🇺🇸
TPI-Abuse
2026-09-07 06:46:16
(11 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.252.28.174 (174.28.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.28.174 (174.28.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:46:07.671321 2026] [security2:error] [pid 30014:tid 30014] [client 35.252.28.174:60984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.substack.diegolaje.com"] [uri "/.git/config"] [unique_id "ap5dr1M_DOpqrm_drOaN-wAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 05:10:09
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.252.28.174 (174.28.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.28.174 (174.28.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 01:10:00.271334 2026] [security2:error] [pid 12388:tid 12388] [client 35.252.28.174:34482] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sublimationconsultants.ipostsocialmedia.com"] [uri "/.git/config"] [unique_id "ap5HKDJvf5OlmT3hQBxoYQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 01:40:31
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.28.174 (174.28.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.28.174 (174.28.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 21:40:25.675221 2026] [security2:error] [pid 25248:tid 25248] [client 35.252.28.174:43288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.styxfreeworld.grayhost.net"] [uri "/.git/config"] [unique_id "ap4WCTzkZ8s8_EtIlejHqwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Stylottica
2026-09-07 01:21:21
(5 hours ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
🇬🇧
andypiper
2026-09-07 01:01:55
(5 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇩🇪
EGP Abuse Dept
2026-09-07 00:12:21
(6 hours ago)
Scanning for web/db/file exploits on www.styleoptiek.nl
SQL Injection
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 22:50:17
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.28.174 (174.28.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.28.174 (174.28.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:50:13.319977 2026] [security2:error] [pid 20495:tid 20495] [client 35.252.28.174:39394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stygianpassage.com.greighhouse.com"] [uri "/.git/config"] [unique_id "ap3uJRZkLrt1yLVX-C3u6gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-06 22:07:53
(8 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-06 22:02:42
(8 hours ago)
Auto-ban: >3000 req/min op 2026-09-06
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-06 21:28:58
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.28.174 (174.28.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.28.174 (174.28.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:28:53.788109 2026] [security2:error] [pid 10764:tid 10875] [client 35.252.28.174:41098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stupidlikeyou.ceol.us"] [uri "/.git/config"] [unique_id "ap3bFd9O9H0i-tisIKBwHAAAAE0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇴
jad-abuse
2026-09-06 20:58:47
(9 hours ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, env_probe, source_backup, server_status, wp_admin. Observed by 1 sensor(s); 213 hits.
show less
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-06 20:40:12
(10 hours ago)
Excessive multi-domain requests
Brute-Force
🇨🇭
backslash
2026-09-06 20:21:07
(10 hours ago)
block ruleset likely probe for CVE-2025-55182 619E65C9C14E5E741C55CC8FD5E5630F031EBB6A
Web App Attack
🇳🇱
Savvii
2026-09-06 20:12:22
(10 hours ago)
20 attempts against mh-misbehave-ban on orcus
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 20:03:16
(10 hours ago)
35.252.28.174 - - [06/Sep/2026:22:03:12 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows N ...
show more
35.252.28.174 - - [06/Sep/2026:22:03:12 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.252.28.174 - - [06/Sep/2026:22:03:13 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.252.28.174 - - [06/Sep/2026:22:03:13 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.252.28.174 - - [06/Sep/2026:22:03:13 +0200] "GET /.git/config HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.252.28.174 - - [06/Sep/2026:22:03:13 +0200] "GET /.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.252.28.174 - - [06/Sep/2026:2
...
show less
Bad Web Bot
Web App Attack