π©πͺ
4server
2026-09-15 20:57:01
(5 days ago)
[TueSep1522:56:56.9720592026][security2:error][pid3799455:tid3799555][client35.247.249.225:0]ModSecu ...
show more
[TueSep1522:56:56.9720592026][security2:error][pid3799455:tid3799555][client35.247.249.225:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.tecnospinasagl.ch.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"aqmxGKVoAg-FJsvSnPFj_gAAAM4\"]
show less
Port Scan
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 19:01:40
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.247.249.225 (225.249.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.249.225 (225.249.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:01:33.271892 2026] [security2:error] [pid 26581:tid 26581] [client 35.247.249.225:53796] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tecnoconce.tecnoconce.com"] [uri "/.git/config"] [unique_id "aqmWDTAI5CcujMVPO4n0SgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
tecnoacquisti.com
2026-09-15 18:41:25
(5 days ago)
PrestaShop Security Module: suspicious probe path detected (/phpinfo.php)
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 12:45:51
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.247.249.225 (225.249.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.249.225 (225.249.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 08:45:46.731697 2026] [security2:error] [pid 31880:tid 31880] [client 35.247.249.225:43886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wasabioldies.com"] [uri "/.git/config"] [unique_id "aqk9-nSJmBnpCNfUuuwb2QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
MM-bot
2026-09-15 08:34:57
(5 days ago)
URL-probe: HTTP/1.1 GET request on /.git/config (2026-09-15 10:34:57 UTC+2)
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-09-15 07:19:44
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.247.249.225 (225.249.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.249.225 (225.249.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 03:19:35.992425 2026] [security2:error] [pid 18261:tid 18261] [client 35.247.249.225:42592] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "warshaw1.com"] [uri "/.git/config"] [unique_id "aqjxh1ePxGHnSlHkgQJGDAAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 05:01:15
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.247.249.225 (225.249.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.249.225 (225.249.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 01:01:10.378146 2026] [security2:error] [pid 18796:tid 18796] [client 35.247.249.225:51700] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.technlunch.ahijado.org"] [uri "/.git/config"] [unique_id "aqjRFoeD1NOCxKtbPA8ksQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
pscriptos
2026-09-15 04:57:29
(5 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
π©πͺ
FeG Deutschland
2026-09-15 03:59:39
(5 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 124
Exploited Host
Web App Attack
Anonymous
2026-07-29 07:00:00
(1 month ago)
Apache probe; attempts=544; exact paths: /.env | /.env.backup | /.env.bak | /.env.dev | /.env.develo ...
show more
Apache probe; attempts=544; exact paths: /.env | /.env.backup | /.env.bak | /.env.dev | /.env.development | /.env.example | /.env.local | /.env.old | /.env.php.bak | /.env.prod.bak | /.env.production | /.env.production.bak | /.env.staging | /.env.swp | /.env.test | /.git-credentials | /.git/HEAD | /.git/config | /.hermes/.env | /.openclaw/.env | /@fs/.env?raw?? | /@fs/root/.env?raw?? | /actuator | /actuator/configprops | /actuator/env | /actuator/mappings | /admin/.env | /api/.env | /app/.env | /backend/.env | /config.env | /config/.env | /config/.env.php | /core/.env | /dev/.env | /docker/.env | /frontend/.env | /laravel/.env | /production/.env | /public/.env | /sendgrid.env | /server/.env | /src/.env | /staging/.env | /web/.env
show less
Web App Attack
π©πͺ
LRob
2026-07-24 13:20:23
(1 month ago)
CrowdSec: crowdsecurity/http-probing | req: /.git-credentials | 11 distinct paths | UA: Mozilla/5.0 ...
show more
CrowdSec: crowdsecurity/http-probing | req: /.git-credentials | 11 distinct paths | UA: Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)
show less
Port Scan
Web App Attack
π©πͺ
piticu iuli
2026-07-24 11:57:38
(1 month ago)
(mod_security) mod_security triggered on hostname [redacted] 35.247.249.225 (BR/Brazil/225.249.247.3 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.247.249.225 (BR/Brazil/225.249.247.35.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-07-24 08:02:57
(1 month ago)
Aggressive web scan
Web App Attack
π³π±
e.fierstra
2026-07-24 07:18:30
(1 month ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
π©πͺ
FeG Deutschland
2026-07-24 07:05:33
(1 month ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack