🇺🇸
TPI-Abuse
2026-09-08 17:49:19
(37 minutes ago)
(mod_security) mod_security (id:949110) triggered by 8.231.191.154 (154.191.231.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 8.231.191.154 (154.191.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:49:14.149706 2026] [security2:error] [pid 8478:tid 8478] [client 8.231.191.154:53684] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.hallemann.crazycontrols.com"] [uri "/.git/config"] [unique_id "aqBKmitSDaJQu8wAPWjTugAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Epimetheus
2026-09-08 17:18:30
(1 hour ago)
Unauthorized access attempts:
[GET] /.git/config
UA: Unknown
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 17:07:20
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 8.231.191.154 (154.191.231.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.191.154 (154.191.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 13:07:16.318475 2026] [security2:error] [pid 3797:tid 3797] [client 8.231.191.154:37828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gvimmobilier.com"] [uri "/.git/config"] [unique_id "aqBAxC7l-E5WAHwlC3CfJAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 16:49:16
(1 hour ago)
8.231.191.154 - - [08/Sep/2026:13:49:16 -0300] "GET /.git/config HTTP/1.1" 403 829 "-" "-"
...
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
🇺🇸
mnsf
2026-09-08 16:05:51
(2 hours ago)
Abuse Detected (37)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 15:43:54
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.231.191.154 (154.191.231.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.191.154 (154.191.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:43:49.511660 2026] [security2:error] [pid 10655:tid 10655] [client 8.231.191.154:56506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sentinel-sg.com.springmeadowventures.com"] [uri "/.git/config"] [unique_id "aqAtNdSu2ncP8JedskxDjgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
ALPHANET
2026-09-08 15:37:34
(2 hours ago)
web exploits
Hacking
Exploited Host
Web App Attack
Anonymous
2026-09-08 15:35:01
(2 hours ago)
suspicious request in access.log
Web App Attack
🇧🇪
cmbplf
2026-09-08 15:10:54
(3 hours ago)
2.892 requests with url.path */.git/config
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-08 15:07:38
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.231.191.154 (154.191.231.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.191.154 (154.191.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 11:07:31.794955 2026] [security2:error] [pid 14734:tid 14734] [client 8.231.191.154:39040] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.secure-rep.com"] [uri "/.git/config"] [unique_id "aqAks_SiB4gFYvE67CRoEQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-08 15:06:09
(3 hours ago)
Trying to access config files
Web App Attack
🇳🇿
Antinson
2026-09-08 15:05:19
(3 hours ago)
Requests to unauthorized or suspicious endpoints (.git, .well-known, .php, etc.)
Bad Web Bot
Anonymous
2026-09-08 14:54:53
(3 hours ago)
8.231.191.154 detected and blocked by apache-modsecurity after 1 try
Brute-Force
🇬🇧
Aetherweb Ark
2026-09-08 14:53:08
(3 hours ago)
(mod_security) mod_security (id:949110) triggered by 8.231.191.154 (US/United States/154.191.231.8.b ...
show more
(mod_security) mod_security (id:949110) triggered by 8.231.191.154 (US/United States/154.191.231.8.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 14:49:06
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.231.191.154 (154.191.231.8.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 8.231.191.154 (154.191.231.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 10:48:59.125185 2026] [security2:error] [pid 25064:tid 25064] [client 8.231.191.154:60368] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.seanevans.com"] [uri "/.git/config"] [unique_id "aqAgW8CNybGrwNvxDNGvTwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack