🇳🇱
Site.eu
2026-09-03 12:18:40
(41 minutes ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-03 11:23:03
(1 hour ago)
Bot / scanning and/or hacking attempts: GET /keyfile.json HTTP/1.1, GET /gcp-sa.json HTTP/1.1, GET / ...
show more
Bot / scanning and/or hacking attempts: GET /keyfile.json HTTP/1.1, GET /gcp-sa.json HTTP/1.1, GET /.config/gcloud/application_default_credentials.json HTTP/1, GET /gcp-credentials.json HTTP/1.1, GET /service-account.json HTTP/1.1, GET /phpinfo.php.old HTTP/1.1, GET / HTTP/1.1, GET /firebase-key.json HTTP/1.1, GET /credentials.json HTTP/1.1, GET /key.json HTTP/1.1
show less
Hacking
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 07:43:03
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.103.92 (92.103.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.103.92 (92.103.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 03:43:00.345418 2026] [security2:error] [pid 26676:tid 26676] [client 35.252.103.92:49778] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thestardance.stardancertantra.com"] [uri "/.git/config"] [unique_id "apklBM-a33eKzpHsOzOPHwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
masterguru
2026-09-03 07:34:29
(5 hours ago)
Remote Command Execution: Unix Shell Expression Found. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\ ...
show more
Remote Command Execution: Unix Shell Expression Found. Pattern match "(?:\\\\$(?:\\\\((?:\\\\(.*\\\\)|.*)\\\\)|\\\\{.*\\\\})| (932130-147)
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-03 06:46:18
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.103.92 (92.103.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.103.92 (92.103.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 02:46:14.505096 2026] [security2:error] [pid 19003:tid 19003] [client 35.252.103.92:44376] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thespotfurniture.trademartghana.com"] [uri "/.git/config"] [unique_id "apkXtl9_NiMj-LYCnWgyrwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 05:37:47
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.103.92 (92.103.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.103.92 (92.103.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 01:37:40.068386 2026] [security2:error] [pid 26688:tid 26688] [client 35.252.103.92:47732] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thepodiatricbillingspecialists.drxcontent.com"] [uri "/.git/config"] [unique_id "apkHpJLbk0K0HOTbmKwMIQAAAHM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-03 05:20:05
(7 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-03 05:10:26
(7 hours ago)
35.252.103.92 - - [03/Sep/2026:07:10:20 +0200] "POST / HTTP/1.1" 500 1438 "-" "Mozilla/5.0 (Macintos ...
show more
35.252.103.92 - - [03/Sep/2026:07:10:20 +0200] "POST / HTTP/1.1" 500 1438 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.252.103.92 - - [03/Sep/2026:07:10:21 +0200] "GET /.env HTTP/1.1" 404 4508 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.252.103.92 - - [03/Sep/2026:07:10:21 +0200] "GET /.env.local HTTP/1.1" 404 520 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.252.103.92 - - [03/Sep/2026:07:10:21 +0200] "GET /.env.production HTTP/1.1" 404 520 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.252.103.92 - - [03/Sep/2026:07:10:22 +0200] "GET /.env.staging HTTP/1.1" 404 520 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/1
show less
Web App Attack
Hacking
🇲🇽
octageeks.com
2026-09-03 04:18:38
(8 hours ago)
Wordpress malicious attack:[octablocked]
Web App Attack
🇩🇪
Lino Project
2026-09-03 03:27:47
(9 hours ago)
35.252.103.92 - - [03/Sep/2026:05:27:43 +0200] "GET /.git/config HTTP/1.1" 403 424 "-" "Mozilla/5.0 ...
show more
35.252.103.92 - - [03/Sep/2026:05:27:43 +0200] "GET /.git/config HTTP/1.1" 403 424 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 01:30:25
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.103.92 (92.103.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.103.92 (92.103.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 21:30:17.789103 2026] [security2:error] [pid 922:tid 922] [client 35.252.103.92:34202] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thepeonypeople.com.vanemby.com"] [uri "/.git/config"] [unique_id "apjNqeNsHks69NME8oqV9wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
andypiper
2026-09-03 01:02:03
(11 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 00:40:27
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.103.92 (92.103.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.103.92 (92.103.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 20:40:22.544011 2026] [security2:error] [pid 23325:tid 23325] [client 35.252.103.92:48122] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.thesiteworks.windisfun.com"] [uri "/.git/config"] [unique_id "apjB9kc5ATHa6X2vy3GtqQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Hazzard
2026-09-03 00:12:32
(12 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
🇺🇸
TPI-Abuse
2026-09-02 21:17:43
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.103.92 (92.103.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.103.92 (92.103.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 17:17:38.188185 2026] [security2:error] [pid 15175:tid 15175] [client 35.252.103.92:39710] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.theseventhcongregationofladderdayvixens.org.tortoisehosting.com"] [uri "/.git/config"] [unique_id "apiScoHVPfiIRiDLITMZfQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack