🇩🇪
ghostwarriors
2026-09-07 14:50:05
(21 minutes ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 14:45:23
(26 minutes ago)
(mod_security) mod_security (id:210492) triggered by 8.228.26.11 (11.26.228.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.26.11 (11.26.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 10:45:18.395704 2026] [security2:error] [pid 9870:tid 9870] [client 8.228.26.11:59218] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.turboswim.chevronparkett.com"] [uri "/.git/config"] [unique_id "ap7N_gvW780e24ALkK84hQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
yitzhaq
2026-09-07 14:33:32
(38 minutes ago)
8.228.26.11 - - [07/Sep/2026:16:33:24 +0200] "GET / HTTP/1.1" 302 4665 "-" "Mozilla/5.0 (Macintosh; ...
show more
8.228.26.11 - - [07/Sep/2026:16:33:24 +0200] "GET / HTTP/1.1" 302 4665 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.228.26.11 - - [07/Sep/2026:16:33:24 +0200] "POST / HTTP/1.1" 302 650 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.228.26.11 - - [07/Sep/2026:16:33:25 +0200] "GET /.git/config HTTP/1.1" 302 650 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.228.26.11 - - [07/Sep/2026:16:33:25 +0200] "POST / HTTP/1.1" 302 650 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.228.26.11 - - [07/Sep/2026:16:33:25 +0200] "GET /.env HTTP/1.1" 302 650 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.228.26.11
show less
Web App Attack
Hacking
🇦🇺
screwlooseit.com.au
2026-09-07 13:17:11
(1 hour ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/11.26.228.8.bc.googleusercontent. ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/11.26.228.8.bc.googleusercontent.com
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 08:32:25
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.26.11 (11.26.228.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.26.11 (11.26.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:32:19.845936 2026] [security2:error] [pid 25236:tid 25236] [client 8.228.26.11:39420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.twilight-2000.com.f4fbbs.com"] [uri "/.git/config"] [unique_id "ap52k50rWxLfCZJ0zmWH4wAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Octopuce
2026-09-07 08:04:30
(7 hours ago)
Aggressive web search of vulnerable pages: /.env /.env.local /app/.env /apps/.env /api/.env ...
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 07:49:08
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.26.11 (11.26.228.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.26.11 (11.26.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:49:02.802376 2026] [security2:error] [pid 7170:tid 7170] [client 8.228.26.11:49430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tumerotata.com"] [uri "/.git/config"] [unique_id "ap5sblQVWJq1sLbPwvn_6gAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-07 07:41:50
(7 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack
🇧🇪
cmbplf
2026-09-07 07:10:55
(8 hours ago)
17.727 requests in 1 hour (2mos3w1d)
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 05:32:49
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.26.11 (11.26.228.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.26.11 (11.26.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 01:32:44.673510 2026] [security2:error] [pid 22754:tid 22754] [client 8.228.26.11:56526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.twccsolutions.com"] [uri "/.git/config"] [unique_id "ap5MfO0mcM2sGSRluJznSAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-07 05:19:23
(9 hours ago)
8.228.26.11 - - [07/Sep/2026:07:19:20 +0200] "GET /.git/config HTTP/1.1" 404 184 "-" "Mozilla/5.0 (X ...
show more
8.228.26.11 - - [07/Sep/2026:07:19:20 +0200] "GET /.git/config HTTP/1.1" 404 184 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.228.26.11 - - [07/Sep/2026:07:19:21 +0200] "GET /.env HTTP/1.1" 404 184 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.228.26.11 - - [07/Sep/2026:07:19:21 +0200] "GET /.env.local HTTP/1.1" 404 184 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.228.26.11 - - [07/Sep/2026:07:19:21 +0200] "GET /.env.production HTTP/1.1" 404 184 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.228.26.11 - - [07/Sep/2026:07:19:21 +0200] "GET /.env.staging HTTP/1.1" 404 184 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
8.228.26.11 - - [07/Sep/2026:07:19:21 +0200] "GET /.env.de
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 03:46:17
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 8.228.26.11 (11.26.228.8.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 8.228.26.11 (11.26.228.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 23:46:12.261102 2026] [security2:error] [pid 3396:tid 3396] [client 8.228.26.11:43118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tvsolar.aguasolar.com"] [uri "/.git/config"] [unique_id "ap4zhFGiRytNKASyAf5bzgAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-07 03:43:16
(11 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
🇳🇱
Site.eu
2026-09-07 02:42:08
(12 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-07 00:44:18
(14 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack