๐บ๐ธ
etu brutus
2026-09-04 00:37:11
(42 minutes ago)
35.254.196.10 has been banned for [WebApp Attack]
...
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 23:33:19
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.254.196.10 (10.196.254.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.196.10 (10.196.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:33:13.341729 2026] [security2:error] [pid 28326:tid 28326] [client 35.254.196.10:13834] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "frankweyer.com"] [uri "/.git/config"] [unique_id "apoDuQSv_2gAfevJ1L0vcgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
filou812
2026-09-03 23:18:06
(2 hours ago)
url tried is "/.git/config"
Web App Attack
๐ฉ๐ช
joharikop
2026-09-03 23:13:39
(2 hours ago)
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-cred ...
show more
Nginx: credential/secret file probe (/.env, /.git, /.aws etc). Automated ban via fail2ban nginx-credential-probes jail.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 22:20:12
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.254.196.10 (10.196.254.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.196.10 (10.196.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 18:20:07.757871 2026] [security2:error] [pid 29712:tid 29712] [client 35.254.196.10:54028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "essentialee.com"] [uri "/.git/config"] [unique_id "apnyl_ApTDqU_xRIK5165wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-03 22:19:46
(2 hours ago)
[FriSep0400:19:34.7434442026][security2:error][pid3484696:tid3484705][client35.254.196.10:0]ModSecur ...
show more
[FriSep0400:19:34.7434442026][security2:error][pid3484696:tid3484705][client35.254.196.10:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"eselectronic.ch\"][uri\"/.git/config\"][unique_id\"apnydm7GRXG5Lbr7gLOmIwAAAUE\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-03 22:15:37
(3 hours ago)
Multiple WAF Violations
Web App Attack
๐ฎ๐น
Inartis
2026-09-03 22:13:33
(3 hours ago)
35.254.196.10 - - [04/Sep/2026:00:13:32 +0200] "GET /.git/config HTTP/1.1" 403 5008 "-" "Mozilla/5.0 ...
show more
35.254.196.10 - - [04/Sep/2026:00:13:32 +0200] "GET /.git/config HTTP/1.1" 403 5008 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 20:31:27
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.254.196.10 (10.196.254.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.196.10 (10.196.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:31:21.673581 2026] [security2:error] [pid 20107:tid 20107] [client 35.254.196.10:10670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fetchamreadingroom.org"] [uri "/.git/config"] [unique_id "apnZGdOacDUgJ5ZnwJl8dwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 20:09:39
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.254.196.10 (10.196.254.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.196.10 (10.196.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 16:09:33.212213 2026] [security2:error] [pid 19500:tid 19500] [client 35.254.196.10:54088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dkdesign.click"] [uri "/.git/config"] [unique_id "apnT_TZu2IQAcne_7CnwWgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
Peregrine
2026-09-03 20:03:32
(5 hours ago)
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 35.254.196.10 104.22.14.70 - - [03/Sep/2026:17:03:2 ...
show more
Fail2Ban ct101 Jail: tomcat-honeypot | Evidence: 35.254.196.10 104.22.14.70 - - [03/Sep/2026:17:03:29 -0300] "GET /.git/config HTTP/1.1" 404 18193
show less
Bad Web Bot
๐ฉ๐ช
big-cloud.nl
2026-09-03 18:49:46
(6 hours ago)
Try to access /.git/config
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-03 18:48:57
(6 hours ago)
cloudlinux2 fail2ban: 2026-09-03 20:43:58,467 fail2ban.actions [1472]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-03 20:43:58,467 fail2ban.actions [1472]: NOTICE [plesk-modsecurity] Unban 34.125.144.181cloudlinux2 fail2ban: 2026-09-03 20:44:03,085 fail2ban.actions [1472]: NOTICE [plesk-modsecurity] Unban 51.77.70.237cloudlinux2 fail2ban: 2026-09-03 20:44:20,542 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 35.225.33.58 - 2026-09-03 20:44:20cloudlinux2 fail2ban: 2026-09-03 20:44:23,438 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 34.81.40.33 - 2026-09-03 20:44:23cloudlinux2 fail2ban: 2026-09-03 20:45:02,200 fail2ban.filter [1472]: INFO [plesk-wordpress] Found 45.131.193.203 - 2026-09-03 20:45:00cloudlinux2 fail2ban: 2026-09-03 20:45:06,366 fail2ban.actions [1472]: NOTICE [plesk-modsecurity] Unban 221.121.102.223cloudlinux2 fail2ban: 2026-09-03 20:45:10,011 fail2ban.filter [1472]: INFO [plesk-modsecurity] Found 35.254.196.10 - 2026-09-03 20:45:10cloudlinux2 fail2ban: 2026-09-03 20:45:26,799 fail2ban.filter
show less
Web App Attack
๐จ๐ฆ
Anytech
2026-09-03 17:31:51
(7 hours ago)
Blocked by ConnMonitor
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 16:58:43
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.254.196.10 (10.196.254.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.196.10 (10.196.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 12:58:38.334597 2026] [security2:error] [pid 28505:tid 28505] [client 35.254.196.10:53002] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fixitsmart.com"] [uri "/.git/config"] [unique_id "apmnPjUYD5venkTKNjaGmgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack