๐ณ๐ฑ
Site.eu
2026-08-31 14:33:19
(6 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-08-31 14:16:52
(6 hours ago)
35.234.139.40 - - [31/Aug/2026:16:16:49 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows N ...
show more
35.234.139.40 - - [31/Aug/2026:16:16:49 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.234.139.40 - - [31/Aug/2026:16:16:50 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.234.139.40 - - [31/Aug/2026:16:16:50 +0200] "POST / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.234.139.40 - - [31/Aug/2026:16:16:50 +0200] "GET /.git/config HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.234.139.40 - - [31/Aug/2026:16:16:50 +0200] "GET /.env HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.234.139.40 - - [31/Aug/2026:1
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 14:06:32
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.139.40 (40.139.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.139.40 (40.139.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 10:06:27.652305 2026] [security2:error] [pid 26803:tid 26803] [client 35.234.139.40:47888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.recreationwebsites.brushmileage.org"] [uri "/.git/config"] [unique_id "apWKY3NpkLuosg5T6nGUWQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 13:38:56
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.139.40 (40.139.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.139.40 (40.139.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 09:38:51.002755 2026] [security2:error] [pid 4189135:tid 4189144] [client 35.234.139.40:33386] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.records.emehache.com"] [uri "/.git/config"] [unique_id "apWD64qG1gcln32l1KoJCAAAAQc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 12:43:48
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.139.40 (40.139.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.139.40 (40.139.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 08:43:40.814390 2026] [security2:error] [pid 6302:tid 6302] [client 35.234.139.40:35592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.recipes.mikeneame.com"] [uri "/.git/config"] [unique_id "apV2_ISSdbmcMnBxMx3XRAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-08-31 12:26:15
(8 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
Anonymous
2026-08-31 12:11:31
(8 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: GB, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: GB, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 12:05:55
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.139.40 (40.139.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.139.40 (40.139.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 08:05:48.311287 2026] [security2:error] [pid 19976:tid 19976] [client 35.234.139.40:52994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.recetabook.com.creartest.com"] [uri "/.git/config"] [unique_id "apVuHLAJGu_JnfYU4rertwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-08-31 10:50:08
(9 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-31 10:49:16
(9 hours ago)
35.234.139.40 - - [31/Aug/2026:12:49:12 +0200] "GET /.env2 HTTP/1.1" 301 600 "-" "Mozilla/5.0 (X11; ...
show more
35.234.139.40 - - [31/Aug/2026:12:49:12 +0200] "GET /.env2 HTTP/1.1" 301 600 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.234.139.40 - - [31/Aug/2026:12:49:13 +0200] "GET /.env_copy HTTP/1.1" 301 608 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.234.139.40 - - [31/Aug/2026:12:49:13 +0200] "GET /.env.txt HTTP/1.1" 301 606 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.234.139.40 - - [31/Aug/2026:12:49:13 +0200] "GET /.env.json HTTP/1.1" 301 608 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.234.139.40 - - [31/Aug/2026:12:49:13 +0200] "GET /.env.yaml HTTP/1.1" 301 608 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.234.139.40 - - [31/Aug/2026:12:49:13 +0200] "GET /.env.ym
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-31 09:28:48
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.139.40 (40.139.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.139.40 (40.139.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 05:28:41.982418 2026] [security2:error] [pid 3602:tid 3613] [client 35.234.139.40:43542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.reattaforsale.com.piazza9.com"] [uri "/.git/config"] [unique_id "apVJSVZUX32aHkjXBxv9GgAAAIk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-31 08:45:30
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.139.40 (40.139.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.139.40 (40.139.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 04:45:23.950690 2026] [security2:error] [pid 17279:tid 17279] [client 35.234.139.40:50734] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.realtorpaul.buynorthwest.com"] [uri "/.git/config"] [unique_id "apU_Izp-igHcvA9BopGKKQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-31 06:28:57
(14 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
Anonymous
2026-08-31 03:59:13
(16 hours ago)
35.234.139.40 - - [31/Aug/2026:05:59:09 +0200] "GET /.git/config HTTP/1.1" 403 623 "-" "Mozilla/5.0 ...
show more
35.234.139.40 - - [31/Aug/2026:05:59:09 +0200] "GET /.git/config HTTP/1.1" 403 623 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.234.139.40 - - [31/Aug/2026:05:59:09 +0200] "GET /.env HTTP/1.1" 403 623 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.234.139.40 - - [31/Aug/2026:05:59:09 +0200] "GET /.env.local HTTP/1.1" 403 623 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.234.139.40 - - [31/Aug/2026:05:59:09 +0200] "GET /.env.production HTTP/1.1" 403 623 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.234.139.40 - - [31/Aug/2026:05:59:09 +0200] "GET /.env.staging HTTP/1.1" 403 623 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.234.139.40 - - [31/Aug/2026:05:59:09 +0200] "
...
show less
DDoS Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-30 22:00:34
(22 hours ago)
Auto-ban: >3000 req/min op 2026-08-30
Web App Attack
SSH
Hacking