๐ฆ๐บ
2000cn.com.au
2026-08-26 15:14:20
(1 minute ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
JustMeHere
2026-08-26 10:40:50
(4 hours ago)
[Wed Aug 26 06:40:45.924373 2026] [security2:error] [pid 1313:tid 1351] [client 35.236.189.52:37926] ...
show more
[Wed Aug 26 06:40:45.924373 2026] [security2:error] [pid 1313:tid 1351] [client 35.236.189.52:37926] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "yorknation.com"] [uri "/.git/config"] [unique_id "ao7CrR8uuhrrAdRVES7OvwAAAMo"]
...
show less
Web App Attack
Anonymous
2026-08-26 10:34:11
(4 hours ago)
[server.techsupportltd.gr] httpd-config-scan: sites=www.wavedancercyprus.com; logs=/var/log/httpd/do ...
show more
[server.techsupportltd.gr] httpd-config-scan: sites=www.wavedancercyprus.com; logs=/var/log/httpd/domains/wavedancercyprus.com.log; samples=/.git/config
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 10:33:39
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.189.52 (52.189.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.189.52 (52.189.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 06:33:35.138300 2026] [security2:error] [pid 24225:tid 24225] [client 35.236.189.52:29648] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vpatech.com"] [uri "/.git/config"] [unique_id "ao7A_4Chi7d-xYfu5rGNowAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
MM-bot
2026-08-26 10:07:26
(5 hours ago)
URL-probe: HTTP/1.1 GET request on /.git/config (2026-08-26 12:07:26 UTC+2)
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-26 09:45:59
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.189.52 (52.189.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.189.52 (52.189.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 05:45:51.883153 2026] [security2:error] [pid 11342:tid 11342] [client 35.236.189.52:4314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "epicjellyfish.com"] [uri "/.git/config"] [unique_id "ao61zyyOhgSGo5tAykPYmwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-08-26 09:23:55
(5 hours ago)
cloudlinux2 fail2ban: 2026-08-26 11:19:57,544 fail2ban.filter [1775]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-08-26 11:19:57,544 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 35.236.189.52 - 2026-08-26 11:19:57cloudlinux2 fail2ban: 2026-08-26 11:20:08,068 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 212.227.226.25 - 2026-08-26 11:20:07cloudlinux2 fail2ban: 2026-08-26 11:20:34,609 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 185.242.180.193 - 2026-08-26 11:20:33cloudlinux2 fail2ban: 2026-08-26 11:21:28,800 fail2ban.filter [1775]: INFO [plesk-wordpress] Found 94.237.46.54 - 2026-08-26 11:21:28cloudlinux2 fail2ban: 2026-08-26 11:22:04,301 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 172.68.151.64 - 2026-08-26 11:22:04cloudlinux2 fail2ban: 2026-08-26 11:22:04,316 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 172.68.151.65 - 2026-08-26 11:22:04cloudlinux2 fail2ban: 2026-08-26 11:22:46,315 fail2ban.filter [1775]: INFO [plesk-modsecurity] Found 34.124.206.86 - 2026-08-26 11:22:4
show less
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-08-26 09:23:13
(5 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 09:22:32
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.189.52 (52.189.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.189.52 (52.189.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 05:22:26.971489 2026] [security2:error] [pid 18222:tid 18222] [client 35.236.189.52:16150] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adultshop61.net"] [uri "/.git/config"] [unique_id "ao6wUiOLTmQBIm1a7oRnoQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-26 07:58:38
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.189.52 (52.189.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.189.52 (52.189.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 26 03:58:34.245409 2026] [security2:error] [pid 11600:tid 11600] [client 35.236.189.52:44488] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "greencornokies.org"] [uri "/.env"] [unique_id "ao6cqkp6-ygYW9DwmkwMygAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
on-com
2026-08-26 04:30:34
(10 hours ago)
URL scan
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-08-25 22:52:20
(16 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 18:21:07
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.189.52 (52.189.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.189.52 (52.189.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 14:21:00.019801 2026] [security2:error] [pid 25468:tid 25468] [client 35.236.189.52:17768] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zmgmt.net"] [uri "/.git/config"] [unique_id "ao3dDGFP--tEQD_PIdzWKAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
voormedia
2026-08-25 18:12:20
(21 hours ago)
Accessed trap at '/.git/config'
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-25 17:35:52
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.189.52 (52.189.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.189.52 (52.189.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 25 13:35:47.603182 2026] [security2:error] [pid 1012:tid 1012] [client 35.236.189.52:47644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "southsideaccountingservices.com"] [uri "/.git/config"] [unique_id "ao3Sc8Ooi8ftJHrq7Cd40wAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack