๐ฉ๐ช
big-cloud.nl
2026-09-03 18:03:05
(8 minutes ago)
Try to access /.git/config
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 17:54:13
(16 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.253.162.22 (22.162.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.162.22 (22.162.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 13:54:09.439009 2026] [security2:error] [pid 24535:tid 24535] [client 35.253.162.22:24282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "coordinatedtechnology.net"] [uri "/.git/config"] [unique_id "apm0QWmeBp5KoqGXFTwddQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 17:28:31
(42 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.253.162.22 (22.162.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.162.22 (22.162.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 13:28:24.418942 2026] [security2:error] [pid 5656:tid 5656] [client 35.253.162.22:47372] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bookguardian.net"] [uri "/.git/config"] [unique_id "apmuOEkUdLMR4Pg-o7dozQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-03 17:08:57
(1 hour ago)
cloudlinux2 fail2ban: 2026-09-03 19:03:52,357 fail2ban.filter [1472]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-03 19:03:52,357 fail2ban.filter [1472]: INFO [plesk-wordpress] Found 89.67.37.2 - 2026-09-03 19:03:52cloudlinux2 fail2ban: 2026-09-03 19:04:23,349 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 136.112.68.82 - 2026-09-03 19:04:23cloudlinux2 fail2ban: 2026-09-03 19:05:37,751 fail2ban.filter [1472]: INFO [plesk-wordpress] Found 24.234.208.136 - 2026-09-03 19:05:37cloudlinux2 fail2ban: 2026-09-03 19:05:48,432 fail2ban.filter [1472]: INFO [plesk-wordpress] Found 45.146.55.184 - 2026-09-03 19:05:47cloudlinux2 fail2ban: 2026-09-03 19:07:16,280 fail2ban.filter [1472]: INFO [plesk-apache] Found 34.11.95.176 - 2026-09-03 19:07:16cloudlinux2 fail2ban: 2026-09-03 19:07:12,857 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 34.181.166.210 - 2026-09-03 19:07:12cloudlinux2 fail2ban: 2026-09-03 19:07:20,694 fail2ban.filter [1472]: INFO [plesk-apache] Found 34.11.95.176 - 2026-09-03 19:07:20cloudlinux2 fa
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 17:03:12
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.253.162.22 (22.162.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.162.22 (22.162.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 13:03:06.047120 2026] [security2:error] [pid 31106:tid 31106] [client 35.253.162.22:9964] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fourhillsco.com"] [uri "/.git/config"] [unique_id "apmoSjfplPM3-0dmU7MyBQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-03 16:47:32
(1 hour ago)
[ThuSep0318:47:30.0426182026][security2:error][pid3165891:tid3166146][client35.253.162.22:0]ModSecur ...
show more
[ThuSep0318:47:30.0426182026][security2:error][pid3165891:tid3166146][client35.253.162.22:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"essesolution.ch\"][uri\"/.git/config\"][unique_id\"apmkomppCsdlTBjVFaLgQwAAAEo\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 16:35:08
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.253.162.22 (22.162.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.162.22 (22.162.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 12:35:03.759887 2026] [security2:error] [pid 7455:tid 7455] [client 35.253.162.22:36290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dyslexiaspecialistsonline.com"] [uri "/.git/config"] [unique_id "apmhtyaeFlJtvCsgASYIvAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 15:43:20
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.253.162.22 (22.162.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.162.22 (22.162.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 11:43:15.142326 2026] [security2:error] [pid 17989:tid 17989] [client 35.253.162.22:8578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brandsmedia.com"] [uri "/.git/config"] [unique_id "apmVk4xtRfWZW4UJXJY7sgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 09:56:25
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.253.162.22 (22.162.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.162.22 (22.162.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 05:56:22.330523 2026] [security2:error] [pid 17468:tid 17468] [client 35.253.162.22:61726] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "unitedletter.com"] [uri "/.git/config"] [unique_id "aplERsaSseB6oN6Cd_lLQgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 09:20:19
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.253.162.22 (22.162.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.162.22 (22.162.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 05:20:13.320067 2026] [security2:error] [pid 18345:tid 18345] [client 35.253.162.22:7822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "switkoprofiri.org"] [uri "/.git/config"] [unique_id "apk7zUtIeHiIAaQz8QKUGgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
Bay13
2026-09-02 09:44:54
(1 day ago)
CrowdSec:custom/http-sensitive-files
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-01 21:59:10
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-31.
show less
Web App Attack
SSH
Hacking
๐จ๐ญ
4server
2026-09-01 20:10:03
(1 day ago)
[TueSep0122:10:00.2183332026][security2:error][pid536894:tid536984][client35.253.162.22:0]ModSecurit ...
show more
[TueSep0122:10:00.2183332026][security2:error][pid536894:tid536984][client35.253.162.22:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"safertechnics.ch\"][uri\"/.git/config\"][unique_id\"apcxGBCaAQmXGRy8m5PG_wAAABU\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 10:49:17
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.253.162.22 (22.162.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.162.22 (22.162.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 06:49:10.521971 2026] [security2:error] [pid 24071:tid 24071] [client 35.253.162.22:47122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jeffreyasweeney.com"] [uri "/.git/config"] [unique_id "apatpnoOEWVpOuz3g6bZygAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 09:14:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.253.162.22 (22.162.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.162.22 (22.162.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 05:14:18.464594 2026] [security2:error] [pid 14258:tid 14258] [client 35.253.162.22:3114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hiddentcgcards.com"] [uri "/.git/config"] [unique_id "apaXahcZqG0VmUYByAqmrQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack