🇩🇪
EGP Abuse Dept
2026-09-08 04:30:59
(2 minutes ago)
Scanning for web/db/file exploits on www.terhaag-wintergaerten.de
SQL Injection
Bad Web Bot
Web App Attack
🇩🇪
Viveronese
2026-09-08 03:53:29
(39 minutes ago)
HTTP vulnerability scanning
Web App Attack
🇬🇧
consul.to
2026-09-08 01:32:04
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-07 22:02:27
(6 hours ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-09-06.
show less
Web App Attack
SSH
Hacking
🇳🇱
Site.eu
2026-09-07 17:19:12
(11 hours ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-09-07 14:42:27
(13 hours ago)
Web scanner: GET /.git/config
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-07 14:19:16
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.255.219.4 (4.219.255.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.219.4 (4.219.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 10:19:09.543178 2026] [security2:error] [pid 8121:tid 8121] [client 35.255.219.4:33962] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.templeantiques.org"] [uri "/.git/config"] [unique_id "ap7H3a0repnHmPMYhrSeXgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 12:48:17
(15 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.255.219.4 (4.219.255.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:949110) triggered by 35.255.219.4 (4.219.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 08:48:13.257493 2026] [security2:error] [pid 24119:tid 24119] [client 35.255.219.4:46842] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.temp.pathpointsandbox.click"] [uri "/.git/config"] [unique_id "ap6yjWhTTfvu1ri2rCS2tQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 12:00:42
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.255.219.4 (4.219.255.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.219.4 (4.219.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 08:00:37.462551 2026] [security2:error] [pid 17001:tid 17001] [client 35.255.219.4:52786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.temi.handyrehab.com"] [uri "/.git/config"] [unique_id "ap6nZe3g_8ny2oJzxzNiewAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 11:45:51
(16 hours ago)
35.255.219.4 - - [07/Sep/2026:08:45:51 -0300] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Wi ...
show more
35.255.219.4 - - [07/Sep/2026:08:45:51 -0300] "GET /.git/config HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Port Scan
Hacking
SQL Injection
Brute-Force
Bad Web Bot
Exploited Host
🇺🇸
Starburst SysOp Team
2026-09-07 10:26:57
(18 hours ago)
Malware host detected by rbl.malware.expert. RBL lookup of 4.219.255.35.rbl.malware.expert succeeded ...
show more
Malware host detected by rbl.malware.expert. RBL lookup of 4.219.255.35.rbl.malware.expert succeeded at REMOTE_ADDR. (400010-mnz6-1)
show less
Hacking
🇸🇪
vaia.cloud
2026-09-07 08:45:44
(19 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 06:31:11
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.255.219.4 (4.219.255.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.219.4 (4.219.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 02:31:04.133838 2026] [security2:error] [pid 2504:tid 2504] [client 35.255.219.4:55644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.terruven.badritual.art"] [uri "/.git/config"] [unique_id "ap5aKOCEvtpfb3rZrKVeOQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 05:30:09
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.255.219.4 (4.219.255.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.255.219.4 (4.219.255.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 01:30:01.341665 2026] [security2:error] [pid 14667:tid 14667] [client 35.255.219.4:34756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.terrencetorrent.nickmontfort.com"] [uri "/.git/config"] [unique_id "ap5L2fxtzyPxmlXnKc55TgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇾
Rizzy
2026-09-07 04:56:58
(23 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack