๐ฉ๐ช
palzer.IT
2026-09-16 17:08:51
(14 hours ago)
Fail2ban automatic report for plesk-apache-badbot: 35.193.206.187 - - [15/Sep/2026:16:23:28 +0200] G ...
show more
Fail2ban automatic report for plesk-apache-badbot: 35.193.206.187 - - [15/Sep/2026:16:23:28 +0200] GET /__/firebase/init.json [DOMAIN_REMOVED] 404 6484 [DOMAIN_REMOVED] Mozilla/5.0 (compatible; Amazonbot/0.1; +[DOMAIN_REMOVED]
show less
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-09-16 01:39:54
(1 day ago)
[cb-09al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[cb-09al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 35.193.206.187 - - [16/Sep/2026:03:39:32 +0200] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/2.0" 404 1855 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
35.193.206.187 - - [16/Sep/2026:03:39:32 +0200] "GET /auth HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.193.206.187 - - [16/Sep/2026:03:39:32 +0200] "GET /signin HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.193.206.187 - - [16/Sep/2026:03:39:32 +0200] "GET /login
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-16 00:59:54
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-16 00:54:38
(1 day ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
๐ซ๐ท
sthoyer.de
2026-09-16 00:25:31
(1 day ago)
35.193.206.187 - - [16/Sep/2026:02:25:29 +0200] "GET /rclone.conf HTTP/2" 302 495 "-" "Mozilla/5.0 ( ...
show more
35.193.206.187 - - [16/Sep/2026:02:25:29 +0200] "GET /rclone.conf HTTP/2" 302 495 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
35.193.206.187 - - [16/Sep/2026:02:25:29 +0200] "GET /z9x8c7v6b5-debug-trigger-sthoyer.de HTTP/2" 302 495 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
35.193.206.187 - - [16/Sep/2026:02:25:30 +0200] "GET /assets/manifest.json HTTP/2" 302 495 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
...
show less
Web App Attack
๐ฉ๐ช
Serpentex
2026-09-15 23:53:52
(1 day ago)
35.193.206.187 - - [16/Sep/2026:01:53:51 +0200] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/proc/self/environ ...
show more
35.193.206.187 - - [16/Sep/2026:01:53:51 +0200] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/proc/self/environ HTTP/1.1" 400 150 "-" "-"
35.193.206.187 - - [16/Sep/2026:01:53:51 +0200] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env HTTP/1.1" 400 150 "-" "-"
35.193.206.187 - - [16/Sep/2026:01:53:51 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 150 "-" "-"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-15 22:06:44
(1 day ago)
[cb-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.193.206.187 - - [16/Sep/2026:00:06:43 +0200] "GET /proc/self/cmdline HTTP/2.0" 404 29381 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 21:42:14
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฌ๐ง
Celtic
2026-09-15 21:29:40
(1 day ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
๐บ๐ธ
mnsf
2026-09-15 21:06:21
(1 day ago)
Too many Status 40X (17)
Scanning/Probing (17)
Brute-Force
Web App Attack
๐ซ๐ท
Baking333
2026-09-15 17:17:39
(1 day ago)
[redacted] 35.193.206.187 - - [15/Sep/2026:18:17:38 +0100] "GET /.[redacted] HTTP/1.1" 302 6798 0/51 ...
show more
[redacted] 35.193.206.187 - - [15/Sep/2026:18:17:38 +0100] "GET /.[redacted] HTTP/1.1" 302 6798 0/51218 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; +claudebot@[redacted])" 443 [redacted] 35.193.206.187 - - [15/Sep/2026:18:17:38 +0100] "GET /.vite/[redacted] HTTP/1.1" 302 6798 0/45139 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" 443 [redacted] 35.193.206.187 - - [15/Sep/2026:18:17:38 +0100] "GET /public/[redacted] HTTP/1.1" 302 6798 0/51302 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://[redacted]/)" 443
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
[email protected]
2026-09-15 16:56:28
(1 day ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-09-15 15:55:07
(1 day ago)
2026-09-15 17:53:22 AH10244: invalid URI path (/%2e%2e/.env) && 2026-09-15 17:53:24 AH10244: invalid ...
show more
2026-09-15 17:53:22 AH10244: invalid URI path (/%2e%2e/.env) && 2026-09-15 17:53:24 AH10244: invalid URI path (/public/plugins/alertlist/../../../../../../../../proc/self/environ) && 2026-09-15 17:53:24 AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ) && 211 more within 20 minutes
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-15 15:16:03
(1 day ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-15 14:52:14
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.193.206.187 (187.206.193.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.193.206.187 (187.206.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:52:08.906581 2026] [security2:error] [pid 20895:tid 20895] [client 35.193.206.187:51914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "seizetheseason.com"] [uri "/.env.js"] [unique_id "aqlbmKNetbWhs6lAZ4qxUQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack