🇸🇪
vaia.cloud
2026-09-12 07:20:02
(3 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇧🇷
dominioz
2026-09-12 05:46:24
(4 hours ago)
2026-09-12 05:45:16 GET /.env - - 35.246.127.199 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_ ...
show more
2026-09-12 05:45:16 GET /.env - - 35.246.127.199 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 495
2026-09-12 05:45:17 GET /.env.local - - 35.246.127.199 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 495
2026-09-12 05:45:19 GET /.env.production - - 35.246.127.199 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 495
2026-09-12 05:45:20 GET /.env.staging - - 35.246.127.199 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 495
2026-09-12 05:45:21 GET /.env.development - - 35.246.127.199 HTTP/1.1 Mozilla/5.0+(Macintosh;+Intel+Mac+OS+X+10_15_7)+AppleWebKit/537.36+(KHTML,+like+Gecko)+Chrome/131.0.0.0+Safari/537.36 - 301 495
2026-09-12 05:45:23 GET /.env.tes
...
show less
Web App Attack
🇳🇱
Savvii
2026-09-12 05:44:25
(4 hours ago)
20 attempts against mh-misbehave-ban on ceres
Brute-Force
Bad Web Bot
Web App Attack
🇨🇭
🇨🇭 Hosting
2026-09-12 05:10:36
(5 hours ago)
Automated WAF report: 400-500 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
🇩🇪
ger-stg-sifi1
2026-09-12 05:02:54
(5 hours ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
🇳🇱
Site.eu
2026-09-12 04:08:22
(6 hours ago)
Excessive multi-domain requests
Brute-Force
🇳🇱
Site.eu
2026-09-11 19:49:24
(14 hours ago)
Excessive 404/403 errors
Brute-Force
🇩🇪
4server
2026-09-11 19:30:01
(14 hours ago)
[FriSep1121:29:55.9499192026][security2:error][pid2209777:tid2209985][client35.246.127.199:0]ModSecu ...
show more
[FriSep1121:29:55.9499192026][security2:error][pid2209777:tid2209985][client35.246.127.199:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.tpgs.ch.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"aqRWs3dONmKibFW3FnCJGQAAAcg\"]
show less
Port Scan
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 16:27:57
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.246.127.199 (199.127.246.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.127.199 (199.127.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:27:53.741801 2026] [security2:error] [pid 15767:tid 15767] [client 35.246.127.199:37786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.grabnerconsulting.com"] [uri "/.git/config"] [unique_id "aqQsCTGaCExP1P5-S296CQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 14:42:17
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.246.127.199 (199.127.246.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.127.199 (199.127.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 10:42:10.351039 2026] [security2:error] [pid 21607:tid 21607] [client 35.246.127.199:50408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.desertrosedoves.com"] [uri "/.git/config"] [unique_id "aqQTQkEM3TlxWh3rCxchjwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 13:33:22
(20 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.246.127.199 (199.127.246.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.127.199 (199.127.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 09:33:19.593297 2026] [security2:error] [pid 11726:tid 11726] [client 35.246.127.199:43290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.boardingatthewedge.com"] [uri "/.git/config"] [unique_id "aqQDH6YYiPelYGaih9baRAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
pm33
2026-09-11 12:49:15
(21 hours ago)
Unauthorized connections HTTP 403
Web App Attack
🇧🇪
cmbplf
2026-09-11 12:12:57
(22 hours ago)
11.940 requests from abuseipdb.com blacklisted IP (2mos4d19h)
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 12:10:50
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.246.127.199 (199.127.246.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.127.199 (199.127.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 08:10:42.023815 2026] [security2:error] [pid 11328:tid 11328] [client 35.246.127.199:51064] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.aiamur.com"] [uri "/.git/config"] [unique_id "aqPvwiBuuMl2LviadH-jsQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 11:43:20
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.246.127.199 (199.127.246.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.127.199 (199.127.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 07:43:15.913323 2026] [security2:error] [pid 32319:tid 32319] [client 35.246.127.199:36314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.test.accinternational.net"] [uri "/.git/config"] [unique_id "aqPpU9Zm2fMzrb3cjLTpFAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack