π©πͺ
MarkGGN
2026-09-03 21:27:33
(31 minutes ago)
Web attack. 2a01:230:4:7bc::2 - - [03/Sep/2026:23:27:32 +0200] "GET /.env HTTP/1.1" 444 0 "-" "Mozil ...
show more
Web attack. 2a01:230:4:7bc::2 - - [03/Sep/2026:23:27:32 +0200] "GET /.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
2a01:230:4:7bc::2 - - [03/Sep/2026:23:27:32 +0200] "GET /.git/config HTTP/1.1" 404 1428 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36"
show less
Web App Attack
π¨π
4server
2026-09-03 21:18:16
(40 minutes ago)
[ThuSep0323:18:08.6471562026][security2:error][pid1771357:tid1771604][client2a01:230:4:7bc::2:0]ModS ...
show more
[ThuSep0323:18:08.6471562026][security2:error][pid1771357:tid1771604][client2a01:230:4:7bc::2:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.swiss-web-hosting.hostingedominio.net\"][uri\"/.git/config\"][unique_id\"apnkEJxCYhkz1bLjuuia8wAAAI4\"]
show less
Hacking
Web App Attack
πΊπΈ
Charlesiv
2026-09-03 20:02:52
(1 hour ago)
Triggered Cloudflare WAF (firewallCustom) from RU.
Action taken: BLOCK
ASN: 29182 (JSC IOT)
Protocol ...
show more
Triggered Cloudflare WAF (firewallCustom) from RU.
Action taken: BLOCK
ASN: 29182 (JSC IOT)
Protocol: HTTP/1.1 (GET method)
Endpoint: /
Timestamp: 2026-09-03T19:25:24Z
Ray ID: a35723e55ab5d29d
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/126.0.0.0 Safari/537.36
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-03 18:58:20
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:230:4:7bc::2 (aleck.sawkin2016.fvds.ru): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:230:4:7bc::2 (aleck.sawkin2016.fvds.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 14:58:13.701176 2026] [security2:error] [pid 25552:tid 25552] [client 2a01:230:4:7bc::2:58250] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brownweddinginvitations.net"] [uri "/.git/config"] [unique_id "apnDRQ4vOv3dBr9mstxV9AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 17:21:47
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:230:4:7bc::2 (aleck.sawkin2016.fvds.ru): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:230:4:7bc::2 (aleck.sawkin2016.fvds.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 13:21:43.408660 2026] [security2:error] [pid 4472:tid 4472] [client 2a01:230:4:7bc::2:42028] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bokharienterprises.stbms.com"] [uri "/.git/config"] [unique_id "apmsp36brKvFKBb0au3v0QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 16:49:12
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:230:4:7bc::2 (aleck.sawkin2016.fvds.ru): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:230:4:7bc::2 (aleck.sawkin2016.fvds.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 12:49:04.746817 2026] [security2:error] [pid 28518:tid 28518] [client 2a01:230:4:7bc::2:52128] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.hg/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.newbook.flyingdodopublications.com"] [uri "/.hg/store/00manifest.i"] [unique_id "apmlADoYjcJ5erLy0adHDAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
pm33
2026-09-03 16:15:13
(5 hours ago)
Excessive crawling HTTP 404
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 13:59:28
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:230:4:7bc::2 (aleck.sawkin2016.fvds.ru): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:230:4:7bc::2 (aleck.sawkin2016.fvds.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 09:59:19.611476 2026] [security2:error] [pid 3980:tid 3980] [client 2a01:230:4:7bc::2:49074] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.hg/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.listitwithsteve.com"] [uri "/.hg/store/00manifest.i"] [unique_id "apl9NyZ8ca41FhA5246VyAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2026-09-03 13:32:59
(8 hours ago)
104 requests with url.path *debug.log
104 requests with url.path */debug.log
Brute-Force
Bad Web Bot
π©πͺ
big-cloud.nl
2026-09-03 13:17:17
(8 hours ago)
Try to access /.svn/entries
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 11:43:10
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:230:4:7bc::2 (aleck.sawkin2016.fvds.ru): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:230:4:7bc::2 (aleck.sawkin2016.fvds.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 07:43:02.333902 2026] [security2:error] [pid 4024:tid 4024] [client 2a01:230:4:7bc::2:57330] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.brooklyntrademarklawyers.karenbernsteinlaw.net"] [uri "/wp-config.php.bak"] [unique_id "apldRoPVu2YR3d_okuCzXwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 11:06:28
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a01:230:4:7bc::2 (aleck.sawkin2016.fvds.ru): 1 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a01:230:4:7bc::2 (aleck.sawkin2016.fvds.ru): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 07:06:20.901505 2026] [security2:error] [pid 22093:tid 22093] [client 2a01:230:4:7bc::2:51494] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.soulybygrace.com"] [uri "/.git/index"] [unique_id "aplUrKEIH2gaZ4ADYuxykQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
4server
2026-09-03 09:10:06
(12 hours ago)
[ThuSep0311:10:01.9693242026][security2:error][pid2696761:tid2696892][client2a01:230:4:7bc::2:0]ModS ...
show more
[ThuSep0311:10:01.9693242026][security2:error][pid2696761:tid2696892][client2a01:230:4:7bc::2:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.miotrentino.it\"][uri\"/.hg/store/00manifest.i\"][unique_id\"apk5aYNqjN7f9S5BBFUJAAAAARQ\"]
show less
Port Scan
Brute-Force
Web App Attack
π³π±
Site.eu
2026-09-03 08:37:29
(13 hours ago)
Excessive multi-domain requests
Brute-Force
π³π±
WeCloudit-Anti-Abuse
2026-09-03 06:32:02
(15 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking