🇩🇪
maxpower
2026-09-12 18:01:53
(3 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.192.18.44 (US/United States/44.18.192 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.192.18.44 (US/United States/44.18.192.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.192.18.44 - - [12/Sep/2026:20:01:47 +0200] "GET /secrets.env HTTP/2.0" 429 41 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" "35.192.18.44" host=vortici.it
show less
Port Scan
🇳🇱
Savvii
2026-09-12 17:25:25
(4 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-12 17:09:21
(4 hours ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
maxpower
2026-09-12 16:10:06
(5 hours ago)
(junkbot) REGOLA 8 - Junk Bot Blocked 35.192.18.44 (US/United States/44.18.192.35.bc.googleuserconte ...
show more
(junkbot) REGOLA 8 - Junk Bot Blocked 35.192.18.44 (US/United States/44.18.192.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.192.18.44 - - [12/Sep/2026:18:10:00 +0200] "GET /api/v1/env HTTP/2.0" 200 4802 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" "35.192.18.44" host=villapardi.it
show less
Port Scan
🇺🇸
Victor López
2026-09-12 15:11:07
(6 hours ago)
videoprenatal.com 35.192.18.44 - - [12/Sep/2026:10:11:06 -0500] "GET /images../.env HTTP/2.0" 404 20 ...
show more
videoprenatal.com 35.192.18.44 - - [12/Sep/2026:10:11:06 -0500] "GET /images../.env HTTP/2.0" 404 20703 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)" -
videoprenatal.com 35.192.18.44 - - [12/Sep/2026:10:11:06 -0500] "GET /assets../.env HTTP/2.0" 404 20703 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" -
videoprenatal.com 35.192.18.44 - - [12/Sep/2026:10:11:07 -0500] "GET /uploads../.env HTTP/2.0" 404 20703 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)" -
...
show less
Hacking
Web App Attack
🇸🇪
vaia.cloud
2026-09-12 14:10:02
(7 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
🇩🇪
maxpower
2026-09-12 12:47:21
(9 hours ago)
(junkbot) REGOLA 8 - Junk Bot Blocked 35.192.18.44 (US/United States/44.18.192.35.bc.googleuserconte ...
show more
(junkbot) REGOLA 8 - Junk Bot Blocked 35.192.18.44 (US/United States/44.18.192.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.192.18.44 - - [12/Sep/2026:14:47:19 +0200] "GET /wp-json HTTP/2.0" 200 4802 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)" "35.192.18.44" host=villapardi.it
show less
Port Scan
🇺🇸
TPI-Abuse
2026-09-12 12:02:36
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.192.18.44 (44.18.192.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.192.18.44 (44.18.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 08:02:28.760764 2026] [security2:error] [pid 3230780:tid 3230823] [client 35.192.18.44:37526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "viasatsales.com"] [uri "/.git/config"] [unique_id "aqU_VAP7n45hLl7yoQ1HLwAAAI4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 11:24:33
(10 hours ago)
Detected by CrowdSec: crowdsecurity/http-bad-user-agent
Web App Attack
🇺🇸
H24
2026-09-12 11:18:14
(10 hours ago)
/@fs/.env /@fs/home/ec2-user/.aws/credentials /.env /uploads../.env //.env /@fs/var/task/.env /media ...
show more
/@fs/.env /@fs/home/ec2-user/.aws/credentials /.env /uploads../.env //.env /@fs/var/task/.env /media../.env /assets../.env /api/w/default/jobs_u/get_log_file/../../../../proc/self/environ /admin/.env
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 10:57:03
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.192.18.44 (44.18.192.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.192.18.44 (44.18.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 06:56:55.134745 2026] [security2:error] [pid 10664:tid 10664] [client 35.192.18.44:55348] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||velvetculture.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "velvetculture.com"] [uri "/rclone.conf"] [unique_id "aqUv99y45kueX-Jbd9PoLAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
debestelapp
2026-09-12 10:45:12
(11 hours ago)
Web App Attack
🇩🇪
Vegascosmetics
2026-09-12 10:40:00
(11 hours ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB repu ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after first-seen suspicion / AbuseIPDB reputation policy (no URL signature). Evidence: Suspicion-Ban (Score 85>=65, Abuse 100, NonEU, first-seen)
show less
Hacking
Exploited Host
Web App Attack
🇳🇱
Savvii
2026-09-12 09:58:59
(11 hours ago)
20 attempts against mh_ha-misbehave-ban on onion
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-12 09:48:34
(12 hours ago)
Excessive multi-domain requests
Brute-Force