๐ซ๐ท
geot
2026-09-17 14:19:39
(17 hours ago)
GET /.docker/.env HTTP/1.1
GET /.env.production?raw HTTP/1.1
GET /wp/.env HTTP/1.1
GET /actuator/env ...
show more
GET /.docker/.env HTTP/1.1
GET /.env.production?raw HTTP/1.1
GET /wp/.env HTTP/1.1
GET /actuator/env HTTP/1.1
GET /docker-compose.yaml HTTP/1.1
GET /configuration.php.bak HTTP/1.1
GET /userfiles?path=../../../../.env HTTP/1.1
show less
Hacking
Web App Attack
Anonymous
2026-09-16 06:10:06
(2 days ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ซ๐ท
regishoussin
2026-09-16 04:52:16
(2 days ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-09-16 04:52 UTC.
show less
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-16 04:19:12
(2 days ago)
cloudlinux2 fail2ban: 2026-09-16 06:14:41,564 fail2ban.filter [1818]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-16 06:14:41,564 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 101.26.28.26 - 2026-09-16 06:14:41cloudlinux2 fail2ban: 2026-09-16 06:15:05,923 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 152.59.28.213 - 2026-09-16 06:15:05cloudlinux2 fail2ban: 2026-09-16 06:15:38,011 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 152.59.28.213 - 2026-09-16 06:15:38cloudlinux2 fail2ban: 2026-09-16 06:15:48,599 fail2ban.actions [1818]: NOTICE [plesk-modsecurity] Ban 35.193.12.80cloudlinux2 fail2ban: 2026-09-16 06:15:48,365 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 35.193.12.80 - 2026-09-16 06:15:48cloudlinux2 fail2ban: 2026-09-16 06:15:48,602 fail2ban.filter [1818]: INFO [recidive] Found 35.193.12.80 - 2026-09-16 06:15:48cloudlinux2 fail2ban: 2026-09-16 06:15:48,344 fail2ban.filter [1818]: INFO [plesk-modsecurity] Found 35.193.12.80 - 2026-09-16 06:15:48cloudlinux2 fail2ban: 2026-09-16
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-16 01:22:43
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.193.12.80 (80.12.193.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.193.12.80 (80.12.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:22:37.179922 2026] [security2:error] [pid 27694:tid 27694] [client 35.193.12.80:45200] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sansavin.com.hk"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqnvXRRnATEg2EjdtUbTPQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฉ๐ช
palzer.IT
2026-09-15 23:31:13
(2 days ago)
Fail2ban automatic report for plesk-apache-badbot: 35.193.12.80 - - [16/Sep/2026:01:30:53 +0200] GET ...
show more
Fail2ban automatic report for plesk-apache-badbot: 35.193.12.80 - - [16/Sep/2026:01:30:53 +0200] GET /z9x8c7v6b5-debug-trigger-sandraboehm.ch [DOMAIN_REMOVED] 404 58278 [DOMAIN_REMOVED] Mozilla/5.0 (compatible; Bytespider; spider-feedback@[DOMAIN_REMOVED]) AppleWebKit/537.36
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-15 22:48:00
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.193.12.80 (80.12.193.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.193.12.80 (80.12.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:47:56.087211 2026] [security2:error] [pid 12815:tid 12817] [client 35.193.12.80:34538] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sandbarsteve.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sandbarsteve.com"] [uri "/rclone.conf"] [unique_id "aqnLHPH9FdSgKFFmiWOC4gAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-15 22:05:15
(2 days ago)
Scanning/Probing (19)
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-15 21:57:30
(2 days ago)
[ti-02ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.193.12.80 - - [15/Sep/2026:23:57:30 +0200] "GET /@fs/.env?url&raw?? HTTP/2.0" 301 492 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:40:41
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.193.12.80 (80.12.193.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.193.12.80 (80.12.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:40:34.160695 2026] [security2:error] [pid 16424:tid 16424] [client 35.193.12.80:39934] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||samuelpaley.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "samuelpaley.com"] [uri "/server.key"] [unique_id "aqm7UqhaKuF7mo93cQP1sQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-09-15 21:37:11
(2 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.193.12.80 (US/Uni ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.193.12.80 (US/United States/80.12.193.35.bc.googleusercontent.com)
show less
Bad Web Bot
๐ฌ๐ง
Greg Poulson
2026-09-15 21:18:03
(2 days ago)
Our website was hit by this DDOS at a rate of 118 in 5 minutes.
DDoS Attack
Web Spam
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-15 20:53:18
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.193.12.80 (80.12.193.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.193.12.80 (80.12.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:53:12.794711 2026] [security2:error] [pid 5541:tid 5541] [client 35.193.12.80:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||samosbet.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "samosbet.com"] [uri "/rclone.conf"] [unique_id "aqmwOKrw-Vvru9bLeAZqGgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:00:55
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.193.12.80 (80.12.193.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.193.12.80 (80.12.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:00:48.933340 2026] [security2:error] [pid 16438:tid 16438] [client 35.193.12.80:47766] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||samelsner.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "samelsner.com"] [uri "/z9x8c7v6b5-debug-trigger-samelsner.com"] [unique_id "aqmj8GjAckg-Kwn9kJPdSAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack