๐ณ๐ฑ
homeshowdomain.nl
2026-09-16 22:02:06
(1 day ago)
Auto-ban: >3000 req/min op 2026-09-16
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-16 06:49:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.247.203.28 (28.203.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.203.28 (28.203.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 02:48:59.094096 2026] [security2:error] [pid 622:tid 622] [client 35.247.203.28:41694] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.staff.getitenglish.com"] [uri "/.git/config"] [unique_id "aqo72-K6XF1FC2PnGueUEAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-16 04:47:51
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-16 02:36:57
(1 day ago)
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35. ...
show more
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35.247.203.28 - - \[16/Sep/2026:04:36:52 +0200\] "GET /.git/config HTTP/1.1" 500 6015 "-" "Mozilla/5.0 \(Macintosh\; Intel Mac OS X 10_15_7\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ด
jad-abuse
2026-09-16 02:33:31
(1 day ago)
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_expos ...
show more
ActiveDefense automated detection: malicious HTTP scanning / exploit attempts. Signatures: git_exposure, env_probe, source_backup. Observed by 1 sensor(s); 17 hits.
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-15 21:48:04
(2 days ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.247.203.28 (BR/Brazil/28.203.247. ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.247.203.28 (BR/Brazil/28.203.247.35.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-15 19:49:34
(2 days ago)
35.247.203.28 - - [15/Sep/2026:19:48:32 +0000] "POST / HTTP/1.1" 403 18465 "-" "Mozilla/5.0 (X11; Li ...
show more
35.247.203.28 - - [15/Sep/2026:19:48:32 +0000] "POST / HTTP/1.1" 403 18465 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.247.203.28"
35.247.203.28 - - [15/Sep/2026:19:48:33 +0000] "POST / HTTP/1.1" 403 18466 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.247.203.28"
35.247.203.28 - - [15/Sep/2026:19:48:33 +0000] "GET /.git/config HTTP/1.1" 403 14325 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.247.203.28"
35.247.203.28 - - [15/Sep/2026:19:48:33 +0000] "GET /.env HTTP/1.1" 403 14325 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.247.203.28"
35.247.203.28 - - [15/Sep/2026:19:48:34 +0000] "GET /.env.local HTTP/1.1" 403 14325 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Ge
...
show less
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-15 19:27:42
(2 days ago)
(modsecurity) srv102 ModSecurity 35.247.203.28 (BR/Brazil/28.203.247.35.bc.googleusercontent.com): 3 ...
show more
(modsecurity) srv102 ModSecurity 35.247.203.28 (BR/Brazil/28.203.247.35.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-15 09:10:11
(2 days ago)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 07:18:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.247.203.28 (28.203.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.203.28 (28.203.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 03:18:43.002662 2026] [security2:error] [pid 18240:tid 18240] [client 35.247.203.28:39282] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.justiniggercom.indie100.com"] [uri "/.git/config"] [unique_id "aqjxU56tiveudbkZcLJVPgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-15 04:22:35
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
homeshowdomain.nl
2026-09-05 22:03:17
(1 week ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-04.
show less
Web App Attack
SSH
Hacking
๐ณ๐ฑ
e.fierstra
2026-09-04 15:01:24
(1 week ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 14:47:22
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.247.203.28 (28.203.247.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.203.28 (28.203.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 10:47:15.627025 2026] [security2:error] [pid 31768:tid 31768] [client 35.247.203.28:58140] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "claytonappliancenewnan.com"] [uri "/.env.dev"] [unique_id "aprZ87OPaCADVYcwlujQsgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-04 13:40:04
(1 week ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack