Anonymous
2026-09-02 04:15:15
(2 hours ago)
Blocked by ModSec and CSF
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-02 04:14:11
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.76.206 (206.76.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.76.206 (206.76.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 00:14:02.705201 2026] [security2:error] [pid 27486:tid 27486] [client 35.221.76.206:40212] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lemritz.org.shtondo.com"] [uri "/.git/config"] [unique_id "apeiimtde9o4TJj7HqXwkwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-09-02 04:06:17
(2 hours ago)
[WedSep0206:06:10.4145182026][security2:error][pid2143224:tid2143438][client35.221.76.206:0]ModSecur ...
show more
[WedSep0206:06:10.4145182026][security2:error][pid2143224:tid2143438][client35.221.76.206:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".git\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.lemox.ch.81-17-25-250.cpanel.site\"][uri\"/.git/config\"][unique_id\"apegsh8hSQu9Q3lQr0tmNQAAAUc\"]
show less
Hacking
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-02 03:50:04
(2 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-02 03:33:52
(2 hours ago)
35.221.76.206 - - [02/Sep/2026:05:33:48 +0200] "GET /.git/config HTTP/1.1" 403 520 "-" "Mozilla/5.0 ...
show more
35.221.76.206 - - [02/Sep/2026:05:33:48 +0200] "GET /.git/config HTTP/1.1" 403 520 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.221.76.206 - - [02/Sep/2026:05:33:48 +0200] "GET /.git/config HTTP/1.1" 403 520 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.221.76.206 - - [02/Sep/2026:05:33:46 +0200] "POST / HTTP/1.1" 200 7836 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.221.76.206 - - [02/Sep/2026:05:33:46 +0200] "POST / HTTP/1.1" 200 7839 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.221.76.206 - - [02/Sep/2026:05:33:46 +0200] "POST / HTTP/1.1" 200 7838 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.221.76.206 - - [02/Se
show less
Web App Attack
Hacking
๐ณ๐ฑ
Site.eu
2026-09-02 03:00:06
(3 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
LRob
2026-09-02 01:26:17
(4 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env (+1 more) | 2026-09-02 01:26 UTC
show less
Hacking
Web App Attack
๐ฉ๐ฐ
HostingGroup
2026-09-02 01:16:53
(5 hours ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 44. First blocked: 2026-09-02.
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-01 23:12:00
(7 hours ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-01 22:00:19
(8 hours ago)
Auto-ban: >3000 req/min op 2026-09-01
Web App Attack
SSH
Hacking
Anonymous
2026-09-01 21:42:34
(8 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ธ๐ช
vaia.cloud
2026-09-01 21:35:02
(8 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 21:33:25
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.76.206 (206.76.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.76.206 (206.76.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 17:33:18.062831 2026] [security2:error] [pid 1485:tid 1485] [client 35.221.76.206:46428] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.lejzerowicz.williamgilcher.com"] [uri "/.git/config"] [unique_id "apdEntwxr4Dse9hMMBrN4AAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-01 20:59:34
(9 hours ago)
[da.kdns.gr] httpd-config-scan: sites=www.leitz.gr; logs=/var/log/httpd/domains/leitz.gr.log; sample ...
show more
[da.kdns.gr] httpd-config-scan: sites=www.leitz.gr; logs=/var/log/httpd/domains/leitz.gr.log; samples=/.git/config | /.env | /.env.local
show less
Hacking
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-01 20:00:09
(10 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking