π©πͺ
pscriptos
2026-10-08 13:46:05
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
π©πͺ
4server
2026-10-08 12:40:22
(9 hours ago)
[ThuOct0814:40:16.7335052026][security2:error][pid2369405:tid2369503][client35.208.73.36:0]ModSecuri ...
show more
[ThuOct0814:40:16.7335052026][security2:error][pid2369405:tid2369503][client35.208.73.36:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"federicorella.ch.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"asePMPC-XEuQuycTIKUBmQAAAAE\"]
show less
Port Scan
Brute-Force
Web App Attack
π³π±
Site.eu
2026-10-08 12:28:27
(9 hours ago)
Excessive multi-domain requests
Brute-Force
π¬π§
consul.to
2026-10-08 12:12:02
(9 hours ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 09:14:42
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.208.73.36 (36.73.208.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.208.73.36 (36.73.208.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 05:14:36.057150 2026] [security2:error] [pid 7429:tid 7429] [client 35.208.73.36:49336] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "federallog.com"] [uri "/.git/config"] [unique_id "asde_HxpIwyUUfRUxcYTfgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 08:35:55
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.208.73.36 (36.73.208.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.208.73.36 (36.73.208.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 04:35:52.290959 2026] [security2:error] [pid 23975:tid 23975] [client 35.208.73.36:40762] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fedeoliva.cl"] [uri "/.git/config"] [unique_id "asdV6Blij3DcszwvJ8e5zgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-10-08 08:31:39
(13 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
Anonymous
2026-10-08 03:45:01
(18 hours ago)
suspicious request in access.log
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 01:35:41
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.208.73.36 (36.73.208.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.208.73.36 (36.73.208.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:35:37.205643 2026] [security2:error] [pid 32170:tid 32170] [client 35.208.73.36:35346] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "feaverslane.com"] [uri "/.git/config"] [unique_id "asbzafwkwrNaVZPV6BPYCgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 19:46:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.208.73.36 (36.73.208.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.208.73.36 (36.73.208.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 15:46:00.273276 2026] [security2:error] [pid 20009:tid 20009] [client 35.208.73.36:56862] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "feathersolar.com"] [uri "/.git/config"] [unique_id "asahePC4s3u2v76gKefXsAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
nzhost.co.nz
2026-10-07 19:42:01
(1 day ago)
$f2bV_matches
Hacking
Brute-Force
π«π·
masterguru
2026-10-07 15:56:35
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-196)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 15:53:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.208.73.36 (36.73.208.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.208.73.36 (36.73.208.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 11:53:25.821120 2026] [security2:error] [pid 24981:tid 25063] [client 35.208.73.36:47452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fearofpools.com"] [uri "/.git/config"] [unique_id "asZq9Ve1TMu_D4rSIsqMfQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π°π·
stypr
2026-10-07 10:15:50
(1 day ago)
Malicious activity detected on HTTP/HTTPS
Hacking
Brute-Force
Web App Attack
π³π±
homeshowdomain.nl
2026-10-06 21:59:38
(1 day ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-10-05.
show less
Web App Attack
SSH
Hacking