🇩🇪
pscriptos
2026-09-15 01:25:21
(14 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇩🇪
Melle
2026-09-15 01:25:04
(14 hours ago)
Blocked by CrowdSec | Scenario: crowdsecurity/http-sensitive-files | 35.198.18.177 triggered 5 event ...
show more
Blocked by CrowdSec | Scenario: crowdsecurity/http-sensitive-files | 35.198.18.177 triggered 5 events | Detected: 2026-09-15T01:25:01.608235809Z
show less
Web App Attack
Hacking
🇳🇱
Eric
2026-09-15 00:27:14
(15 hours ago)
[Tue Sep 15 00:27:13.362047 2026] [security2:error] [pid 2442180:tid 2442180] [client 35.198.18.177: ...
show more
[Tue Sep 15 00:27:13.362047 2026] [security2:error] [pid 2442180:tid 2442180] [client 35.198.18.177:0] [client 35.198.18.177] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.fambus.nl"] [uri "/.git/config"] [unique_id "aqiQ4R4X-jGSAhU3hz6GggAAAAc"]
[Tue Sep 15 00:27:13.903363 2026] [security2:error] [pid 2442180:tid 2442180] [client 35.198.18.177:0] [client 35.198.18.177] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [seve
...
show less
Hacking
Web App Attack
Anonymous
2026-09-14 22:16:19
(17 hours ago)
🚨 Repeated automated attempts to access prohibited paths and exploit known web application vulnerabi ...
show more
🚨 Repeated automated attempts to access prohibited paths and exploit known web application vulnerabilities.
show less
Bad Web Bot
Web App Attack
🇩🇪
paissangroup
2026-09-14 22:10:48
(17 hours ago)
Multiple WAF Violations
Web App Attack
🇩🇪
33three
2026-09-14 18:33:27
(21 hours ago)
Fail2Ban jail WebAttack triggered
Brute-Force
🇳🇱
Site.eu
2026-09-14 16:46:54
(23 hours ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
FD-IX
2026-09-14 13:49:13
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
Anonymous
2026-09-14 13:46:16
(1 day ago)
35.198.18.177 - - [14/Sep/2026:15:46:12 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh ...
show more
35.198.18.177 - - [14/Sep/2026:15:46:12 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.198.18.177 - - [14/Sep/2026:15:46:12 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.198.18.177 - - [14/Sep/2026:15:46:13 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.198.18.177 - - [14/Sep/2026:15:46:13 +0200] "GET /.git/config HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.198.18.177 - - [14/Sep/2026:15:46:13 +0200] "GET /.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35
...
show less
Bad Web Bot
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-14 13:36:52
(1 day ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇦🇹
penguin-solutions.at
2026-09-14 11:06:58
(1 day ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
🇬🇧
consul.to
2026-09-14 10:32:29
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
🇮🇹
Inartis
2026-09-14 10:10:11
(1 day ago)
35.198.18.177 - - [14/Sep/2026:12:10:10 +0200] "GET /.git/config HTTP/1.1" 200 51410 "-" "Mozilla/5. ...
show more
35.198.18.177 - - [14/Sep/2026:12:10:10 +0200] "GET /.git/config HTTP/1.1" 200 51410 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.198.18.177 - - [14/Sep/2026:12:10:10 +0200] "GET /.git/config HTTP/1.1" 200 51410 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-14 05:32:26
(1 day ago)
Excessive 404/403 errors
Brute-Force
🇫🇷
masterguru
2026-09-14 05:09:31
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack