๐ณ๐ฑ
e.fierstra
2026-10-09 23:04:18
(3 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-10-09 22:45:13
(3 hours ago)
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-08 01:01:58
(2 days ago)
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.216.39.18 - - [08/Oct/2026:03:01:42 +0200] "GET /.git/config HTTP/1.1" 404 341 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-10-07 23:45:02
(2 days ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 23:04:26
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.216.39.18 (18.39.216.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.216.39.18 (18.39.216.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:04:19.421393 2026] [security2:error] [pid 25846:tid 25846] [client 35.216.39.18:49822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wiltoncheese.com"] [uri "/.git/config"] [unique_id "asbP8ybGgtmUhYzXCVIEJgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 21:45:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.216.39.18 (18.39.216.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.216.39.18 (18.39.216.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 17:45:11.457282 2026] [security2:error] [pid 17480:tid 17480] [client 35.216.39.18:48072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wilsonclassof81.org"] [uri "/.git/config"] [unique_id "asa9Z5lRtMVRkpNjlDcRuwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-07 20:56:14
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ง๐ช
cmbplf
2026-10-07 20:33:39
(2 days ago)
4.934 requests with url.path *.env
866 requests with url.path *phpinfo.php
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-07 20:26:42
(2 days ago)
(mod_security) mod_security (id:949110) triggered by 35.216.39.18 (18.39.216.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 35.216.39.18 (18.39.216.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 16:26:37.101535 2026] [security2:error] [pid 1526:tid 1526] [client 35.216.39.18:52078] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "wilmoth.us"] [uri "/app/.env"] [unique_id "asaq_QA9xAAffUJ5bhHWmAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-10-07 19:42:54
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-07 18:46:33
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 16:58:28
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.216.39.18 (18.39.216.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.216.39.18 (18.39.216.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 12:58:25.051736 2026] [security2:error] [pid 3679:tid 3679] [client 35.216.39.18:58004] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "willowstick-carbon.com"] [uri "/.git/config"] [unique_id "asZ6MYnqqBH81nlTDFxstAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 16:41:12
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.216.39.18 (18.39.216.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.216.39.18 (18.39.216.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 12:41:02.432263 2026] [security2:error] [pid 21769:tid 21769] [client 35.216.39.18:36752] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "willowriver3.com"] [uri "/.git/config"] [unique_id "asZ2HptxSaqTmu0isA3r6AAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 16:06:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.216.39.18 (18.39.216.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.216.39.18 (18.39.216.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 12:06:42.051548 2026] [security2:error] [pid 19318:tid 19318] [client 35.216.39.18:33142] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "willowgrovemusic.com"] [uri "/.git/config"] [unique_id "asZuEkfvMQsIDjm-8Ch64QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 15:34:02
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.216.39.18 (18.39.216.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.216.39.18 (18.39.216.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 11:33:58.758542 2026] [security2:error] [pid 28684:tid 28684] [client 35.216.39.18:52896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "willowbrookins.com"] [uri "/.git/config"] [unique_id "asZmZgssscwxJrUAZ4NUnAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack