Anonymous
2026-09-07 20:42:13
(42 minutes ago)
Bot / seems abusive / Apache connections: 20
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 20:20:21
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.252.49.205 (205.49.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.49.205 (205.49.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 16:20:17.243252 2026] [security2:error] [pid 23274:tid 23274] [client 35.252.49.205:46976] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.theseventhcongregationofladderdayvixens.org.tortoisehosting.com"] [uri "/.git/config"] [unique_id "ap8cgRDVbl7JeJEYWysppgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
pipeline.es
2026-09-07 19:22:04
(2 hours ago)
Web scanning / probing for vulnerable paths | URL: /jenkins/.env | Evidence: thesecrettravel.pt 35.2 ...
show more
Web scanning / probing for vulnerable paths | URL: /jenkins/.env | Evidence: thesecrettravel.pt 35.252.49.205 - - [07/Sep/2026:21:21:15 +0200] \"GET /jenkins/.env HTTP/1.1\" 404 22444 \"-\" \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=SA | ASN: GOOGLE-CLOUD-PLATFORM | Country: SA
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 18:04:37
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.49.205 (205.49.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.49.205 (205.49.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 14:04:30.692648 2026] [security2:error] [pid 28257:tid 28257] [client 35.252.49.205:55954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.theomegans.mroxygen.org"] [uri "/.git/config"] [unique_id "ap78rgwRf0SnR72PFMZ3uwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 17:27:57
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.49.205 (205.49.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.49.205 (205.49.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 13:27:53.592767 2026] [security2:error] [pid 872275:tid 872298] [client 35.252.49.205:49174] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thesardinemenmovie.plumeraproductions.com"] [uri "/.git/config"] [unique_id "ap70GbZBiXUuFNMTNeEcxgAAANE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-07 17:22:19
(4 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-07 16:55:00
(4 hours ago)
[da.kdns.gr] httpd-config-scan: sites=www.theofanisp.gr; logs=/var/log/httpd/domains/theofanisp.gr.l ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.theofanisp.gr; logs=/var/log/httpd/domains/theofanisp.gr.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
🇨🇦
Dunham Support
2026-09-07 16:36:33
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.252.49.205 (SA/Saudi Arabia/205.49.2 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.252.49.205 (SA/Saudi Arabia/205.49.252.35.bc.googleusercontent.com)
show less
SQL Injection
🇺🇸
TPI-Abuse
2026-09-07 14:58:01
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.49.205 (205.49.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.49.205 (205.49.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 10:57:54.270849 2026] [security2:error] [pid 623:tid 623] [client 35.252.49.205:42256] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thenotarymobile.com.trancelucid.com"] [uri "/.git/config"] [unique_id "ap7Q8tZajO_dsE4Uan_PzQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 14:02:41
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.49.205 (205.49.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.49.205 (205.49.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 10:02:38.087196 2026] [security2:error] [pid 12173:tid 12173] [client 35.252.49.205:39166] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thenitecapsbluesband.craftcare.net"] [uri "/.git/config"] [unique_id "ap7D_p45KLLADd9UCZYAFAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
screwlooseit.com.au
2026-09-07 13:10:29
(8 hours ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/205.49.252.35.bc.googleuserconten ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/205.49.252.35.bc.googleusercontent.com
show less
Web App Attack
🇩🇪
LRob
2026-09-07 12:25:25
(8 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-07 12:25 UTC
show less
Hacking
Web App Attack
🇳🇱
svr
2026-09-07 10:56:29
(10 hours ago)
Abusive Automated Web Scanner
Web App Attack
🇳🇱
ConsulHosting
2026-09-07 09:39:17
(11 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇺🇸
mnsf
2026-09-07 09:05:17
(12 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack