🇳🇱
debestelapp
2026-09-05 07:35:09
(9 hours ago)
Web App Attack
🇩🇪
gadix
2026-09-05 07:19:57
(9 hours ago)
[05/Sep/2026:09:19:57.091544 +0200] apvCnbasmujV6oDy4VGz5AAAAAY 35.227.108.236 42686 127.0.0.1 7081
...
show more
[05/Sep/2026:09:19:57.091544 +0200] apvCnbasmujV6oDy4VGz5AAAAAY 35.227.108.236 42686 127.0.0.1 7081
[05/Sep/2026:09:19:57.096526 +0200] apvCnc9ecHNiFK7n4ewK1AAAAAA 35.227.108.236 42700 127.0.0.1 7081
[05/Sep/2026:09:19:57.098556 +0200] apvCncMqYfrD0ui2U9dBcAAAAAs 35.227.108.236 42716 127.0.0.1 7081
...
show less
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-04 22:01:21
(19 hours ago)
Auto-ban: >3000 req/min op 2026-09-04
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 15:22:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.227.108.236 (236.108.227.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.108.236 (236.108.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 11:22:02.312398 2026] [security2:error] [pid 8418:tid 8425] [client 35.227.108.236:38054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.desert-automotive.com"] [uri "/wp-config.php~"] [unique_id "apriGhXTEsdkaRVPn4WufgAAAUU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Felisse
2026-09-04 14:59:50
(1 day ago)
CrowdSec ban: crowdsecurity/http-sensitive-files (duration: 3h56m56s)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 14:07:38
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.227.108.236 (236.108.227.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.108.236 (236.108.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:07:31.252906 2026] [security2:error] [pid 11475:tid 11475] [client 35.227.108.236:40588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.title37.com"] [uri "/wp-config.php.swp"] [unique_id "aprQo4NaSxIEhxewmcGTHgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:43:31
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.227.108.236 (236.108.227.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.108.236 (236.108.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:43:26.686332 2026] [security2:error] [pid 21370:tid 21370] [client 35.227.108.236:55560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "icwcruisersguide.bahamascruisersguide.com"] [uri "/wp-config.php.bak"] [unique_id "aprK_u0tWbbxdSMAi0BqDgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Aetherweb Ark
2026-09-04 13:42:23
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 35.227.108.236 (US/United States/236.108.227.35 ...
show more
(mod_security) mod_security (id:949110) triggered by 35.227.108.236 (US/United States/236.108.227.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:17:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.227.108.236 (236.108.227.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.108.236 (236.108.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:16:55.882609 2026] [security2:error] [pid 31655:tid 31655] [client 35.227.108.236:51788] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tactara.net"] [uri "/.env.prod"] [unique_id "aprExwu8Gj2bWvj5cDBY3wAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-04 12:55:46
(1 day ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.env.old (+12 more) | 2026-09-04 12:55 UTC
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:49:26
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 35.227.108.236 (236.108.227.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 35.227.108.236 (236.108.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:49:20.613290 2026] [security2:error] [pid 10418:tid 10418] [client 35.227.108.236:58016] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "maricotippett.com"] [uri "/wp-config.php.swp"] [unique_id "apq-UCaJJQFkwTyC4qmv3wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 12:32:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.227.108.236 (236.108.227.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.108.236 (236.108.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 08:31:54.039767 2026] [security2:error] [pid 31365:tid 31365] [client 35.227.108.236:38150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gdrankin.com"] [uri "/.env.prod"] [unique_id "apq6OhjohSorZc2_L_R9hAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FD-IX
2026-09-04 12:25:08
(1 day ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:53:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.227.108.236 (236.108.227.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.108.236 (236.108.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:53:06.617983 2026] [security2:error] [pid 21510:tid 21510] [client 35.227.108.236:49504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.advantageinvestigation.com"] [uri "/wp-config.php.swp"] [unique_id "apqxIrHNPewRCmpwi6xAFgAAAEg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇭🇺
miszterx.hu
2026-09-04 11:05:13
(1 day ago)
XORP (haproxy): 6x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_ipt ...
show more
XORP (haproxy): 6x HTTP 404/403/500 or handshake failure in 24h. Automated report from log_check_iptables_generator.sh (xorp.hu)
show less
Web App Attack