๐ธ๐ช
vaia.cloud
2026-10-09 22:00:02
(13 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฉ๐ช
vmd56152.contaboserver.net
2026-10-09 18:12:11
(17 hours ago)
[Fri Oct 09 20:12:09.539393 2026] [proxy_fcgi:error] [pid 2424234:tid 140435322251008] [client 35.21 ...
show more
[Fri Oct 09 20:12:09.539393 2026] [proxy_fcgi:error] [pid 2424234:tid 140435322251008] [client 35.214.18.32:43154] AH01071: Got error 'Primary script unknown'
[Fri Oct 09 20:12:09.571071 2026] [proxy_fcgi:error] [pid 2424234:tid 140435095811840] [client 35.214.18.32:43154] AH01071: Got error 'Primary script unknown'
[Fri Oct 09 20:12:09.663305 2026] [proxy_fcgi:error] [pid 2424234:tid 140435221636864] [client 35.214.18.32:43154] AH01071: Got error 'Primary script unknown'
[Fri Oct 09 20:12:09.700133 2026] [proxy_fcgi:error] [pid 2424234:tid 140435313858304] [client 35.214.18.32:43154] AH01071: Got error 'Primary script unknown'
[Fri Oct 09 20:12:09.817074 2026] [proxy_fcgi:error] [pid 2424234:tid 140435397785344] [client 35.214.18.32:43154] AH01071: Got error 'Primary script unknown'
[Fri Oct 09 20:12:09.976648 2026] [proxy_fcgi:error] [pid 2424234:tid 140435330643712] [client 35.214.18.32:43154] AH01071: Got error 'Primary script unknown'
[Fri Oct 09 20:12:09.996483 2026] [proxy_fcgi:
...
show less
Brute-Force
๐ณ๐ฑ
Site.eu
2026-10-09 17:39:39
(18 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-10-08 23:16:21
(1 day ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: GB, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: GB, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
mail.avx.gr
2026-10-08 08:41:40
(2 days ago)
(nginxENVSCAN) nginx environment-file scanner detected from 35.214.18.32 (GB/United Kingdom/England/ ...
show more
(nginxENVSCAN) nginx environment-file scanner detected from 35.214.18.32 (GB/United Kingdom/England/London/32.18.214.35.bc.googleusercontent.com)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-08 08:19:39
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.214.18.32 (32.18.214.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.214.18.32 (32.18.214.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 04:19:35.590678 2026] [security2:error] [pid 2043:tid 2088] [client 35.214.18.32:37154] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "re52s.com"] [uri "/.git/config"] [unique_id "asdSF2ExeX8lATxCRa6hCgAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
vtchost.com
2026-10-08 07:23:02
(2 days ago)
forbidden http request, scanning for weaknesses
...
Web App Attack
Anonymous
2026-10-08 05:34:42
(2 days ago)
35.214.18.32 - - [08/Oct/2026:07:34:35 +0200] "GET /.git/config HTTP/1.1" 403 619 "-" "Mozilla/5.0 ( ...
show more
35.214.18.32 - - [08/Oct/2026:07:34:35 +0200] "GET /.git/config HTTP/1.1" 403 619 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.214.18.32 - - [08/Oct/2026:07:34:35 +0200] "GET /.env HTTP/1.1" 403 619 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.214.18.32 - - [08/Oct/2026:07:34:35 +0200] "GET /.env.local HTTP/1.1" 403 619 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.214.18.32 - - [08/Oct/2026:07:34:35 +0200] "GET /.env.production HTTP/1.1" 403 619 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.214.18.32 - - [08/Oct/2026:07:34:35 +0200] "GET /.env.staging HTTP/1.1" 403 619 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.214.18.32 - - [08/Oct/2026:07:34:35 +0200] "GET /.
...
show less
DDoS Attack
๐ง๐ช
cmbplf
2026-10-08 05:33:12
(2 days ago)
2.928 requests with url.path *.env
Brute-Force
Bad Web Bot
๐จ๐ญ
๐จ๐ญ Hosting
2026-10-08 05:10:21
(2 days ago)
Automated WAF report: 200-300 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-10-08 03:05:02
(2 days ago)
2026-10-08 05:03:26 GET /.git/config [301] && 2026-10-08 05:03:26 GET /.env [301] && 2026-10-08 05:0 ...
show more
2026-10-08 05:03:26 GET /.git/config [301] && 2026-10-08 05:03:26 GET /.env [301] && 2026-10-08 05:03:27 GET /.env.bak [301] && 239 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 02:06:34
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.214.18.32 (32.18.214.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.214.18.32 (32.18.214.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 22:06:30.547991 2026] [security2:error] [pid 3571:tid 3571] [client 35.214.18.32:59516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rdu.kmp.net"] [uri "/.git/config"] [unique_id "asb6pnKI7xSUGKTrjlC5pAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
webanyone
2026-10-08 01:38:15
(2 days ago)
Secret file probe | method: GET | path: /.git/config | ua: Mozilla/5.0 (X11; Linux x86_64) AppleWebK ...
show more
Secret file probe | method: GET | path: /.git/config | ua: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 01:20:28
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.214.18.32 (32.18.214.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.214.18.32 (32.18.214.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 21:20:21.064068 2026] [security2:error] [pid 21053:tid 21053] [client 35.214.18.32:37608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rdsparts.com"] [uri "/.git/config"] [unique_id "asbv1bvEBnBpXbaoLle2YQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-10-08 01:03:12
(2 days ago)
Domain : rdservices4x4.com
Rule : hack
2026-10-08 01:01:05 ***hidden-privacy*** GET /.env.bak - 443 ...
show more
Domain : rdservices4x4.com
Rule : hack
2026-10-08 01:01:05 ***hidden-privacy*** GET /.env.bak - 443 - 35.214.18.32 HTTP/1.1 Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36 - rdservices4x4.com 404 0 2 1563 298 3 - -
show less
Hacking
SQL Injection
Brute-Force