🇳🇱
WeCloudit-Anti-Abuse
2026-09-11 09:40:28
(12 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-11 09:26:26
(26 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.247.242.100 (100.242.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.242.100 (100.242.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 05:26:18.590728 2026] [security2:error] [pid 27950:tid 27950] [client 35.247.242.100:60088] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.twccsolutions.com"] [uri "/.git/config"] [unique_id "aqPJOsR9TppQNS5Smj5a5AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
SSH-Admin
2026-09-11 09:00:04
(53 minutes ago)
Probing for Exploits on ns200
Exploited Host
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 07:58:45
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.247.242.100 (100.242.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.242.100 (100.242.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 03:58:42.049968 2026] [security2:error] [pid 12386:tid 12386] [client 35.247.242.100:33954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tvsolar.aguasolar.com"] [uri "/.git/config"] [unique_id "aqO0slwkqFz056eLi07NHAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
SSH-Admin
2026-09-11 07:03:02
(2 hours ago)
Probing for Exploits on ns74
Exploited Host
Web App Attack
🇳🇱
wlt-blocker
2026-09-11 05:09:51
(4 hours ago)
Unauthorized access to webpage admin
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 04:45:21
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.242.100 (100.242.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.242.100 (100.242.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 00:45:16.445834 2026] [security2:error] [pid 5120:tid 5120] [client 35.247.242.100:52096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tv.ctemdr.com"] [uri "/.git/config"] [unique_id "aqOHXHCBZS0sdNC4bGi0NAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-11 04:20:27
(5 hours ago)
Excessive multi-domain requests
Brute-Force
🇪🇸
pipeline.es
2026-09-11 03:27:43
(6 hours ago)
Web scanning / probing for vulnerable paths | URL: /core/.env | Evidence: altovolta.es 35.247.242.10 ...
show more
Web scanning / probing for vulnerable paths | URL: /core/.env | Evidence: altovolta.es 35.247.242.100 - - [11/Sep/2026:05:27:20 +0200] \"GET /core/.env HTTP/1.1\" 404 207 \"-\" \"Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=BR | ASN: GOOGLE-CLOUD-PLATFORM | Country: BR
show less
Port Scan
Web App Attack
🇩🇪
paissangroup
2026-09-11 01:30:39
(8 hours ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 01:24:19
(8 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.247.242.100 (100.242.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 35.247.242.100 (100.242.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 21:24:11.556890 2026] [security2:error] [pid 26328:tid 26328] [client 35.247.242.100:58090] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.tn.cescfoundation.org"] [uri "/.git/config"] [unique_id "aqNYO2kfx_1dAynhe4XWAwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-10 22:51:50
(11 hours ago)
Excessive 404/403 errors
Brute-Force
🇳🇱
homeshowdomain.nl
2026-09-10 22:00:07
(11 hours ago)
Auto-ban: >3000 req/min op 2026-09-10
Web App Attack
SSH
Hacking
🇨🇭
backslash
2026-09-10 17:18:00
(16 hours ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-10 15:24:49
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.242.100 (100.242.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.242.100 (100.242.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 11:24:45.862809 2026] [security2:error] [pid 871501:tid 871501] [client 35.247.242.100:42034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.utp.cyber507.net"] [uri "/.git/config"] [unique_id "aqLLvVnf1GYzWOxzPDey0AAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack