🇳🇱
homeshowdomain.nl
2026-09-17 21:59:22
(2 days ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-16.
show less
Web App Attack
SSH
Hacking
🇲🇽
octageeks.com
2026-09-16 04:08:14
(4 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
🇩🇪
MBombeck
2026-09-16 02:46:34
(4 days ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
🇳🇱
Alt255
2026-09-15 22:05:24
(4 days ago)
[ti-29al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-29al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.236.30.63 - - [16/Sep/2026:00:05:23 +0200] "GET /.git/config HTTP/1.1" 301 632 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
🇩🇪
kkw
2026-09-15 20:58:02
(4 days ago)
[REDACTED] 35.236.30.63 - - [15/Sep/2026:22:58:01 +0200] "GET /.git/config HTTP/1.1" 302 1919 "-" "M ...
show more
[REDACTED] 35.236.30.63 - - [15/Sep/2026:22:58:01 +0200] "GET /.git/config HTTP/1.1" 302 1919 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 18:50:15
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.236.30.63 (63.30.236.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.30.63 (63.30.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:50:09.640804 2026] [security2:error] [pid 17549:tid 17549] [client 35.236.30.63:42818] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "metrosearchinc.com"] [uri "/.git/config"] [unique_id "aqmTYZF55lGXAflmILTfyAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 17:59:11
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.236.30.63 (63.30.236.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.30.63 (63.30.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:59:06.346800 2026] [security2:error] [pid 10145:tid 10220] [client 35.236.30.63:52426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "metropolitanbasel.org.metropolitanbasel.org"] [uri "/.git/config"] [unique_id "aqmHagb0RXJ3JZTMBFX_cwAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
dynamix
2026-09-15 09:38:38
(4 days ago)
Multiple WAF Violations
Web App Attack
🇳🇱
Savvii
2026-09-15 09:13:44
(4 days ago)
20 attempts against mh_ha-misbehave-ban on pf221116
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
gadix
2026-09-15 07:53:46
(4 days ago)
[15/Sep/2026:09:53:45.391226 +0200] aqj5ia6lt7tHgiN7w-iE3AAAAJI 35.236.30.63 39050 127.0.0.1 7081
[1 ...
show more
[15/Sep/2026:09:53:45.391226 +0200] aqj5ia6lt7tHgiN7w-iE3AAAAJI 35.236.30.63 39050 127.0.0.1 7081
[15/Sep/2026:09:53:45.735292 +0200] aqj5ia6lt7tHgiN7w-iE3QAAAJg 35.236.30.63 39078 127.0.0.1 7081
[15/Sep/2026:09:53:45.896080 +0200] aqj5iVDgVyqnJxnEl6rtqAAAAFI 35.236.30.63 39094 127.0.0.1 7081
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 06:42:24
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.236.30.63 (63.30.236.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.30.63 (63.30.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 02:42:19.273217 2026] [security2:error] [pid 10353:tid 10353] [client 35.236.30.63:48910] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "the-schlosser.net"] [uri "/.git/config"] [unique_id "aqjoy1-6BOGAvd__LuOU3wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-15 01:45:03
(5 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack