πΊπΈ
TPI-Abuse
2026-09-19 13:13:13
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.156.94 (94.156.185.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.156.94 (94.156.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 19 09:13:08.071697 2026] [security2:error] [pid 13624:tid 13624] [client 35.185.156.94:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.hollyranch.com"] [uri "/pipeline/.env"] [unique_id "aq6KZBvDF0Rn4R_XSOJuWAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
itsolon
2026-09-19 05:55:39
(10 hours ago)
[19/Sep/2026:07:55:39 +0200] 178979733981.715864 35.185.156.94 41764 217.154.7.177 443
[19/Sep/2026: ...
show more
[19/Sep/2026:07:55:39 +0200] 178979733981.715864 35.185.156.94 41764 217.154.7.177 443
[19/Sep/2026:07:55:39 +0200] 178979733965.201941 35.185.156.94 41764 217.154.7.177 443
[19/Sep/2026:07:55:39 +0200] 178979733975.524646 35.185.156.94 41764 217.154.7.177 443
[19/Sep/2026:07:55:39 +0200] 178979733941.963553 35.185.156.94 41764 217.154.7.177 443
[19/Sep/2026:07:55:39 +0200] 178979733947.615974 35.185.156.94 41764 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
π©πͺ
raph
2026-09-19 04:34:15
(12 hours ago)
[LIB DIR] crawler /vendor/*, /node_modules/*, /laravel/*, etc.
Bad Web Bot
Web App Attack
π«π·
β¨
2026-09-19 01:57:04
(14 hours ago)
Domain : redirect.netenergy.uk
Rule : hack
2026-09-19 01:54:35 217.194.210.152 GET /z9x8c7v6b5-debug ...
show more
Domain : redirect.netenergy.uk
Rule : hack
2026-09-19 01:54:35 217.194.210.152 GET /z9x8c7v6b5-debug-trigger-blog.hermanwald.com - 443 - 35.185.156.94 HTTP/2 Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; https://openai.com/gptbot) - blog.hermanwald.com 404 0 2 1448 519 207 - -
show less
Hacking
SQL Injection
Brute-Force
π©πͺ
bazter.pro
2026-09-18 16:14:59
(1 day ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
πͺπΈ
el-brujo
2026-09-18 14:38:00
(1 day ago)
HTTP DDoS Attack Layer 7
DDoS Attack
π¨π
dalslab ltd
2026-09-18 13:42:41
(1 day ago)
[18/Sep/2026:15:42:40 +0200] - 404 404 - GET https ai.dalslab.com "/static/manifest.json" [Client 35 ...
show more
[18/Sep/2026:15:42:40 +0200] - 404 404 - GET https ai.dalslab.com "/static/manifest.json" [Client 35.185.156.94] [Length 22] [Gzip -] [Sent-to 10.1.1.246] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-"
[18/Sep/2026:15:42:40 +0200] - 405 405 - POST https ai.dalslab.com "/" [Client 35.185.156.94] [Length 31] [Gzip -] [Sent-to 10.1.1.246] "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)" "-"
[18/Sep/2026:15:42:40 +0200] - 405 405 - POST https ai.dalslab.com "/graphql" [Client 35.185.156.94] [Length 31] [Gzip -] [Sent-to 10.1.1.246] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "https://ai.dalslab.com"
[18/Sep/2026:15:42:41 +0200] - 404 404 - GET https ai.dalslab.com "/config.js" [Client 35.185.156.94] [Length 22] [Gzip -] [Sent-to 10.1.1.246] "CCBot/2.0 (https://commoncrawl.or
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-18 11:31:51
(1 day ago)
Portscan: TCP/8443 (5x), TCP/8080 (5x)
Port Scan
π©πͺ
XICTRON
2026-09-18 11:25:06
(1 day ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
π§πͺ
boxed-it
2026-09-18 11:14:37
(1 day ago)
GET /.git/config (Tarpitted for 42m26s, wasted 149.3kB)
Web App Attack
π¦πΊ
HostFission
2026-09-18 08:16:49
(1 day ago)
PSAD port scan detected
Port Scan
πͺπΈ
el-brujo
2026-09-18 04:27:41
(1 day ago)
18/Sep/2026:06:27:41.204644 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
18/Sep/2026:06:27:41.204644 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 35.185.156.94] ModSecurity: Warning. Pattern match "(?i)(?:\\\\\\\\x5c|(?:%(?:c(?:0%(?:[2aq]f|5c|9v)|1%(?:[19p]c|8s|af))|2(?:5(?:c(?:0%25af|1%259c)|2f|5c)|%46|f)|(?:(?:f(?:8%8)?0%8|e)0%80%a|bg%q)f|%3(?:2(?:%(?:%6|4)6|F)|5%%63)|u(?:221[56]|002f|EFC8|F025)|1u|5c)|0x(?:2f|5c)|\\\\\\\\/))(?:%(?:(?:f(?:(?:c%80|8)%8)?0%8 ..." at REQUEST_URI_RAW. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-930-APPLICATION-ATTACK-LFI.conf"] [line "48"] [id "930100"] [msg "Path Traversal Attack (/../)"] [data "Matched Data: /..%252f found within REQUEST_URI_RAW: /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw??"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-lfi"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/255/153/126"] [hostname "grafana.elhacker.net"] [uri "/@fs/..%2f..%2f..%2f..%2f..%
...
show less
Hacking
Web App Attack
π©πͺ
london2038.com
2026-09-18 03:16:54
(1 day ago)
Malformed or malicious web request
35.185.156.94 - - [18/Sep/2026:05:16:52 +0200] "POST /graphql HTT ...
show more
Malformed or malicious web request
35.185.156.94 - - [18/Sep/2026:05:16:52 +0200] "POST /graphql HTTP/2.0" 404 12693 "https://forum.<REDACTED>" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
show less
Hacking
Web App Attack
π©πͺ
konseptit
2026-09-18 03:16:45
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 35.185.156.94 (TW/Taiwan/94.156.185.35. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.185.156.94 (TW/Taiwan/94.156.185.35.bc.googleusercontent.com)
show less
SQL Injection
πΉπΌ
kk_it_man
2026-09-18 02:56:03
(1 day ago)
hack
Hacking