🇩🇪
LRob
2026-09-07 05:23:47
(10 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-07 05:23 UTC
show less
Hacking
Web App Attack
🇳🇱
Site.eu
2026-09-07 04:46:05
(11 hours ago)
Excessive multi-domain requests
Brute-Force
🇳🇱
WeCloudit-Anti-Abuse
2026-09-07 04:43:09
(11 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇳🇱
svr
2026-09-07 04:31:50
(11 hours ago)
Abusive Automated Web Scanner
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 03:05:54
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.233.195 (195.233.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.233.195 (195.233.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 23:05:50.538902 2026] [security2:error] [pid 1775985:tid 1776032] [client 35.194.233.195:44318] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.isa-energy.net.oplconnect.com"] [uri "/.git/config"] [unique_id "ap4qDgFr_IfloKDM32emoQAAAUo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 01:30:45
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.233.195 (195.233.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.233.195 (195.233.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 21:30:41.549939 2026] [security2:error] [pid 1026401:tid 1026401] [client 35.194.233.195:51880] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.iptncolon.cyber507.net"] [uri "/.git/config"] [unique_id "ap4TwRaaQBrOsMW-uT_I6gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 19:51:11
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.233.195 (195.233.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.233.195 (195.233.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 15:51:06.690424 2026] [security2:error] [pid 4353:tid 4353] [client 35.194.233.195:58660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sicktrax.com"] [uri "/.git/config"] [unique_id "ap3EKq1FtIT7yWias92V2wAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-06 08:12:41
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 07:11:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.194.233.195 (195.233.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.233.195 (195.233.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 03:11:13.436011 2026] [security2:error] [pid 27124:tid 27152] [client 35.194.233.195:41568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.georgementz.com.aafm.us"] [uri "/.git/config"] [unique_id "ap0SER3goX6S0YCm-4ntAgAAAJg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-06 06:47:57
(1 day ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
Anonymous
2026-09-06 04:18:03
(1 day ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
🇧🇪
cmbplf
2026-09-06 00:28:02
(1 day ago)
4.755 requests with url.path *.env
934 requests with url.path *phpinfo.php
Brute-Force
Bad Web Bot
🇨🇦
john doe
2026-09-06 00:16:46
(1 day ago)
SentinelBot: Secret-path hunting (5 distinct paths): Env File Hunting (score: 61)
Bad Web Bot
🇨🇭
backslash
2026-09-06 00:09:22
(1 day ago)
block ruleset likely probe for CVE-2025-55182 619E65C9C14E5E741C55CC8FD5E5630F031EBB6A
Web App Attack
Anonymous
2026-09-05 23:23:33
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack