Anonymous
2026-09-03 03:13:10
(1 hour ago)
35.252.1.100 - - [03/Sep/2026:05:13:06 +0200] "GET /.git/config HTTP/1.1" 404 184 "-" "Mozilla/5.0 ( ...
show more
35.252.1.100 - - [03/Sep/2026:05:13:06 +0200] "GET /.git/config HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.252.1.100 - - [03/Sep/2026:05:13:06 +0200] "GET /.env HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.252.1.100 - - [03/Sep/2026:05:13:06 +0200] "GET /.env.local HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.252.1.100 - - [03/Sep/2026:05:13:06 +0200] "GET /.env.production HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.252.1.100 - - [03/Sep/2026:05:13:07 +0200] "GET /.env.staging HTTP/1.1" 404 184 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-03 01:50:58
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ฌ๐ง
andypiper
2026-09-03 01:02:51
(3 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-03 00:10:33
(4 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-02 23:42:14
(4 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 21:49:44
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.1.100 (100.1.252.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.1.100 (100.1.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 17:49:36.328192 2026] [security2:error] [pid 5937:tid 5937] [client 35.252.1.100:39828] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tv.grancanariaholidays.com"] [uri "/.git/config"] [unique_id "apiZ8PkHNslRyzlyhUm9aAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-02 21:05:16
(7 hours ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-02 20:54:46
(7 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.252.1.100 (100.1.252.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 35.252.1.100 (100.1.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 16:54:41.980197 2026] [security2:error] [pid 17946:tid 17946] [client 35.252.1.100:36964] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.tsmais.cescfoundation.org"] [uri "/.git/config"] [unique_id "apiNEXdtzw8Ej8IzmDLTtgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Dunham Support
2026-09-02 20:45:23
(7 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.252.1.100 (IL/Israel/100.1.252.35.bc ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.252.1.100 (IL/Israel/100.1.252.35.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
dot.mg
2026-09-02 20:18:23
(8 hours ago)
Bad behaviour
Web Spam
๐ฉ๐ช
LRob
2026-09-02 20:02:56
(8 hours ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /.git/config (+1 more) | 2026-09-02 20:02 UTC
show less
Hacking
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-09-02 13:02:58
(15 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
๐ณ๐ฟ
Antinson
2026-09-02 12:44:24
(15 hours ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-02 12:15:39
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.1.100 (100.1.252.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.1.100 (100.1.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 08:15:31.407119 2026] [security2:error] [pid 26501:tid 26501] [client 35.252.1.100:44426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.truthbeam.org.amybeam.com"] [uri "/.git/config"] [unique_id "apgTY3HeV4YtgwfK8LxRLQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-02 11:20:12
(17 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack