Anonymous
2026-09-23 01:30:02
(1 hour ago)
CrowdSec decision: crowdsecurity/thinkphp-cve-2018-20062 (origin: crowdsec)
Port Scan
Anonymous
2026-09-23 00:30:05
(2 hours ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-23 00:21:19
(2 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-22 23:30:03
(3 hours ago)
CrowdSec decision: crowdsecurity/http-crawl-non_statics (origin: crowdsec)
Port Scan
๐ฉ๐ช
thesimonmanuel
2026-09-22 21:01:32
(6 hours ago)
35.195.114.147 - - [23/Sep/2026:02:31:31 +0530] "GET /static//app/.env HTTP/2.0" 403 106 "https://ww ...
show more
35.195.114.147 - - [23/Sep/2026:02:31:31 +0530] "GET /static//app/.env HTTP/2.0" 403 106 "https://www.[redacted].com/static//app/.env" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
show less
Web App Attack
๐บ๐ธ
www.nomadomia.com
2026-09-22 20:38:12
(6 hours ago)
Hack attack .env
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
Major Hostility
2026-09-22 18:41:18
(8 hours ago)
"GET /manifest.json HTTP/1.1" 404
"GET /webpack-stats.json HTTP/1.1" 404
"GET /signin HTTP/1.1" 404
...
show more
"GET /manifest.json HTTP/1.1" 404
"GET /webpack-stats.json HTTP/1.1" 404
"GET /signin HTTP/1.1" 404
"GET /sign-in HTTP/1.1" 404
"GET /auth HTTP/1.1" 404
"GET /dist/manifest.json HTTP/1.1" 404
"GET /x8p7ulnwv04gf45dk3o8 HTTP/1.1" 404
"GET /account/login HTTP/1.1" 404
"GET /user/login HTTP/1.1" 404
"GET /register HTTP/1.1" 404
"GET /forgot-password HTTP/1.1" 404
"GET /signup HTTP/1.1" 404
"GET /reset-password HTTP/1.1" 404
"GET /dashboard HTTP/1.1" 404
"GET /console HTTP/1.1" 404
"GET /admin HTTP/1.1" 404
"GET /backoffice HTTP/1.1" 404
"GET /panel HTTP/1.1" 404
"GET /account HTTP/1.1" 404
"GET /app HTTP/1.1" 404
"GET /portal HTTP/1.1" 404
"GET /s
show less
Web App Attack
Anonymous
2026-09-22 17:25:05
(9 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ฎ๐น
ciccio diddo
2026-09-22 16:11:09
(11 hours ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
๐ท๐ด
iulianh
2026-09-22 16:01:05
(11 hours ago)
80,443
Brute-Force
SSH
๐บ๐ธ
oralunal
2026-09-22 16:00:38
(11 hours ago)
IP banned by Fail2Ban in jail ah-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:37:44
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.195.114.147 (147.114.195.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.195.114.147 (147.114.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:37:39.749403 2026] [security2:error] [pid 26314:tid 26314] [client 35.195.114.147:55380] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||astglobalgroup.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "astglobalgroup.com"] [uri "/z9x8c7v6b5-debug-trigger-astglobalgroup.com"] [unique_id "arKgw0U-FplnN39sq2kjMgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:20:44
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.195.114.147 (147.114.195.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.195.114.147 (147.114.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:20:39.171184 2026] [security2:error] [pid 24536:tid 24536] [client 35.195.114.147:59422] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||barkoskieelectric.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "barkoskieelectric.com"] [uri "/z9x8c7v6b5-debug-trigger-barkoskieelectric.com"] [unique_id "arKcx332i0sYvRsLp-uVRQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:55:49
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.195.114.147 (147.114.195.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.195.114.147 (147.114.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:55:44.426570 2026] [security2:error] [pid 7934:tid 8001] [client 35.195.114.147:34844] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||colinkyffinmusic.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "colinkyffinmusic.com"] [uri "/z9x8c7v6b5-debug-trigger-colinkyffinmusic.com"] [unique_id "arKW8JFRVvFBDL2fMT0nwQAAAco"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
dalslab ltd
2026-09-22 14:47:35
(12 hours ago)
35.195.114.147 - - [22/Sep/2026:16:47:33 +0200] "POST /graphql HTTP/1.1" 405 556 "http://dalslab.com ...
show more
35.195.114.147 - - [22/Sep/2026:16:47:33 +0200] "POST /graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.195.114.147 - - [22/Sep/2026:16:47:33 +0200] "POST / HTTP/1.1" 405 154 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
35.195.114.147 - - [22/Sep/2026:16:47:33 +0200] "POST /api/graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.195.114.147 - - [22/Sep/2026:16:47:33 +0200] "POST /v1/graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.195.114.147 - - [22/Sep/2026:16:47:34 +0200] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 154 "-" "-"
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack