🇩🇪
iNetWorker
2026-09-07 12:54:09
(17 minutes ago)
trolling for resource vulnerabilities
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 11:46:54
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.239.133.9 (9.133.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.133.9 (9.133.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 07:46:52.162846 2026] [security2:error] [pid 328006:tid 328029] [client 35.239.133.9:36548] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.photo.gallery.the-aquifer.com"] [uri "/.git/config"] [unique_id "ap6kLNmC3KD-cHRGzP7tDgAAANM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 11:12:56
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.239.133.9 (9.133.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.133.9 (9.133.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 07:12:50.063307 2026] [security2:error] [pid 5656:tid 5656] [client 35.239.133.9:44054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pintoresdecasascdmx.com.spyasociados.com"] [uri "/.git/config"] [unique_id "ap6cMgHaqgpEQS9A0R4KgAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 09:50:37
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.239.133.9 (9.133.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.133.9 (9.133.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 05:50:32.988572 2026] [security2:error] [pid 21352:tid 21352] [client 35.239.133.9:60592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.phoneresponse.com.junoproperties.com"] [uri "/.git/config"] [unique_id "ap6I6Ld_RWjTcCMBVLsGqgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
MM-bot
2026-09-07 09:37:47
(3 hours ago)
URL-probe: HTTP/1.1 GET request on /.git/config (2026-09-07 11:37:47 UTC+2)
Web App Attack
Hacking
Anonymous
2026-09-07 09:00:12
(4 hours ago)
PSCSERV WPSCAN 35.239.133.9
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 05:38:59
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.239.133.9 (9.133.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.133.9 (9.133.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 01:38:53.959744 2026] [security2:error] [pid 7386:tid 7386] [client 35.239.133.9:51474] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pinkdrink.com.digitalracemedia.com"] [uri "/.git/config"] [unique_id "ap5N7VjTmbdCDQ2b2MMPQgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
TheDjRider
2026-09-07 04:21:20
(8 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-07T04:21:18.459664891Z. Context: http_status=200
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 02:16:34
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.239.133.9 (9.133.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.239.133.9 (9.133.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 22:16:28.644494 2026] [security2:error] [pid 6037:tid 6037] [client 35.239.133.9:35824] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pine.rustyog.net|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pine.rustyog.net"] [uri "/.env.bak"] [unique_id "ap4efFWAvoaxxd_5yNiR3gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
mnsf
2026-09-07 02:05:16
(11 hours ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
🇩🇪
23p02732
2026-09-07 00:03:07
(13 hours ago)
Automated web scanning and malicious probing
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Philister11
2026-09-07 00:00:57
(13 hours ago)
CrowdSec: crowdsecurity/http-probing (US/AS396982)
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-06 22:11:58
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.239.133.9 (9.133.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.239.133.9 (9.133.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:11:52.695104 2026] [security2:error] [pid 12839:tid 12839] [client 35.239.133.9:47804] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pilotchristmascards.com"] [uri "/.git/config"] [unique_id "ap3lKED-Ao5q2xGEPRi1eAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-06 21:59:27
(15 hours ago)
Auto-ban: >3000 req/min op 2026-09-06
Web App Attack
SSH
Hacking
🇨🇦
polycoda
2026-09-06 21:24:06
(15 hours ago)
🔥 VERY AGGRESSIVE SCANNER probed over 500 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack