π¨π
4server
2026-09-15 20:54:52
(6 hours ago)
[TueSep1522:54:45.9079082026][security2:error][pid1970070:tid1970198][client8.235.49.79:0]ModSecurit ...
show more
[TueSep1522:54:45.9079082026][security2:error][pid1970070:tid1970198][client8.235.49.79:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"mail.annunci-ticino.ch.81-17-25-250.cpanel.site\"][uri\"/.git/config\"][unique_id\"aqmwlW4knsxaH4paGT9v_wAAAM8\"]
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 20:38:58
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.235.49.79 (79.49.235.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.235.49.79 (79.49.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:38:54.124948 2026] [security2:error] [pid 1265:tid 1265] [client 8.235.49.79:58660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.anngardner.net"] [uri "/.git/config"] [unique_id "aqms3k3qxYHUdFqzdvyB2gAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
R.G.
2026-09-15 19:26:41
(7 hours ago)
(ScanningForFiles) Scanning for files triggerd 8.235.49.79 (US/United States/79.49.235.8.bc.googleus ...
show more
(ScanningForFiles) Scanning for files triggerd 8.235.49.79 (US/United States/79.49.235.8.bc.googleusercontent.com): 10 in the last 900 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 11:27:33
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.235.49.79 (79.49.235.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.235.49.79 (79.49.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 07:27:28.621882 2026] [security2:error] [pid 17986:tid 17986] [client 8.235.49.79:48390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "naturev.net"] [uri "/.git/config"] [unique_id "aqkroCEJwA4SRoivoTQXWQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-09-15 10:37:49
(16 hours ago)
Excessive 404/403 errors
Brute-Force
πΊπΈ
nasset
2026-09-15 07:15:20
(19 hours ago)
8.235.49.79 - - [15/Sep/2026:00:15:18 -0700] "GET /admin/.env HTTP/1.1" 403 640 "-" "Mozilla/5.0 (Wi ...
show more
8.235.49.79 - - [15/Sep/2026:00:15:18 -0700] "GET /admin/.env HTTP/1.1" 403 640 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.235.49.79 - - [15/Sep/2026:00:15:19 -0700] "GET /backend/.env HTTP/1.1" 403 640 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.235.49.79 - - [15/Sep/2026:00:15:19 -0700] "GET /server/.env HTTP/1.1" 403 640 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.235.49.79 - - [15/Sep/2026:00:15:19 -0700] "GET /frontend/.env HTTP/1.1" 403 640 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.235.49.79 - - [15/Sep/2026:00:15:19 -0700] "GET /src/.env HTTP/1.1" 403 640 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
π©πͺ
ghostwarriors
2026-09-15 06:50:07
(20 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 06:39:49
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.235.49.79 (79.49.235.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.235.49.79 (79.49.235.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 02:39:44.070692 2026] [security2:error] [pid 9203:tid 9203] [client 8.235.49.79:41730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nashes.net"] [uri "/.git/config"] [unique_id "aqjoMIPSg5UMv3NHoDt-vwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
ksol-hostmaster
2026-09-15 06:22:45
(20 hours ago)
2026/09/15 08:22:45 [error] 46485#1053195: *6463037 access forbidden by rule, client: 8.235.49.79, s ...
show more
2026/09/15 08:22:45 [error] 46485#1053195: *6463037 access forbidden by rule, client: 8.235.49.79, server: chat.crxforum.ksol.io, request: "GET / HTTP/1.1", host: "chat.crxforum.ksol.io"
...
show less
Web Spam
π«π·
dynamix
2026-09-15 06:18:49
(20 hours ago)
Automated web vulnerability and path enumeration scan with excessive 404 requests
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 03:22:04
(23 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking