๐ง๐ท
radardatelecom
2026-09-23 22:23:08
(20 hours ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-23 22:03:13
(20 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-22.
show less
Web App Attack
SSH
Hacking
Anonymous
2026-09-22 16:45:03
(2 days ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
tentwentyfour
2026-09-22 16:08:15
(2 days ago)
Blocked for probing for sensitive web application components
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:07:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.236.38.144 (144.38.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.38.144 (144.38.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:07:26.317508 2026] [security2:error] [pid 31688:tid 31688] [client 35.236.38.144:60110] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "periodpiano.org"] [uri "/.env.production"] [unique_id "arKnvmWVlD0BiMLycMiFWgAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 15:05:59
(2 days ago)
[ti-02ov] Web exploit scanning: 11 suspicious requests detected by fail2ban jail apache-scanner. Exa ...
show more
[ti-02ov] Web exploit scanning: 11 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.236.38.144 - - [22/Sep/2026:17:05:58 +0200] "GET /.env.prod HTTP/1.1" 301 6490 "-" "crusader-worker/1.0"
35.236.38.144 - - [22/Sep/2026:17:05:58 +0200] "GET /.env.dev HTTP/1.1" 301 6490 "-" "crusader-worker/1.0"
35.236.38.144 - - [22/Sep/2026:17:05:58 +0200] "GET /.env.local HTTP/1.1" 301 6490 "-" "crusader-worker/1.0"
35.236.38.144 - - [22/Sep/2026:17:05:58 +0200] "GET /.env.bak HTTP/1.1" 301 6490 "-" "crusader-worker/1.0"
35.236.38.144 - - [22/Sep/2026:17:05:58 +0200] "GET /.env.production HTTP/1.1" 301 6490 "-" "crusader-worker/1.0"
35.236.38.144 - - [22/Sep/2026:17:05:58 +0200] "GET /.env.backup HTTP/1.1" 301 6490 "-"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-22 15:05:12
(2 days ago)
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-22 14:49:20
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 14:29:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.236.38.144 (144.38.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.38.144 (144.38.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:29:41.917502 2026] [security2:error] [pid 12273:tid 12273] [client 35.236.38.144:50194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lexie.boens.org"] [uri "/wp-config.php~"] [unique_id "arKQ1XcZvRfP5moKVIZbSQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hary74656
2026-09-22 13:48:48
(2 days ago)
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3.
[earlier text truncated]
owasp-cr ...
show more
Fail2Ban on schani.hostmi.at: jail=apache-modsecurity, failures=3.
[earlier text truncated]
owasp-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [ver "OWASP_CRS/4.29.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "hvm.weavernet.at"] [uri "/wp-config.php.bak"] [unique_id "arKHQLuMsrWMt6Nx_cTUfQAAANE"]
[Tue Sep 22 15:48:48.310972 2026] [vhost schani.hostmi.at] [security2:error] [pid 274446:tid 140478716573376] [client 35.236.38.144:41410] [realclient 35.236.38.144:41410] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/opt/owasp-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [ver "OWASP_CRS/4.29.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "hvm.weavernet.at"] [uri "/wp-config.php~"] [unique_id "arKHQFHz_KDgb84hxFrjSAAAAEE"]
show less
Web App Attack
๐ฉ๐ช
mondor.ro
2026-09-22 13:17:55
(2 days ago)
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 35.236.38.144, Reason: ...
show more
Cluster member 148.251.176.225 (DE/Germany/antares.webyouridea.ro) said, DENY 35.236.38.144, Reason:[(mod_security) mod_security (id:210492) triggered by 35.236.38.144 (US/United States/144.38.236.35.bc.googleusercontent.com): 3 in the last 3600 secs]; Ports: *; Direction: inout; Trigger: LF_CLUSTER; Logs:
show less
Port Scan
๐ฌ๐ง
consul.to
2026-09-22 13:13:01
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
dynamix
2026-09-22 12:49:45
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:11:38
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.236.38.144 (144.38.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.38.144 (144.38.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:11:31.688935 2026] [security2:error] [pid 5875:tid 5875] [client 35.236.38.144:38140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "deargrampy.net"] [uri "/.env.example"] [unique_id "arJwc9LOxvzLJCZz3-T3BwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-22 12:05:31
(2 days ago)
Scanning/Probing (20)
Brute-Force
Web App Attack