🇩🇪
ghostwarriors
2026-09-07 13:20:08
(20 minutes ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-07 13:11:19
(28 minutes ago)
35.204.145.182 - - [07/Sep/2026:15:11:16 +0200] "GET /api/.env HTTP/1.1" 404 1267 "-" "Mozilla/5.0 ( ...
show more
35.204.145.182 - - [07/Sep/2026:15:11:16 +0200] "GET /api/.env HTTP/1.1" 404 1267 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.204.145.182 - - [07/Sep/2026:15:11:16 +0200] "GET /web/.env HTTP/1.1" 404 1267 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.204.145.182 - - [07/Sep/2026:15:11:16 +0200] "GET /site/.env HTTP/1.1" 404 1267 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.204.145.182 - - [07/Sep/2026:15:11:16 +0200] "GET /public/.env HTTP/1.1" 404 1267 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.204.145.182 - - [07/Sep/2026:15:11:16 +0200] "GET /admin/.env HTTP/1.1" 404 1267 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.204.145.182 - - [07/Sep/2026:15:11:16 +02
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 09:38:07
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.204.145.182 (182.145.204.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.145.182 (182.145.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:38:02.869965 2026] [security2:error] [pid 12850:tid 12873] [client 35.204.145.182:40454] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.henrisphoto.robertdanielsllc.com"] [uri "/.git/config"] [unique_id "ap6F-t4wJmaIpolrXSEi0gAAAVQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
taivas.nl
2026-09-07 09:32:20
(4 hours ago)
Bad_requests
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 09:10:07
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.204.145.182 (182.145.204.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.145.182 (182.145.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:09:59.883234 2026] [security2:error] [pid 29674:tid 29674] [client 35.204.145.182:43524] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.hazardrecords.org.ankitoner.com"] [uri "/.git/config"] [unique_id "ap5_Z7QBm8exm-Kuov4ZZQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-07 08:46:57
(4 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 08:44:54
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.204.145.182 (182.145.204.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.145.182 (182.145.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:44:47.057798 2026] [security2:error] [pid 4446:tid 4446] [client 35.204.145.182:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.haywardcarpentry.com"] [uri "/.git/config"] [unique_id "ap55f1lG6NmG600ciYvXdgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
ConsulHosting
2026-09-07 07:52:31
(5 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇩🇪
4server
2026-09-07 04:15:03
(9 hours ago)
[MonSep0706:14:56.4897432026][security2:error][pid3788636:tid3788682][client35.204.145.182:0]ModSecu ...
show more
[MonSep0706:14:56.4897432026][security2:error][pid3788636:tid3788682][client35.204.145.182:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.helvetica-advisors.ch.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"ap46QBk0ZPjVXtPDi8EWuwAAAYo\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
WPJoe
2026-09-07 04:03:59
(9 hours ago)
35.204.145.182 - - [07/Sep/2026:04:03:49 +0000] "GET /.git/config HTTP/1.1" 403 422 "-" "Mozilla/5.0 ...
show more
35.204.145.182 - - [07/Sep/2026:04:03:49 +0000] "GET /.git/config HTTP/1.1" 403 422 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.204.145.182 - - [07/Sep/2026:04:03:50 +0000] "GET /.env HTTP/1.1" 403 422 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.204.145.182 - - [07/Sep/2026:04:03:50 +0000] "GET /.env.local HTTP/1.1" 403 422 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.204.145.182 - - [07/Sep/2026:04:03:50 +0000] "GET /.env.production HTTP/1.1" 403 422 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.204.145.182 - - [07/Sep/2026:04:03:51 +0000] "GET /.env.staging HTTP/1.1" 403 422 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.204.145.182 - - [07/Sep/2026:04:03:51 +0
...
show less
Web App Attack
Bad Web Bot
🇬🇧
consul.to
2026-09-07 04:01:45
(9 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
Mangelot Hosting
2026-09-07 03:19:17
(10 hours ago)
(php_susp_dir) srv102 PHP Suspicious Directory 35.204.145.182 (NL/The Netherlands/182.145.204.35.bc. ...
show more
(php_susp_dir) srv102 PHP Suspicious Directory 35.204.145.182 (NL/The Netherlands/182.145.204.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
Anonymous
2026-09-07 03:13:15
(10 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-07 02:23:24
(11 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 01:51:16
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.204.145.182 (182.145.204.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.145.182 (182.145.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 21:51:08.849503 2026] [security2:error] [pid 2019:tid 2019] [client 35.204.145.182:56386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.helpchd.rememberingemily.com"] [uri "/.git/config"] [unique_id "ap4YjLY2xw_PVUCyyA1VXQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack