๐บ๐ธ
[email protected]
2026-09-21 16:46:12
(14 hours ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 71h59m51s)
Port Scan
๐ฟ๐ฆ
conure.sh
2026-09-21 06:01:02
(1 day ago)
csagent: score 23.0: 404 noise floor x12, secrets grab x2; 1 domain(s) in 2s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 05:57:40
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.189.247.171 (171.247.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.247.171 (171.247.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 01:57:36.240620 2026] [security2:error] [pid 19558:tid 19558] [client 35.189.247.171:35988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "kemela.com"] [uri "/.env.production"] [unique_id "arDHUB6tLw0FoOF2PDN1RgAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Phenix Info
2026-09-21 05:44:16
(1 day ago)
SmallGuard.fr/Prestashop Forbidden Ext.
Web App Attack
๐ฉ๐ช
itsolon
2026-09-21 05:43:26
(1 day ago)
[21/Sep/2026:07:43:25 +0200] 178996940548.106808 35.189.247.171 49832 217.154.7.177 443
[21/Sep/2026 ...
show more
[21/Sep/2026:07:43:25 +0200] 178996940548.106808 35.189.247.171 49832 217.154.7.177 443
[21/Sep/2026:07:43:25 +0200] 178996940519.926393 35.189.247.171 49832 217.154.7.177 443
[21/Sep/2026:07:43:25 +0200] 178996940520.501861 35.189.247.171 49832 217.154.7.177 443
[21/Sep/2026:07:43:25 +0200] 178996940533.625921 35.189.247.171 49832 217.154.7.177 443
[21/Sep/2026:07:43:26 +0200] 178996940683.947020 35.189.247.171 49832 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-21 05:30:03
(1 day ago)
CrowdSec decision: crowdsecurity/thinkphp-cve-2018-20062 (origin: crowdsec)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-21 04:58:22
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.189.247.171 (171.247.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.247.171 (171.247.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:58:17.031344 2026] [security2:error] [pid 29727:tid 29783] [client 35.189.247.171:37578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.hollyandandreproperties.com"] [uri "/.git/HEAD"] [unique_id "arC5aY_RyAe_x-7YxDsp9AAAAY8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:09:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.189.247.171 (171.247.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.247.171 (171.247.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:09:16.755118 2026] [security2:error] [pid 18254:tid 18254] [client 35.189.247.171:36382] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hollywoo9.exotic-dancers-los-angeles.com"] [uri "/@fs/var/task/.env"] [unique_id "arCt7IRIxeACk5I-ti-K7AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 03:30:02
(1 day ago)
CrowdSec decision: crowdsecurity/http-probing (origin: crowdsec)
Web App Attack
Anonymous
2026-09-21 02:30:03
(1 day ago)
CrowdSec decision: crowdsecurity/http-crawl-non_statics (origin: crowdsec)
Port Scan
๐จ๐ญ
dalslab ltd
2026-09-21 02:22:47
(1 day ago)
[21/Sep/2026:04:22:46 +0200] - 405 405 - POST https ai.dalslab.com "/graphql" [Client 35.189.247.171 ...
show more
[21/Sep/2026:04:22:46 +0200] - 405 405 - POST https ai.dalslab.com "/graphql" [Client 35.189.247.171] [Length 31] [Gzip -] [Sent-to 10.1.1.246] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "https://ai.dalslab.com"
[21/Sep/2026:04:22:46 +0200] - 404 404 - GET https ai.dalslab.com "/static/manifest.json" [Client 35.189.247.171] [Length 22] [Gzip -] [Sent-to 10.1.1.246] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-"
[21/Sep/2026:04:22:46 +0200] - 405 405 - POST https ai.dalslab.com "/api/graphql" [Client 35.189.247.171] [Length 31] [Gzip -] [Sent-to 10.1.1.246] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "https://ai.dalslab.com"
[21/Sep/2026:04:22:46 +0200] - 405 405 - POST https ai.dalslab.com "/v1/graphql" [Client 35.189.247.171] [Length 31] [Gzip -] [Sent-to 10.
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-21 02:15:02
(1 day ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-21 01:30:03
(1 day ago)
CrowdSec decision: crowdsecurity/http-path-traversal-probing (origin: crowdsec)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-21 00:50:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.189.247.171 (171.247.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.247.171 (171.247.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:50:31.257465 2026] [security2:error] [pid 22004:tid 22004] [client 35.189.247.171:36660] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.honeybeeplace.com"] [uri "/.env.bak"] [unique_id "arB_VzShC533EnCWVJtXbAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:25:06
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.189.247.171 (171.247.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.247.171 (171.247.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:25:03.369183 2026] [security2:error] [pid 28393:tid 28393] [client 35.189.247.171:37748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "home.agingworkforcenews.com"] [uri "/.env.js"] [unique_id "arB5X8aY8NW3cMMEaYNevwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack