๐ฉ๐ช
LRob
2026-09-17 04:15:50
(7 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+10 more) | 2026-09-17 04:15 UTC
show less
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-17 02:55:13
(8 hours ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
homeshowdomain.nl
2026-09-16 21:59:35
(13 hours ago)
Auto-ban: >3000 req/min op 2026-09-16
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-16 14:32:33
(21 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.235.109.216 (216.109.235.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 35.235.109.216 (216.109.235.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 10:32:27.521848 2026] [security2:error] [pid 5769:tid 5769] [client 35.235.109.216:60778] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.orders.pathpointsandbox.click"] [uri "/.git/config"] [unique_id "aqqoe-NvaC0quhtOMLKqFwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 14:03:40
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.235.109.216 (216.109.235.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.235.109.216 (216.109.235.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 10:03:34.108266 2026] [security2:error] [pid 7239:tid 7239] [client 35.235.109.216:49066] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.orchestrateyouraptitudes.ficklepassionproductions.com"] [uri "/.git/config"] [unique_id "aqqhtkcQq6Fc40vwVI-0XgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:19:07
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.235.109.216 (216.109.235.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.235.109.216 (216.109.235.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:19:02.371914 2026] [security2:error] [pid 6956:tid 6956] [client 35.235.109.216:50394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.orangecountyrehearsal.virlouise.com"] [uri "/.git/config"] [unique_id "aqqXRke6910TJ1Gi5GQstQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-16 12:57:08
(22 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 08:48:41
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.235.109.216 (216.109.235.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.235.109.216 (216.109.235.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 04:48:35.497753 2026] [security2:error] [pid 13725:tid 13725] [client 35.235.109.216:51768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pack88.mvscouts.org"] [uri "/.git/config"] [unique_id "aqpX41HoRVbJT3IISp6PzwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
SLSLLC
2026-09-16 08:42:25
(1 day ago)
35.235.109.216 - - [16/Sep/2026:08:42:24 +0000] "GET /.env HTTP/2.0" 403 1881 "-" "Mozilla/5.0 (Maci ...
show more
35.235.109.216 - - [16/Sep/2026:08:42:24 +0000] "GET /.env HTTP/2.0" 403 1881 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
masterguru
2026-09-16 07:23:31
(1 day ago)
Remote Command Execution: Unix Shell Expression Found. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\ ...
show more
Remote Command Execution: Unix Shell Expression Found. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})| (932130-169)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-16 06:36:11
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.235.109.216 (216.109.235.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.235.109.216 (216.109.235.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 02:36:06.627134 2026] [security2:error] [pid 25344:tid 25344] [client 35.235.109.216:45152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pacc.gormish.org"] [uri "/.git/config"] [unique_id "aqo41qeAK6IhZCeu-LfnVAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-16 05:19:44
(1 day ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.235.109.216 - - [16/Sep/2026:07:19:30 +0200] "GET /.git/config HTTP/1.1" 403 8024 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 04:17:15
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.235.109.216 (216.109.235.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.235.109.216 (216.109.235.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 00:17:08.046260 2026] [security2:error] [pid 17922:tid 17922] [client 35.235.109.216:46160] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pa.rustyog.net|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pa.rustyog.net"] [uri "/.env.bak"] [unique_id "aqoYRO7_Q6s2feD-ns9c3gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-16 00:14:53
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.235.109.216 (US/United States/216 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.235.109.216 (US/United States/216.109.235.35.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐ฉ๐ช
pscriptos
2026-09-16 00:12:11
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack