๐ณ๐ฑ
Alt255
2026-09-15 18:01:49
(2 days ago)
[ti-01ov] Excessive 404 errors (web scanning): 63 suspicious requests detected by fail2ban jail <nam ...
show more
[ti-01ov] Excessive 404 errors (web scanning): 63 suspicious requests detected by fail2ban jail <name>. Example: 35.187.91.162 - - [13/Sep/2026:16:35:32 +0200] "GET /z9x8c7v6b5-debug-trigger-maplegroupofcompanies.com HTTP/1.1" 404 2101 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
35.187.91.162 - - [13/Sep/2026:16:35:32 +0200] "POST /graphql HTTP/1.1" 404 2101 "https://maplegroupofcompanies.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
35.187.91.162 - - [13/Sep/2026:16:35:32 +0200] "POST /api/graphql HTTP/1.1" 404 2101 "https://maplegroupofcompanies.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
3
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-14 17:08:56
(3 days ago)
Excessive multi-domain requests
Brute-Force
๐ฎ๐ณ
evicky2002
2026-09-14 06:00:01
(3 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
e.fierstra
2026-09-14 05:28:11
(3 days ago)
excessive HTTP 404 errors
Bad Web Bot
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-14 02:36:02
(4 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
JustMeHere
2026-09-14 00:56:53
(4 days ago)
[Sun Sep 13 20:56:44.603461 2026] [security2:error] [pid 60737:tid 60786] [client 35.187.91.162:3769 ...
show more
[Sun Sep 13 20:56:44.603461 2026] [security2:error] [pid 60737:tid 60786] [client 35.187.91.162:37698] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "accountid.yorknation.com"] [uri "/"] [unique_id "aqdGTBIPbeFzE50wWg5b9QAAANU"]
...
show less
Web App Attack
๐บ๐ธ
mw
2026-09-14 00:01:03
(4 days ago)
GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env HTTP/1.1
Web App Attack
๐บ๐ธ
JustMeHere
2026-09-13 22:56:43
(4 days ago)
[Sun Sep 13 18:56:39.465966 2026] [security2:error] [pid 60737:tid 60782] [client 35.187.91.162:5162 ...
show more
[Sun Sep 13 18:56:39.465966 2026] [security2:error] [pid 60737:tid 60782] [client 35.187.91.162:51628] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "access.yorknation.com"] [uri "/"] [unique_id "aqcqJxIPbeFzE50wWg5HrQAAANE"]
...
show less
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-13 22:30:43
(4 days ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐ฌ๐ง
Apache
2026-09-13 20:04:25
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.187.91.162 (BE/Belgium/162.91.187.35.bc.goog ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.91.162 (BE/Belgium/162.91.187.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 20:00:40
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 35.187.91.162 (162.91.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.187.91.162 (162.91.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 16:00:35.809817 2026] [security2:error] [pid 7841:tid 7841] [client 35.187.91.162:34778] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||zmgmt.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "zmgmt.com"] [uri "/rclone.conf"] [unique_id "aqcA4_ub2LFJdBdQZ3-EgQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-13 19:35:21
(4 days ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ฉ๐ช
yvoictra
2026-09-13 19:25:39
(4 days ago)
Bloqueado automรกticamente por CrowdSec. Escenario: crowdsecurity/http-probing
Web App Attack
๐น๐ท
ycoskun41
2026-09-13 19:21:44
(4 days ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
๐น๐ท
ferique
2026-09-13 19:06:32
(4 days ago)
Real-time Intercept: DNN_AUTH attack. Reference: 2026-09-13 22:06:22.3006 Login failure: 35.187.91. ...
show more
Real-time Intercept: DNN_AUTH attack. Reference: 2026-09-13 22:06:22.3006 Login failure: 35.187.91.162 DNN_AUTH
show less
Web App Attack
Bad Web Bot