๐ณ๐ฑ
Site.eu
2026-09-17 21:01:54
(47 minutes ago)
Excessive 404/403 errors
Brute-Force
๐ฎ๐ณ
evicky2002
2026-09-17 06:00:05
(15 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
Site.eu
2026-09-17 02:38:34
(19 hours ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
homeshowdomain.nl
2026-09-16 22:02:12
(23 hours ago)
Auto-ban: >3000 req/min op 2026-09-16
Web App Attack
SSH
Hacking
๐ฉ๐ช
marten_o
2026-09-16 18:55:46
(1 day ago)
35.199.78.44 - - [16/Sep/2026:20:55:45 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 404 236 "-" "Mozilla/5 ...
show more
35.199.78.44 - - [16/Sep/2026:20:55:45 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 404 236 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 339 458
...
show less
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-16 18:40:02
(1 day ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ฉ๐ช
LRob
2026-09-16 17:46:22
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config | 2026-09-16 17:46 UTC
show less
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-16 14:59:56
(1 day ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
kosada.com
2026-09-16 14:26:31
(1 day ago)
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla ...
show more
Repeated exploit attempts, for example: /.env.staging /.env (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36")
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:55:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.199.78.44 (44.78.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.78.44 (44.78.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:55:51.854902 2026] [security2:error] [pid 23399:tid 23399] [client 35.199.78.44:54574] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.eileensbakeryandcafe.cathrynn.com"] [uri "/.git/config"] [unique_id "aqqf5z2ueRatzJl0uJ_r9QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:28:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.199.78.44 (44.78.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.78.44 (44.78.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:28:17.959299 2026] [security2:error] [pid 7872:tid 7872] [client 35.199.78.44:55526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ericmedley.tremulant.com"] [uri "/.git/config"] [unique_id "aqqZccIztuUDbRRwuD_nEgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-16 13:05:15
(1 day ago)
Scanning/Probing (13)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 12:54:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.199.78.44 (44.78.199.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.78.44 (44.78.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 08:54:02.062766 2026] [security2:error] [pid 17758:tid 17758] [client 35.199.78.44:47144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ehrlichfamily.com.ehrlichmedia.com"] [uri "/.git/config"] [unique_id "aqqRalhcDa2Pm650cUJICAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-16 11:21:47
(1 day ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.199.78.44 - - [16/Sep/2026:13:21:36 +0200] "GET /.git/config HTTP/1.1" 301 648 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-16 11:05:02
(1 day ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack