๐ณ๐ฑ
homeshowdomain.nl
2026-08-28 21:59:45
(4 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-08-27.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 22:03:51
(5 days ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
๐ธ๐ช
nekopavel
2026-08-27 19:59:38
(5 days ago)
35.196.123.135 - - [27/Aug/2026:21:59:36 +0200]"GET /.git/config HTTP/1.1" 301 162"-" 78.69.8.25 "cr ...
show more
35.196.123.135 - - [27/Aug/2026:21:59:36 +0200]"GET /.git/config HTTP/1.1" 301 162"-" 78.69.8.25 "crusader-worker/1.0""0.000" "-""North Charleston" "US"
35.196.123.135 - - [27/Aug/2026:21:59:36 +0200]"GET /api/.git/config HTTP/1.1" 301 162"-" 78.69.8.25 "crusader-worker/1.0""0.000" "-""North Charleston" "US"
35.196.123.135 - - [27/Aug/2026:21:59:36 +0200]"GET /public/.git/config HTTP/1.1" 301 162"-" 78.69.8.25 "crusader-worker/1.0""0.000" "-""North Charleston" "US"
...
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 17:53:24
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.196.123.135 (135.123.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.123.135 (135.123.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 13:53:17.847603 2026] [security2:error] [pid 13319:tid 13319] [client 35.196.123.135:36900] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garrisonfinancial.net"] [uri "/api/.git/config"] [unique_id "apB5jbUj_u4jDz18En6WVwAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-27 16:09:38
(5 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-27 14:27:08
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.196.123.135 (135.123.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.123.135 (135.123.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 10:27:00.821432 2026] [security2:error] [pid 6257:tid 6257] [client 35.196.123.135:44736] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.family.hatfulofrain.com"] [uri "/src/.git/config"] [unique_id "apBJNGMmKBHO6oXIRN3KmQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-08-27 14:09:41
(5 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
seal
2026-08-27 12:28:20
(5 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
SSH
Brute-Force
๐ฉ๐ช
dom4k
2026-08-27 10:26:23
(5 days ago)
35.196.123.135 - - [27/Aug/2026:10:26:22 +0000] "GET /.git/config HTTP/1.1" 444 0 "-" "crusader-work ...
show more
35.196.123.135 - - [27/Aug/2026:10:26:22 +0000] "GET /.git/config HTTP/1.1" 444 0 "-" "crusader-worker/1.0"
...
show less
Web Spam
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-08-27 09:28:17
(5 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฎ๐น
abuseiphack
2026-08-27 09:12:28
(5 days ago)
Automatic report for brute force attack
Bad Web Bot
๐ฉ๐ช
4server
2026-08-27 09:05:37
(5 days ago)
[ThuAug2711:05:32.3058192026][security2:error][pid957212:tid957252][client35.196.123.135:0]ModSecuri ...
show more
[ThuAug2711:05:32.3058192026][security2:error][pid957212:tid957252][client35.196.123.135:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGEmatched5atTX:anomaly_score.[file\"/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf\"][line\"94\"][id\"949110\"][msg\"InboundAnomalyScoreExceeded\(TotalScore:5\)\"][severity\"CRITICAL\"][ver\"OWASP_CRS/3.3.10\"][tag\"application-multi\"][tag\"language-multi\"][tag\"platform-multi\"][tag\"attack-generic\"][hostname\"www.mgevents.ch.136-243-54-122.cpanel.site\"][uri\"/wordpress/.git/config\"][unique_id\"ao_93CC8Dh1TIZizkZnE1QAAAEQ\"]
show less
Port Scan
Brute-Force
Web App Attack
๐ฉ๐ช
stinpriza
2026-08-27 09:00:50
(5 days ago)
common Web Exploits being scanned
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-27 08:55:04
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.196.123.135 (135.123.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.123.135 (135.123.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 04:54:56.189771 2026] [security2:error] [pid 17299:tid 17299] [client 35.196.123.135:35698] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.general.cloudex.link"] [uri "/site/.git/config"] [unique_id "ao_7YNcFB0jjZy_bJFiXiwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-08-27 08:05:20
(5 days ago)
Scanning/Probing (24)
Brute-Force
Web App Attack