🇳🇱
Site.eu
2026-09-07 02:00:25
(5 hours ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
Skyrider
2026-09-07 00:50:58
(6 hours ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
🇫🇮
albionfreemarket.com
2026-09-06 22:01:03
(9 hours ago)
35.194.171.186 - - [06/Sep/2026:22:01:00 +0000] "POST /graphql HTTP/2.0" 403 555 "https://api.albion ...
show more
35.194.171.186 - - [06/Sep/2026:22:01:00 +0000] "POST /graphql HTTP/2.0" 403 555 "https://api.albionfreemarket.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" 0.000 "-" "TW"
35.194.171.186 - - [06/Sep/2026:22:01:01 +0000] "POST /api/graphql HTTP/2.0" 403 555 "https://api.albionfreemarket.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" 0.000 "-" "TW"
...
show less
Bad Web Bot
Web App Attack
🇺🇸
agenciahypelab.com.br
2026-09-06 20:49:55
(10 hours ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-06 20:35:37
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.171.186 (186.171.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.171.186 (186.171.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:35:30.842106 2026] [security2:error] [pid 1317:tid 1317] [client 35.194.171.186:53770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.tulsatvmemories.com"] [uri "/.env.local"] [unique_id "ap3OkkgGpTCDH5rpJnAaHAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 20:26:47
(10 hours ago)
Portscan: TCP/8443 (4x), TCP/8080 (3x)
Port Scan
🇺🇸
xmission.com
2026-09-06 19:40:32
(11 hours ago)
35.194.171.186 - - [06/Sep/2026:13:40:25 -0600] "-" 400 150 "-" "-"
35.194.171.186 - - [06/Sep/2026: ...
show more
35.194.171.186 - - [06/Sep/2026:13:40:25 -0600] "-" 400 150 "-" "-"
35.194.171.186 - - [06/Sep/2026:13:40:25 -0600] "-" 400 150 "-" "-"
35.194.171.186 - - [06/Sep/2026:13:40:28 -0600] "-" 400 150 "-" "-"
35.194.171.186 - - [06/Sep/2026:13:40:28 -0600] "-" 400 150 "-" "-"
35.194.171.186 - - [06/Sep/2026:13:40:31 -0600] "-" 400 150 "-" "-"
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 16:01:48
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.194.171.186 (186.171.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.171.186 (186.171.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 12:01:44.434888 2026] [security2:error] [pid 9899:tid 9899] [client 35.194.171.186:46700] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||davidocchino.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "davidocchino.com"] [uri "/rclone.conf"] [unique_id "ap2OaBlKEppo5d0l4z_9ugAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
interbiznw.com
2026-09-06 15:09:53
(16 hours ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
🇬🇧
Apache
2026-09-06 13:19:04
(18 hours ago)
(mod_security) mod_security (id:930130) triggered by 35.194.171.186 (TW/Taiwan/186.171.194.35.bc.goo ...
show more
(mod_security) mod_security (id:930130) triggered by 35.194.171.186 (TW/Taiwan/186.171.194.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
🇦🇺
[email protected]
2026-09-06 13:12:42
(18 hours ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /v1/graphql
Web App Attack
🇵🇱
sefinek.net
2026-09-06 10:53:44
(20 hours ago)
Triggered Cloudflare WAF (firewallCustom) from TW.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint ...
show more
Triggered Cloudflare WAF (firewallCustom) from TW.
Action: BLOCK | Protocol: HTTP/2 (GET) | Endpoint: /css../.env | UA: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/148.0.0.0 Mobile Safari/537.36 EdgA/148.0.0.0 • Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 10:44:51
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.194.171.186 (186.171.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.171.186 (186.171.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 06:44:45.403695 2026] [security2:error] [pid 8350:tid 8350] [client 35.194.171.186:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||upskirtcrazy.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "upskirtcrazy.com"] [uri "/z9x8c7v6b5-debug-trigger-upskirtcrazy.com"] [unique_id "ap1EHcXZlq3tzFf2doRVzgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
COMAITE
2026-09-06 10:18:29
(21 hours ago)
Suspicious URL access.
Web App Attack
🇩🇪
Skyrider
2026-09-06 10:07:05
(21 hours ago)
crowdsecurity/http-probing
Web App Attack