🇺🇸
TPI-Abuse
2026-09-07 06:57:29
(47 minutes ago)
(mod_security) mod_security (id:210492) triggered by 8.228.192.89 (89.192.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.192.89 (89.192.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:57:22.259411 2026] [security2:error] [pid 23551:tid 23551] [client 8.228.192.89:49854] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.time.ggisoft.com"] [uri "/.git/config"] [unique_id "ap5gUrx8TWxj59xfLOGSZAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-07 06:39:16
(1 hour ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇳🇱
Site.eu
2026-09-07 06:38:45
(1 hour ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 06:35:24
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 8.228.192.89 (89.192.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.192.89 (89.192.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:35:19.176965 2026] [security2:error] [pid 17869:tid 17869] [client 8.228.192.89:35364] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.timcsite.com.woosterclassof64.com"] [uri "/.git/config"] [unique_id "ap5bJxeJmUdmB35LAG2yAAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 06:06:54
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 8.228.192.89 (89.192.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.192.89 (89.192.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:06:46.884104 2026] [security2:error] [pid 12217:tid 12217] [client 8.228.192.89:33606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.timbertoysbt.bigskyprints.com"] [uri "/.git/config"] [unique_id "ap5UdlrOTAxHoSysFt_0xQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 05:33:01
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.192.89 (89.192.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.192.89 (89.192.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 01:32:55.918325 2026] [security2:error] [pid 26659:tid 26659] [client 8.228.192.89:40562] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.timbercreek-130.bahamascruisersguide.com"] [uri "/.git/config"] [unique_id "ap5Mh_BwbD_Z8kpBTo7GCQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-07 05:18:34
(2 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-07 04:11:07
(3 hours ago)
8.228.192.89 - - [07/Sep/2026:06:11:03 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux ...
show more
8.228.192.89 - - [07/Sep/2026:06:11:03 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.228.192.89 - - [07/Sep/2026:06:11:03 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.228.192.89 - - [07/Sep/2026:06:11:03 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.228.192.89 - - [07/Sep/2026:06:11:03 +0200] "GET /.git/config HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.228.192.89 - - [07/Sep/2026:06:11:04 +0200] "GET /.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.228.192.89 - - [07/Sep/2026:06:11:04 +0200] "GET /.env.local HTTP/1.1" 403 183 "-" "M
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 03:31:36
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.192.89 (89.192.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.192.89 (89.192.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 23:31:28.859822 2026] [security2:error] [pid 15330:tid 15330] [client 8.228.192.89:58690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tileoptima.mooseled.com"] [uri "/.git/config"] [unique_id "ap4wEJ4PZ-MSOcWFLPI2bQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-07 03:05:36
(4 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
🇧🇪
cmbplf
2026-09-07 02:36:56
(5 hours ago)
160 requests with url.path *.php.bak
Brute-Force
Bad Web Bot
🇸🇪
vaia.cloud
2026-09-07 02:05:16
(5 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 01:57:25
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.192.89 (89.192.228.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.192.89 (89.192.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 21:57:18.415861 2026] [security2:error] [pid 6550:tid 6550] [client 8.228.192.89:59278] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tiki.jeremyscraig.com"] [uri "/.git/config"] [unique_id "ap4Z_o9_PG9F_P2--xLPhAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-07 01:37:38
(6 hours ago)
Aggressive web search of vulnerable pages: / /.env /.env.local /app/.env /apps/.env ...
Web App Attack
Anonymous
2026-09-07 01:29:08
(6 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking