03/Sep/2026:10:34:59 +0300] -- 35.247.251.222 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.gi ...
show more
[03/Sep/2026:10:34:59 +0300] -- 35.247.251.222 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-03 07:20:11
(17 hours ago)
Web App Attack
Anonymous
2026-09-03 06:06:11
(19 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-03 05:00:42
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.251.222 (222.251.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.251.222 (222.251.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 01:00:38.081334 2026] [security2:error] [pid 27004:tid 27004] [client 35.247.251.222:37128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "patrick.grimone.com"] [uri "/public/.git/config"] [unique_id "apj-9kuv1CM2L5m1pKS8owAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack