🇳🇱
homeshowdomain.nl
2026-09-05 22:01:03
(13 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-04.
show less
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-04 21:52:33
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.252.104.72 (72.104.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.104.72 (72.104.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:52:24.689355 2026] [security2:error] [pid 21522:tid 21522] [client 35.252.104.72:48542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.pinkrays.com"] [uri "/html/.git/config"] [unique_id "aps9mBpxo1nxWIHNWs7JywAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
e.fierstra
2026-09-04 21:29:31
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 21:03:01
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.252.104.72 (72.104.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.104.72 (72.104.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 17:02:54.036258 2026] [security2:error] [pid 18578:tid 18578] [client 35.252.104.72:33724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.jiveturkeyband.com"] [uri "/src/.git/config"] [unique_id "apsx_sZTKKnMpAcJ_cOOQQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 20:45:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.252.104.72 (72.104.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.104.72 (72.104.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 16:45:09.830300 2026] [security2:error] [pid 12058:tid 12058] [client 35.252.104.72:53492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "drgweich.com"] [uri "/html/.git/config"] [unique_id "apst1baaEFwe-DDIcfohPQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 20:12:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.252.104.72 (72.104.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.104.72 (72.104.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 16:12:51.711072 2026] [security2:error] [pid 25400:tid 25400] [client 35.252.104.72:43986] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dry-rot.coretermite.com"] [uri "/api/.git/config"] [unique_id "apsmQ4C6WZHKUF12I-GjdgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
gws-hostmaster
2026-09-04 19:36:11
(1 day ago)
ModSecurity OWASP CRS (Anomaly Score: 5): Restricted File Access Attempt;
Web App Attack
🇮🇹
clamehost.it
2026-09-04 18:42:32
(1 day ago)
Automatic report - Brute Force attack using this IP address
Brute-Force
🇩🇪
SwinT
2026-09-04 16:00:06
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 13:54:19
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.252.104.72 (72.104.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.104.72 (72.104.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 09:54:11.349486 2026] [security2:error] [pid 26555:tid 26583] [client 35.252.104.72:55338] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "boxvalleyrockers.com.workconfident.com"] [uri "/var/www/.git/config"] [unique_id "aprNg5Xp4EhPQJrK5E8khAAAAU4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-04 12:18:52
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇫🇷
dynamix
2026-09-04 11:46:27
(1 day ago)
Multiple WAF Violations
Web App Attack
🇩🇪
Vegascosmetics
2026-09-04 11:40:18
(2 days ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after sensitive config/credentials exposure probe. Evidence: AttackPattern: /\.git (Match: /.git)
show less
Hacking
Brute-Force
Web App Attack
🇧🇾
shopmax
2026-09-04 10:27:39
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇳🇱
Savvii
2026-09-04 10:27:21
(2 days ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack