๐บ๐ธ
TPI-Abuse
2026-09-16 16:08:54
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.54.92 (92.54.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.54.92 (92.54.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:08:50.093677 2026] [security2:error] [pid 21108:tid 21108] [client 35.200.54.92:36546] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.family.amgtr.com"] [uri "/.git/config"] [unique_id "aqq_EsEgx7z3p7xyjDXMSQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-16 15:34:20
(9 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
Eric
2026-09-16 15:17:39
(9 hours ago)
[Wed Sep 16 15:17:36.723496 2026] [security2:error] [pid 178289:tid 178289] [client 35.200.54.92:0] ...
show more
[Wed Sep 16 15:17:36.723496 2026] [security2:error] [pid 178289:tid 178289] [client 35.200.54.92:0] [client 35.200.54.92] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.fambus.nl"] [uri "/.git/config"] [unique_id "aqqzEORWdGA3kp2qqP_LawAAAA4"]
[Wed Sep 16 15:17:38.261732 2026] [security2:error] [pid 93391:tid 93391] [client 35.200.54.92:0] [client 35.200.54.92] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRIT
...
show less
Hacking
Web App Attack
๐ฉ๐ช
kkw
2026-09-16 14:53:16
(10 hours ago)
[REDACTED] 35.200.54.92 - - [16/Sep/2026:16:53:15 +0200] "GET /.git/config HTTP/1.1" 404 564 "-" "Mo ...
show more
[REDACTED] 35.200.54.92 - - [16/Sep/2026:16:53:15 +0200] "GET /.git/config HTTP/1.1" 404 564 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-16 14:47:33
(10 hours ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-09-16 14:40:07
(10 hours ago)
๐จ Repeated automated attempts to access prohibited paths and exploit known web application vulnerabi ...
show more
๐จ Repeated automated attempts to access prohibited paths and exploit known web application vulnerabilities.
show less
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-09-16 13:30:46
(11 hours ago)
Too many 404 requests [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 12:16:41
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.54.92 (92.54.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.54.92 (92.54.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 08:16:35.518400 2026] [security2:error] [pid 31752:tid 31752] [client 35.200.54.92:54596] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.flanav1.yankeetownfishing.com"] [uri "/.git/config"] [unique_id "aqqIo1SjxGI5gk5SP6wcdwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ger-stg-sifi1
2026-09-16 09:11:52
(15 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-16 08:25:13
(16 hours ago)
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-16 07:50:21
(17 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-16 07:42:20
(17 hours ago)
35.200.54.92 - - [16/Sep/2026:09:42:14 +0200] "POST / HTTP/1.1" 200 1526 "-" "Mozilla/5.0 (Macintosh ...
show more
35.200.54.92 - - [16/Sep/2026:09:42:14 +0200] "POST / HTTP/1.1" 200 1526 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.200.54.92 - - [16/Sep/2026:09:42:14 +0200] "GET /.env HTTP/1.1" 404 511 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.200.54.92 - - [16/Sep/2026:09:42:14 +0200] "GET /.env.local HTTP/1.1" 404 511 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.200.54.92 - - [16/Sep/2026:09:42:15 +0200] "GET /.env.production HTTP/1.1" 404 511 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.200.54.92 - - [16/Sep/2026:09:42:15 +0200] "GET /.env.staging HTTP/1.1" 404 511 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0
show less
Web App Attack
Hacking
๐บ๐ธ
dot.mg
2026-09-16 07:21:02
(17 hours ago)
Bad behaviour
Web Spam
๐ธ๐ช
vaia.cloud
2026-09-16 06:45:02
(18 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-16 05:46:37
(19 hours ago)
20 attempts against mh-misbehave-ban on twig
Brute-Force
Bad Web Bot
Web App Attack