๐บ๐ธ
mnsf
2026-09-20 16:05:10
(1 day ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
๐บ๐ธ
helios.live
2026-09-20 15:12:51
(1 day ago)
2026/09/20 15:12:51 [error] 1604909#1604909: *3899144 access forbidden by rule, client: 35.184.161.4 ...
show more
2026/09/20 15:12:51 [error] 1604909#1604909: *3899144 access forbidden by rule, client: 35.184.161.43, server: kocervpn.com, request: "GET /.aws/config HTTP/1.1", host: "kocervpn.com"
2026/09/20 15:12:51 [error] 1604909#1604909: *3899148 access forbidden by rule, client: 35.184.161.43, server: kocervpn.com, request: "GET /admin/.env HTTP/1.1", host: "kocervpn.com"
2026/09/20 15:12:51 [error] 1604909#1604909: *3899148 access forbidden by rule, client: 35.184.161.43, server: kocerroxy.com, request: "GET /.aws/credentials HTTP/1.1", host: "kocerroxy.com"
2026/09/20 15:12:51 [error] 1604909#1604909: *3899148 access forbidden by rule, client: 35.184.161.43, server: kocervpn.com, request: "GET /.git/config HTTP/1.1", host: "kocervpn.com"
2026/09/20 15:12:51 [error] 1604909#1604909: *3899148 access forbidden by rule, client: 35.184.161.43, server: kocerroxy.com, request: "GET /.aws/config HTTP/1.1", host: "kocerroxy.com"
...
show less
Web App Attack
๐น๐ท
ycoskun41
2026-09-20 15:11:15
(1 day ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 15:10:00
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.184.161.43 (43.161.184.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.184.161.43 (43.161.184.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:09:56.988799 2026] [security2:error] [pid 19867:tid 19867] [client 35.184.161.43:57790] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||kobraagencies.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kobraagencies.com"] [uri "/ssl/localhost.key"] [unique_id "aq_3RG9QJ4mOB1PTlSQSMwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:37:03
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.184.161.43 (43.161.184.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.184.161.43 (43.161.184.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:36:55.891961 2026] [security2:error] [pid 31453:tid 31453] [client 35.184.161.43:57286] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||knorgmusic.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "knorgmusic.com"] [uri "/localhost.key"] [unique_id "aq_vh8BcmYDOhldjKanNNwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-20 14:19:27
(1 day ago)
35.184.161.43 - - [20/Sep/2026:10:19:27 -0400] "GET /.aws/credentials HTTP/1.1" 404 4805 "-" "Mozill ...
show more
35.184.161.43 - - [20/Sep/2026:10:19:27 -0400] "GET /.aws/credentials HTTP/1.1" 404 4805 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
35.184.161.43 - - [20/Sep/2026:10:19:27 -0400] "GET /.git/config HTTP/1.1" 403 4792 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
35.184.161.43 - - [20/Sep/2026:10:19:27 -0400] "GET /config/.env HTTP/1.1" 403 4824 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-09-20 13:54:38
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ณ๐ด
Bots.go.to.hell
2026-09-20 13:54:36
(1 day ago)
This IP was detected by CrowdSec triggering custom/http-bad-crawler-ban
Web App Attack
Bad Web Bot
Anonymous
2026-09-20 13:50:50
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:50:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.184.161.43 (43.161.184.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.184.161.43 (43.161.184.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:50:44.512984 2026] [security2:error] [pid 12728:tid 12728] [client 35.184.161.43:41808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "jbaydeliveries.com"] [uri "/packages/.env"] [unique_id "aq_ktH5QIw_0wqRUdxhv8wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 13:30:06
(1 day ago)
CrowdSec decision: crowdsecurity/http-bad-user-agent (origin: crowdsec)
Port Scan
๐ฉ๐ช
bazter.pro
2026-09-20 13:23:49
(1 day ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:20:11
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.184.161.43 (43.161.184.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.184.161.43 (43.161.184.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:20:04.472604 2026] [security2:error] [pid 25540:tid 25540] [client 35.184.161.43:53970] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fritsknuf.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fritsknuf.com"] [uri "/z9x8c7v6b5-debug-trigger-fritsknuf.com"] [unique_id "aq_dhNG2bGQx0h8cvTwFywAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-20 13:14:45
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ฉ๐ช
todix
2026-09-20 13:03:01
(1 day ago)
Web App Attack Exploid from 35.184.161.43
Web App Attack