🇳🇱
homeshowdomain.nl
2026-09-05 22:02:00
(23 minutes ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-04.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-05 21:02:55
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.247.198.223 (223.198.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.198.223 (223.198.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 05 17:02:51.912873 2026] [security2:error] [pid 10047:tid 10047] [client 35.247.198.223:47350] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail02.semisysteme.com"] [uri "/htdocs/.git/config"] [unique_id "apyDe1JkqozxxwYcaUhvpAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
gamabe
2026-09-05 20:45:45
(1 hour ago)
Detected crowdsecurity/http-sensitive-files attack pattern. Reported by CrowdSec IDS.
Hacking
🇳🇱
WeCloudit-Anti-Abuse
2026-09-05 02:30:28
(19 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
🇳🇱
Savvii
2026-09-04 23:07:38
(23 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-04 21:42:58
(1 day ago)
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/public/.git/config | /html/ ...
show more
[da.kdns.gr] httpd-config-scan: logs=/var/log/httpd/access_log; samples=/public/.git/config | /html/.git/config | /.git/config
show less
Hacking
Web App Attack
🇫🇷
dynamix
2026-09-04 21:35:49
(1 day ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:08:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.198.223 (223.198.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.198.223 (223.198.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:08:52.307065 2026] [security2:error] [pid 13663:tid 13663] [client 35.247.198.223:44980] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.emeraldhighlands.org"] [uri "/backend/.git/config"] [unique_id "apszZJjDp2VJ0dakAsLbcgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
2000cn.com.au
2026-09-04 18:37:40
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 15:52:56
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇩🇪
big-cloud.nl
2026-09-04 11:39:26
(1 day ago)
Try to access /src/.git/config
Web App Attack
Anonymous
2026-09-04 11:38:22
(1 day ago)
35.247.198.223 - - [04/Sep/2026:13:38:21 +0200] "GET /src/.git/config HTTP/1.1" 403 164 "-" "crusade ...
show more
35.247.198.223 - - [04/Sep/2026:13:38:21 +0200] "GET /src/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.247.198.223 - - [04/Sep/2026:13:38:21 +0200] "GET /var/www/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.247.198.223 - - [04/Sep/2026:13:38:21 +0200] "GET /www/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.247.198.223 - - [04/Sep/2026:13:38:21 +0200] "GET /public/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.247.198.223 - - [04/Sep/2026:13:38:21 +0200] "GET /site/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.247.198.223 - - [04/Sep/2026:13:38:21 +0200] "GET /.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.247.198.223 - - [04/Sep/2026:13:38:21 +0200] "GET /backend/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.247.198.223 - - [04/Sep/2026:13:38:21 +0200] "GET /wordpress/.git/config HTTP/1.1" 403 164 "-" "crusader-worker/1.0"
35.247.198.223 - - [04/Sep/2026:13:38:21 +0200] "GET /app/.git/config HTTP
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 11:37:10
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.198.223 (223.198.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.198.223 (223.198.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 07:37:04.233225 2026] [security2:error] [pid 3251:tid 3251] [client 35.247.198.223:41666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thegrousewoods.com"] [uri "/var/www/.git/config"] [unique_id "apqtYDyASlR-WFbLsD_jJQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 10:24:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.198.223 (223.198.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.198.223 (223.198.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 06:24:41.448108 2026] [security2:error] [pid 25607:tid 25607] [client 35.247.198.223:40664] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "authsmtp.davisllp.com"] [uri "/htdocs/.git/config"] [unique_id "apqcaQ-JCzeDp8kHAVp98gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-04 09:51:01
(1 day ago)
Web attack/malicious scanning detected
Web App Attack