๐จ๐ญ
Origon
2026-09-16 03:44:53
(2 days ago)
http-sensitive-files - IP: 35.195.123.209 - time="2026-09-16T05:44:53+02:00" level=info msg="(555f6 ...
show more
http-sensitive-files - IP: 35.195.123.209 - time="2026-09-16T05:44:53+02:00" level=info msg="(555f66b4f6a74558bc11e3f93469658es8App0Mcc0TKEeje/crowdsec) crowdsecurity/http-sensitive-files by ip 35.195.123.209 (BE/396982) : 4h ban on Ip 35.195.123.209" module=db
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 14:34:53
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.195.123.209 (209.123.195.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.123.209 (209.123.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:34:49.145456 2026] [security2:error] [pid 15937:tid 15955] [client 35.195.123.209:60312] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leaderoftheopposition.com"] [uri "/.git/config"] [unique_id "aqlXiZ5OIubAX9DnLC5TYwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 12:14:06
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.195.123.209 (209.123.195.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.123.209 (209.123.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 08:13:58.707350 2026] [security2:error] [pid 27266:tid 27266] [client 35.195.123.209:44716] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leadek.com"] [uri "/.git/config"] [unique_id "aqk2htEdNVBKj6CC3hfrwQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-15 11:15:09
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 06:54:56
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.195.123.209 (209.123.195.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.123.209 (209.123.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 02:54:48.034712 2026] [security2:error] [pid 24165:tid 24165] [client 35.195.123.209:43728] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "indie100.com"] [uri "/.git/config"] [unique_id "aqjruNoPrq_8dswpCLtcDQAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
HostingGroup
2026-09-15 06:51:53
(3 days ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 7. First blocked: 2026-09-15.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-15 06:50:52
(3 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+9 more) | 2026-09-15 06:50 UTC
show less
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-09-15 06:04:18
(3 days ago)
Multiple WAF Violations
Web App Attack
๐ฏ๐ต
Watch40x
2026-09-15 02:23:37
(3 days ago)
Automated report from Watch40x security system. Web application probing detected.
Web App Attack