πΊπΈ
TPI-Abuse
2026-10-08 05:36:50
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.216.83.212 (212.83.216.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.216.83.212 (212.83.216.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 01:36:44.376463 2026] [security2:error] [pid 22522:tid 22522] [client 35.216.83.212:50044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.armchairdevotional.shepherdsgroup.com"] [uri "/.git/config"] [unique_id "ascr7CTUokAjYn2XWrwIzgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-10-08 05:35:01
(18 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
π¬π§
consul.to
2026-10-08 04:38:36
(19 hours ago)
Web attack/malicious scanning detected
Web App Attack
π«π·
masterguru
2026-10-08 04:32:25
(19 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 23:55:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.216.83.212 (212.83.216.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.216.83.212 (212.83.216.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:54:53.875462 2026] [security2:error] [pid 13535:tid 13535] [client 35.216.83.212:33848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.arkqp.kreweofhyatt.com"] [uri "/.git/config"] [unique_id "asbbzSh-NxsuDJ1FAf8Y6AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-07 23:18:55
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.216.83.212 (212.83.216.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.216.83.212 (212.83.216.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 19:18:50.275570 2026] [security2:error] [pid 31773:tid 31773] [client 35.216.83.212:58804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.arklahomaflooring.com"] [uri "/.git/config"] [unique_id "asbTWrB-u8c0H0VjDZx2tAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
homeshowdomain.nl
2026-10-07 22:02:05
(1 day ago)
Auto-ban: >3000 req/min op 2026-10-07
Web App Attack
SSH
Hacking
π΅π±
arcy
2026-10-07 20:43:32
(1 day ago)
Detected by CrowdSec IDS on a self-hosted server. Target: HTTP/HTTPS (ports 80/443). Triggered rules ...
show more
Detected by CrowdSec IDS on a self-hosted server. Target: HTTP/HTTPS (ports 80/443). Triggered rules: http-admin-interface-probing, http-probing, http-sensitive-files, http-technology-probing. 17 matching log events between 2026-10-07T20:42:29Z and 20:43:32Z (UTC). Sample requests: GET /phpinfo.php -> 404; GET /admin/phpinfo.php -> 404; GET /test/phpinfo.php -> 404; GET /info.php -> 404; GET /.env.local -> 404; GET /.env.production -> 404; GET /.env.staging -> 404; GET /.env.development -> 404; GET /.env.test -> 404; GET /.env.remote -> 404; GET /.env.bak -> 404; GET /.env.backup -> 404; GET /.env.save -> 404; GET /.env.old -> 404; GET /.env.sample -> 404; GET /.git/config -> 301; GET /.env -> 301
show less
Port Scan
Hacking
Web App Attack
πΈπͺ
vaia.cloud
2026-10-07 19:40:02
(1 day ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
π³π±
Mangelot Hosting
2026-10-07 19:29:39
(1 day ago)
(modsec_attack) srv101 ModSecurity attack 35.216.83.212 (KR/South Korea/212.83.216.35.bc.googleuserc ...
show more
(modsec_attack) srv101 ModSecurity attack 35.216.83.212 (KR/South Korea/212.83.216.35.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-10-07 19:28:28
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-10-07 18:39:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.216.83.212 (212.83.216.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.216.83.212 (212.83.216.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 14:39:13.871107 2026] [security2:error] [pid 9964:tid 9964] [client 35.216.83.212:46024] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.arizonachristmascards.com"] [uri "/.git/config"] [unique_id "asaR0YF0ElAaV4aPCZQDvQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
backslash
2026-10-07 17:12:00
(1 day ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
πΊπΈ
dot.mg
2026-10-07 14:45:23
(1 day ago)
Scan of vulnerable files
Web App Attack
π³π±
Site.eu
2026-10-07 12:48:16
(1 day ago)
Excessive multi-domain requests
Brute-Force