๐บ๐ธ
CDO
2026-09-30 18:38:14
(1 day ago)
URL Injection attempt detected. Automated web attack.
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-30 18:04:52
(1 day ago)
20 attempts against mh_ha-misbehave-ban on star
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:50:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.187.203.195 (195.203.187.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.203.195 (195.203.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:50:44.776094 2026] [security2:error] [pid 7451:tid 7451] [client 35.187.203.195:48770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.eta-mct.com"] [uri "/.env.js"] [unique_id "ar0v1FpERXWpPyBs30vbLQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-09-30 15:01:00
(1 day ago)
[30/Sep/2026:17:00:59 +0200] 179078045943.297951 35.187.203.195 56696 217.154.7.177 443
[30/Sep/2026 ...
show more
[30/Sep/2026:17:00:59 +0200] 179078045943.297951 35.187.203.195 56696 217.154.7.177 443
[30/Sep/2026:17:00:59 +0200] 179078045976.087965 35.187.203.195 56696 217.154.7.177 443
[30/Sep/2026:17:00:59 +0200] 179078045984.574014 35.187.203.195 56696 217.154.7.177 443
[30/Sep/2026:17:01:00 +0200] 179078046030.248903 35.187.203.195 56696 217.154.7.177 443
[30/Sep/2026:17:01:00 +0200] 179078046058.865591 35.187.203.195 56696 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-30 14:54:56
(1 day ago)
20 attempts against mh-misbehave-ban on burne
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:41:41
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.187.203.195 (195.203.187.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.187.203.195 (195.203.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:41:35.488850 2026] [security2:error] [pid 15777:tid 15887] [client 35.187.203.195:39074] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kettlehill.com|F|2"] [data ".kettlehill.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kettlehill.com"] [uri "/z9x8c7v6b5-debug-trigger-www.kettlehill.com"] [unique_id "ar0fn-14HsboWLZrESlMBgAAAlE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-30 14:21:41
(1 day ago)
35.187.203.195 - - [30/Sep/2026:14:21:07 +0000] "GET /wp-content/plugins/genesis-blocks/dist/assets/ ...
show more
35.187.203.195 - - [30/Sep/2026:14:21:07 +0000] "GET /wp-content/plugins/genesis-blocks/dist/assets/js/dismiss.js?ver=1787292027 HTTP/2.0" 403 19911 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.187.203.195"
35.187.203.195 - - [30/Sep/2026:14:21:07 +0000] "GET /wp-content/themes/Divi/includes/builder/feature/dynamic-assets/assets/js/motion-effects.js?ver=4.27.9 HTTP/2.0" 403 19911 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.187.203.195"
35.187.203.195 - - [30/Sep/2026:14:21:07 +0000] "GET /wp-content/plugins/restrict-content-pro/core/includes/gateways/stripe/js/register.min.js?ver=4.0.7 HTTP/2.0" 403 19893 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.187.203.195"
35.187.203.195 - - [30/Sep/2026:14:21:07 +0000] "GET
...
show less
Web App Attack
๐บ๐ธ
robotstxt
2026-09-30 14:05:18
(1 day ago)
35.187.203.195 - - [30/Sep/2026:14:04:38 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 36375 "-" "M ...
show more
35.187.203.195 - - [30/Sep/2026:14:04:38 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 36375 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "35.187.203.195" edge="162.159.106.183"
35.187.203.195 - - [30/Sep/2026:14:04:47 +0000] "GET /.dockerenv HTTP/2.0" 403 2 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "35.187.203.195" edge="172.71.8.66"
35.187.203.195 - - [30/Sep/2026:14:04:48 +0000] "GET /.ssh/config HTTP/2.0" 403 36390 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "35.187.203.195" edge="172.71.8.66"
35.187.203.195 - - [30/Sep/2026:14:04:48 +0000] "GET /.env.js HTTP/2.0" 403 2 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" "35.187.203.195" edge="104.22.148.30"
35.187.203.195 - - [30/Sep/2026:14:04:48 +0000] "GET /.zshrc HTTP/2.0" 403 2 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://d
...
show less
Web App Attack
๐ซ๐ฎ
albionfreemarket.com
2026-09-30 13:59:57
(1 day ago)
35.187.203.195 - - [30/Sep/2026:13:59:54 +0000] "POST /lib/terminal-xhr.php HTTP/2.0" 403 113 "-" "M ...
show more
35.187.203.195 - - [30/Sep/2026:13:59:54 +0000] "POST /lib/terminal-xhr.php HTTP/2.0" 403 113 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" 0.000 "-" "JP"
35.187.203.195 - - [30/Sep/2026:13:59:55 +0000] "POST /graphql HTTP/2.0" 403 171 "https://cdn.albionfreemarket.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" 0.000 "-" "JP"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-30 13:50:15
(1 day ago)
[cb-13al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[cb-13al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 35.187.203.195 - - [30/Sep/2026:15:49:52 +0200] "GET /.vite/manifest.json HTTP/2.0" 404 1878 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.187.203.195 - - [30/Sep/2026:15:49:52 +0200] "GET /74ch069tfqpux5re8mk9 HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
35.187.203.195 - - [30/Sep/2026:15:49:52 +0200] "GET /model/info HTTP/2.0" 404 1920 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
35.187.203.195 - - [30/Sep/2026:15:49:52 +0200] "GET /z9x8c7v6b5-debug-trigger-hub.dutchtallship.com HTTP/2.0" 404 1920 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
tinect
2026-09-30 13:41:47
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ณ๐ฑ
Savvii
2026-09-30 13:18:28
(1 day ago)
20 attempts against mh_ha-misbehave-ban on choy
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
cg-design.co.uk
2026-09-30 12:52:51
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 35.187.203.195 (JP/Japan/195.203.187.35 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.187.203.195 (JP/Japan/195.203.187.35.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-30 11:54:25
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.187.203.195 (195.203.187.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.187.203.195 (195.203.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:54:19.572206 2026] [security2:error] [pid 1623:tid 1623] [client 35.187.203.195:47728] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stable-vitals.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stable-vitals.com"] [uri "/z9x8c7v6b5-debug-trigger-stable-vitals.com"] [unique_id "arz4awPfs3HoXu_QZN3h6QAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-30 11:24:31
(2 days ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack