๐ฉ๐ช
marten_o
2026-07-25 04:04:22
(1 day ago)
35.95.150.191 - - [25/Jul/2026:06:04:22 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 404 49497 "-" "Mozill ...
show more
35.95.150.191 - - [25/Jul/2026:06:04:22 +0200] "GET /tmp/phpinfo.php HTTP/1.1" 404 49497 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 313 50603
...
show less
Web App Attack
๐ซ๐ท
masterguru
2026-07-25 03:18:08
(1 day ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-197)
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-07-25 02:08:33
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-24 22:03:35
(2 days ago)
Auto-ban: >3000 req/min op 2026-07-24
Web App Attack
SSH
Hacking
๐ฉ๐ช
4server
2026-07-24 13:07:08
(2 days ago)
[FriJul2415:07:04.1696982026][security2:error][pid2771118:tid2771393][client35.95.150.191:0]ModSecur ...
show more
[FriJul2415:07:04.1696982026][security2:error][pid2771118:tid2771393][client35.95.150.191:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.admin-services.ch.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"amNjeCgfodwgWfioVySWYgAAAE8\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 12:37:15
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.95.150.191 (ec2-35-95-150-191.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 35.95.150.191 (ec2-35-95-150-191.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 08:37:11.067325 2026] [security2:error] [pid 3761039:tid 3761039] [client 35.95.150.191:43560] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.adlynture.michaelsabbey.org"] [uri "/.git/config"] [unique_id "amNcd_vDFqIfNiNIA8gUFwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-24 12:01:14
(2 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-07-24 07:05:02
(2 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 06:33:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.95.150.191 (ec2-35-95-150-191.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 35.95.150.191 (ec2-35-95-150-191.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 02:33:48.771111 2026] [security2:error] [pid 268946:tid 268971] [client 35.95.150.191:40568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.actiontattooauburn.meanmouse.com"] [uri "/.git/config"] [unique_id "amMHTM_DbQ4MzBLkZ_Bn2gAAAJU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-07-24 04:40:05
(2 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 03:31:38
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.95.150.191 (ec2-35-95-150-191.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 35.95.150.191 (ec2-35-95-150-191.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 23:31:31.940161 2026] [security2:error] [pid 1517198:tid 1517198] [client 35.95.150.191:41552] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.acgprinting.computersraleigh.com"] [uri "/.git/config"] [unique_id "amLck94-RC3e4Djhf7J1WQAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-24 03:06:47
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.95.150.191 (ec2-35-95-150-191.us-west-2.comp ...
show more
(mod_security) mod_security (id:210492) triggered by 35.95.150.191 (ec2-35-95-150-191.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 23:06:39.822994 2026] [security2:error] [pid 3743626:tid 3743626] [client 35.95.150.191:36396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aceshd.mroxygen.org"] [uri "/.git/config"] [unique_id "amLWv6Ipm33dMC2VGMVUhwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack