πΊπΈ
antlac1
2026-09-01 13:13:51
(3 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 12:34:37
(4 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.198.46.84 (84.46.198.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 35.198.46.84 (84.46.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 08:34:29.923153 2026] [security2:error] [pid 16706:tid 16706] [client 35.198.46.84:55552] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.gatewayacoustics.armstrongenvironmental.com"] [uri "/.git/config"] [unique_id "apbGVVFArPY2N1aUjrzX3AAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-09-01 11:52:19
(5 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-01 09:33:42
(7 hours ago)
35.198.46.84 - - [01/Sep/2026:09:33:42 +0000] "GET /.git/config HTTP/1.1" 404 3831 "-" "Mozilla/5.0 ...
show more
35.198.46.84 - - [01/Sep/2026:09:33:42 +0000] "GET /.git/config HTTP/1.1" 404 3831 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
zwebvigil
2026-09-01 08:11:12
(8 hours ago)
35.198.46.84 [01/Sep/2026:01:11:10 -0700] "GET /.git/config HTTP/1.1" 404 2687 "-" port=42866 "Mozi ...
show more
35.198.46.84 [01/Sep/2026:01:11:10 -0700] "GET /.git/config HTTP/1.1" 404 2687 "-" port=42866 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" "-" "www.<host>" 832
35.198.46.84 [01/Sep/2026:01:11:11 -0700] "GET /.env HTTP/1.1" 404 2673 "-" port=42866 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" "-" "www.<host>" 1057
35.198.46.84 [01/Sep/2026:01:11:11 -0700] "GET /.env.local HTTP/1.1" 404 2685 "-" port=42866 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" "-" "www.<host>" 676
35.198.46.84 [01/Sep/2026:01:11:11 -0700] "GET /.env.production HTTP/1.1" 404 2695 "-" port=42866 "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" "-" "www.<host>" 851
35.198.46.84 [01/Sep/2026:01:1
show less
Web App Attack
π©πͺ
FD-IX
2026-09-01 06:45:18
(10 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
π¨π
4server
2026-09-01 05:21:46
(11 hours ago)
[TueSep0107:21:42.4287722026][security2:error][pid1908792:tid1908958][client35.198.46.84:0]ModSecuri ...
show more
[TueSep0107:21:42.4287722026][security2:error][pid1908792:tid1908958][client35.198.46.84:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.garnimolinazzo.ch.81-17-25-250.cpanel.site\"][uri\"/.git/config\"][unique_id\"apZg5grkee32vSHLBSLioAAAABc\"]
show less
Hacking
Web App Attack
π³π±
MM-bot
2026-09-01 04:50:05
(12 hours ago)
URL-probe: HTTP/1.1 GET request on /.git/config (2026-09-01 06:50:05 UTC+2)
Web App Attack
Hacking
π²π½
octageeks.com
2026-09-01 04:08:06
(12 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
π«π·
mrcrassi
2026-09-01 03:28:47
(13 hours ago)
Triggered Cloudflare WAF (firewallManaged) from BR.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST met ...
show more
Triggered Cloudflare WAF (firewallManaged) from BR.
Action taken: BLOCK
Protocol: HTTP/1.1 (POST method)
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
Anonymous
2026-09-01 02:42:39
(14 hours ago)
[ssd5.kdns.gr] httpd-config-scan: sites=www.gardenscare.gr; logs=/var/log/httpd/domains/gardenscare. ...
show more
[ssd5.kdns.gr] httpd-config-scan: sites=www.gardenscare.gr; logs=/var/log/httpd/domains/gardenscare.gr.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
π©πͺ
Philister11
2026-09-01 00:17:45
(16 hours ago)
CrowdSec: crowdsecurity/http-admin-interface-probing (BR/AS396982)
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-01 00:05:44
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.198.46.84 (84.46.198.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.46.84 (84.46.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 20:05:38.348963 2026] [security2:error] [pid 26368:tid 26368] [client 35.198.46.84:42534] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.garantagroup.com.bamedica.com"] [uri "/.git/config"] [unique_id "apYW0lkvBU1YTcxy24XS0gAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
Lee Daniel
2026-08-31 17:49:43
(23 hours ago)
35.198.46.84 - - [31/Aug/2026:13:49:42 -0400] "GET /.env HTTP/1.1" 403 6426 "-" "Mozilla/5.0 (Macint ...
show more
35.198.46.84 - - [31/Aug/2026:13:49:42 -0400] "GET /.env HTTP/1.1" 403 6426 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-31 14:44:37
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.198.46.84 (84.46.198.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.46.84 (84.46.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 10:44:32.767698 2026] [security2:error] [pid 23011:tid 23011] [client 35.198.46.84:56980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.greatwesternfirearms.deubellzebub.com"] [uri "/.git/config"] [unique_id "apWTUCzESFyCzq7NJOxcWwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack