๐ซ๐ฎ
indev.fi
2026-09-29 12:36:28
(1 week ago)
alalipasti.peltopiri.com 35.234.211.7 - - [29/Sep/2026:15:35:57 +0300] "GET /.git/config HTTP/1.1" 4 ...
show more
alalipasti.peltopiri.com 35.234.211.7 - - [29/Sep/2026:15:35:57 +0300] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
alalipasti.peltopiri.com 35.234.211.7 - - [29/Sep/2026:15:35:58 +0300] "GET /.env HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
alalipasti.peltopiri.com 35.234.211.7 - - [29/Sep/2026:15:35:59 +0300] "GET /.env.local HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-29 05:41:53
(1 week ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, env_probe, source_backup, server_status, wp_admin. Observed by 1 sensor(s); 486 hits.
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 05:49:04
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.234.211.7 (7.211.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.211.7 (7.211.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 01:48:58.015494 2026] [security2:error] [pid 28654:tid 28654] [client 35.234.211.7:36542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adj-tech.net"] [uri "/.git/config"] [unique_id "arn_ytI5vDW8Fq67eMGZKgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
wordpresshosting.solutions
2026-09-28 02:32:52
(1 week ago)
Web app vulnerability scanning detected. Evidence: [IP] - - [28/Sep/2026:02:32:36 +0000] "GET /phpin ...
show more
Web app vulnerability scanning detected. Evidence: [IP] - - [28/Sep/2026:02:32:36 +0000] "GET /phpinfo.php HTTP/1.1" 404 50782 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/[IP] Safari/537.36"
[IP] - - [28/Sep/2026:02:32:52 +0000] "GET /test.php HTTP/1.1" 404 45965 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/[IP] Safari/537.36"
show less
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-27 17:05:02
(1 week ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-26 22:20:09
(1 week ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-26 22:17:26
(1 week ago)
35.234.211.7 - - [27/Sep/2026:00:17:22 +0200] "GET /.env.local HTTP/1.1" 404 511 "-" "Mozilla/5.0 (W ...
show more
35.234.211.7 - - [27/Sep/2026:00:17:22 +0200] "GET /.env.local HTTP/1.1" 404 511 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.234.211.7 - - [27/Sep/2026:00:17:22 +0200] "GET /.env.production HTTP/1.1" 404 511 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.234.211.7 - - [27/Sep/2026:00:17:23 +0200] "GET /.env.staging HTTP/1.1" 404 511 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.234.211.7 - - [27/Sep/2026:00:17:23 +0200] "GET /.env.development HTTP/1.1" 404 511 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.234.211.7 - - [27/Sep/2026:00:17:23 +0200] "GET /.env.test HTTP/1.1" 404 511 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/5
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-26 16:02:04
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.234.211.7 (7.211.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.211.7 (7.211.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 12:01:59.046668 2026] [security2:error] [pid 18727:tid 18727] [client 35.234.211.7:38038] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mikeneame.com"] [uri "/.git/config"] [unique_id "arfsd1Al0z0shgJTTdLNRgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 15:29:19
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.234.211.7 (7.211.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.211.7 (7.211.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:29:15.752874 2026] [security2:error] [pid 3082:tid 3082] [client 35.234.211.7:33694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mike-garner.com"] [uri "/.git/config"] [unique_id "arfkyxrmTzqKzJLLdt3AhwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 15:10:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.234.211.7 (7.211.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.211.7 (7.211.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 11:10:06.360807 2026] [security2:error] [pid 24356:tid 24356] [client 35.234.211.7:60820] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mikebenson.com"] [uri "/.git/config"] [unique_id "arfgTlEGuf4jIoidcgOZRAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-26 09:32:41
(1 week ago)
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-17al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.234.211.7 - - [26/Sep/2026:11:32:36 +0200] "GET /.git/config HTTP/1.1" 301 618 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-25 09:21:56
(1 week ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-25 09:05:39
(1 week ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-25 08:48:52
(1 week ago)
(modsecurity) srv104 ModSecurity 35.234.211.7 (IN/India/7.211.234.35.bc.googleusercontent.com): 30 i ...
show more
(modsecurity) srv104 ModSecurity 35.234.211.7 (IN/India/7.211.234.35.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-09-22 08:18:25
(2 weeks ago)
Web attack/malicious scanning detected
Web App Attack