🇸🇪
vaia.cloud
2026-09-07 19:50:02
(55 minutes ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇳🇱
Site.eu
2026-09-07 16:44:32
(4 hours ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
neckaralb-admin.de
2026-09-07 16:04:09
(4 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-09-07 13:45:43
(6 hours ago)
Banned by Fail2Ban on server
Web App Attack
Anonymous
2026-09-07 13:41:50
(7 hours ago)
35.252.24.228 - - [07/Sep/2026:15:41:47 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows ...
show more
35.252.24.228 - - [07/Sep/2026:15:41:47 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.252.24.228 - - [07/Sep/2026:15:41:47 +0200] "POST / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.252.24.228 - - [07/Sep/2026:15:41:47 +0200] "POST / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.252.24.228 - - [07/Sep/2026:15:41:47 +0200] "POST / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.252.24.228 - - [07/Sep/2026:15:41:47 +0200] "GET /.git/config HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.252.24.228 - - [07/Sep/
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 13:26:30
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.24.228 (228.24.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.24.228 (228.24.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 09:26:24.220719 2026] [security2:error] [pid 19712:tid 19721] [client 35.252.24.228:53016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.store.heworeblack.com"] [uri "/.git/config"] [unique_id "ap67gOX1ieuV86ogWiWAXgAAAUQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 13:05:23
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.24.228 (228.24.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.24.228 (228.24.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 09:05:18.361818 2026] [security2:error] [pid 24078:tid 24078] [client 35.252.24.228:41264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stepiz62.com.appsdips.com"] [uri "/.git/config"] [unique_id "ap62jtnwFwR-D8_4Z-pKSQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 12:31:12
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.24.228 (228.24.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.24.228 (228.24.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 08:31:06.120699 2026] [security2:error] [pid 29444:tid 29444] [client 35.252.24.228:36112] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stephenshouse.org.dougscomputers.com"] [uri "/.git/config"] [unique_id "ap6uinAgGgiLI7_rJnAZJgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-07 12:26:35
(8 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
Anonymous
2026-09-07 08:13:29
(12 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
Anonymous
2026-09-07 08:08:34
(12 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: IL, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: IL, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:03:23
(13 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.24.228 (228.24.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.24.228 (228.24.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:03:17.203218 2026] [security2:error] [pid 19967:tid 19967] [client 35.252.24.228:35956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.stonesandbones.theillustrator.net"] [uri "/.git/config"] [unique_id "ap5htRdXeX614aJ2ILkq_AAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
dot.mg
2026-09-07 06:03:02
(14 hours ago)
Bad behaviour
Web Spam
🇩🇪
ghostwarriors
2026-09-07 04:50:09
(15 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
Anonymous
2026-09-07 04:47:38
(15 hours ago)
35.252.24.228 - - [06/Sep/2026:17:01:59 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Window ...
show more
35.252.24.228 - - [06/Sep/2026:17:01:59 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 172.70.153.162
35.252.24.228 - - [06/Sep/2026:17:01:59 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 172.70.153.162
35.252.24.228 - - [06/Sep/2026:17:01:59 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 172.70.153.162
35.252.24.228 - - [06/Sep/2026:17:01:59 -0500] "GET /.env.staging HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 172.70.153.162
35.252.24.228 - - [06/Sep/2026:17:02:00 -0500] "GET /.env.development HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) Appl
...
show less
Brute-Force
Bad Web Bot
Web App Attack