๐ฉ๐ช
klaus_ph
2026-09-28 01:04:52
(1 week ago)
2026-09-27 01:26:44,354 fail2ban.actions [8144]: NOTICE [ipblocklist] Ban 35.188.120.12
...
Bad Web Bot
๐ฉ๐ช
klaus_ph
2026-09-27 07:01:37
(1 week ago)
2026-09-26 02:48:35,205 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 35.188.120.12
.. ...
show more
2026-09-26 02:48:35,205 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 35.188.120.12
...
show less
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-09-24 21:59:05
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-23.
show less
Web App Attack
SSH
Hacking
๐ช๐ธ
robotstxt
2026-09-24 08:08:30
(1 week ago)
35.188.120.12 - - [24/Sep/2026:08:08:22 +0000] "GET /src/.git/config HTTP/1.1" 403 189 "-" "crusader ...
show more
35.188.120.12 - - [24/Sep/2026:08:08:22 +0000] "GET /src/.git/config HTTP/1.1" 403 189 "-" "crusader-worker/1.0" "-" edge="35.188.120.12"
35.188.120.12 - - [24/Sep/2026:08:08:22 +0000] "GET /var/www/.git/config HTTP/1.1" 403 189 "-" "crusader-worker/1.0" "-" edge="35.188.120.12"
35.188.120.12 - - [24/Sep/2026:08:08:22 +0000] "GET /.git/config HTTP/1.1" 403 189 "-" "crusader-worker/1.0" "-" edge="35.188.120.12"
35.188.120.12 - - [24/Sep/2026:08:08:22 +0000] "GET /public/.git/config HTTP/1.1" 403 189 "-" "crusader-worker/1.0" "-" edge="35.188.120.12"
35.188.120.12 - - [24/Sep/2026:08:08:22 +0000] "GET /html/.git/config HTTP/1.1" 403 189 "-" "crusader-worker/1.0" "-" edge="35.188.120.12"
...
show less
Web App Attack
๐บ๐ธ
inderiva6
2026-09-24 07:37:20
(1 week ago)
Automated HTTP(S) attack blocked by first-party WAF. FirstSeen=2026-09-24T07:37:19Z; LastSeen=2026-0 ...
show more
Automated HTTP(S) attack blocked by first-party WAF. FirstSeen=2026-09-24T07:37:19Z; LastSeen=2026-09-24T07:37:20Z; Requests=12; EvidenceHits=12; DistinctPaths=12; Methods=GET; Rules=scanner:12; SamplePaths=/.git/config|/api/.git/config|/app/.git/config|/backend/.git/config|/htdocs/.git/config; LogDigest=a642c50253f88380d89c3eb2da2fc9088de9d7ded7e59c88c8def4896a25012e.
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 03:07:32
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.188.120.12 (12.120.188.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.188.120.12 (12.120.188.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 23:07:26.834182 2026] [security2:error] [pid 14829:tid 14829] [client 35.188.120.12:53136] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.celestialworks.click"] [uri "/.git/config"] [unique_id "arST7gPqLe4cb-nryEn9QQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 02:47:42
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.188.120.12 (12.120.188.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.188.120.12 (12.120.188.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:47:38.965157 2026] [security2:error] [pid 16859:tid 16859] [client 35.188.120.12:45538] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.unwaved.com"] [uri "/src/.git/config"] [unique_id "arSPSi5p2U933f_lN9WxxQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 01:30:12
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.188.120.12 (12.120.188.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.188.120.12 (12.120.188.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:30:04.193795 2026] [security2:error] [pid 28928:tid 28928] [client 35.188.120.12:41450] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.westernmassaa.net"] [uri "/html/.git/config"] [unique_id "arR9HJQEJGGbt43cYaeMZwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-24 01:05:06
(1 week ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฌ๐ง
andypiper
2026-09-24 01:00:34
(1 week ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 00:16:29
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.188.120.12 (12.120.188.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.188.120.12 (12.120.188.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:16:26.053646 2026] [security2:error] [pid 13853:tid 13853] [client 35.188.120.12:56454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.davedoeswater.com"] [uri "/.git/config"] [unique_id "arRr2kKVyFbpLQ0CY0AhtAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
radardatelecom
2026-09-23 22:23:08
(1 week ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-23 21:59:25
(1 week ago)
Auto-ban: >3000 req/min op 2026-09-23
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-23 19:54:33
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.188.120.12 (12.120.188.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.188.120.12 (12.120.188.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:54:26.141097 2026] [security2:error] [pid 26434:tid 26434] [client 35.188.120.12:42836] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chrisbilder.com"] [uri "/www/.git/config"] [unique_id "arQucnZ1tHk6JGHSPOWMIgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-23 18:40:15
(1 week ago)
Multiple WAF Violations
Brute-Force
Web App Attack