🇬🇧
OptimusGO
2026-09-05 21:41:42
(8 hours ago)
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Time ...
show more
Malicious activity detected: web_attack
Server: commstackbc (185.127.18.66)
Attack: web_attack
Timestamp: 2026-09-05 22:41:42 UTC
Log evidence:
09/05/2026-22:41:41.708725 [wDrop] [**] [1:7000500:1] FINSERV CRITICAL: Aggressive Port Scan [**] [Classification: Attempted Information Leak] [Priority: 2] {TCP} 35.252.236.42:50792 -> 185.127.18.66:443
09/05/2026-22:41:41.708725 [**] [1:9000060:2] AUTONOMOUS Long-term Reconnaissance [**] [Classification: (null)] [Priority: 2] {TCP} 35.252.236.42:50792 -> 185.127.18.66:443
show less
Port Scan
Brute-Force
🇳🇱
homeshowdomain.nl
2026-09-04 22:00:32
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-03.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-09-04 21:21:42
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-04 20:34:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.252.236.42 (42.236.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.236.42 (42.236.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 16:34:22.490559 2026] [security2:error] [pid 17939:tid 17939] [client 35.252.236.42:47858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dlptir.us"] [uri "/public/.git/config"] [unique_id "apsrTqQuTLDhdBgXulFCNQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
big-cloud.nl
2026-09-04 20:05:34
(1 day ago)
Try to access /html/.git/config
Web App Attack
🇳🇱
MyGlobalFlowers
2026-09-04 16:31:08
(1 day ago)
Multiple WAF Violations
Web App Attack
🇮🇪
AutosOnShow
2026-09-04 14:59:05
(1 day ago)
blocked for webapp attack | path requested: /.git/config | seen at 2026-09-04 14:58:16.087 |
Web App Attack
🇫🇷
Jimbo67
2026-09-04 12:11:48
(1 day ago)
Cloudflare WAF: 11 hits in 30s | action=block | abuse=suspicious_probe | categories=19 | rule_id=332 ...
show more
Cloudflare WAF: 11 hits in 30s | action=block | abuse=suspicious_probe | categories=19 | rule_id=3329c9d804134f3e89780d69bfd872dc | URIs=/.git/config,/api/.git/config,/app/.git/config,/backend/.git/config,/htdocs/.git/config | confidence=0.82
show less
Bad Web Bot
🇺🇸
ambor
2026-09-04 11:35:02
(1 day ago)
Honeypot triggered: /.git/config on ifebridge.com. User-Agent: crusader-worker/1.0. Method: GET
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:44:36
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.252.236.42 (42.236.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.236.42 (42.236.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:44:32.042893 2026] [security2:error] [pid 19366:tid 19366] [client 35.252.236.42:60708] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "serconpri.com"] [uri "/htdocs/.git/config"] [unique_id "apqhEFJrhOl9RkiXmGDApQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 07:31:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.252.236.42 (42.236.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.236.42 (42.236.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 03:31:23.531876 2026] [security2:error] [pid 11425:tid 11425] [client 35.252.236.42:37192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brianbrock.horsesaw.com"] [uri "/www/.git/config"] [unique_id "appzy6KWPUXn6cp2ByUrCgAAACk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 06:19:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.252.236.42 (42.236.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.236.42 (42.236.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 02:19:41.474754 2026] [security2:error] [pid 31156:tid 31170] [client 35.252.236.42:33816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.dcsindo.com"] [uri "/app/.git/config"] [unique_id "appi_bXaduj_y9pQpylI0QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇦
URAN Publishing Service
2026-09-04 06:08:11
(2 days ago)
[04/Sep/2026:09:08:10 +0300] -- 35.252.236.42 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git ...
show more
[04/Sep/2026:09:08:10 +0300] -- 35.252.236.42 Ban reason: Scanner [CMS_GENERIC] | Request: GET /.git/config HTTP/1.1
show less
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-04 05:11:30
(2 days ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 04:55:06
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.252.236.42 (42.236.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.236.42 (42.236.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 00:54:59.221154 2026] [security2:error] [pid 28406:tid 28406] [client 35.252.236.42:48922] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.gilbertortegajewelry.com"] [uri "/api/.git/config"] [unique_id "appPIx-zHHSyD2atDT6mUAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack