๐ณ๐ฑ
oisecnet
2026-10-02 21:02:08
(6 days ago)
Automated report: Unauthorized vulnerability scanning detected on 2026-10-02. 690 requests from this ...
show more
Automated report: Unauthorized vulnerability scanning detected on 2026-10-02. 690 requests from this IP.
show less
Port Scan
Hacking
Web App Attack
๐บ๐ธ
Charlesiv
2026-10-02 16:00:17
(6 days ago)
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from BE.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /app_dev.php
Timestamp: 2026-10-02T14:51:01Z
Ray ID: a44485d7081bd87e
UA: Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)
show less
Bad Web Bot
๐ต๐ฑ
sefinek.net
2026-10-02 15:42:56
(6 days ago)
Triggered Cloudflare WAF (firewallCustom) from BE.
Action: BLOCK | Protocol: HTTP/2 (POST) | Endpoin ...
show more
Triggered Cloudflare WAF (firewallCustom) from BE.
Action: BLOCK | Protocol: HTTP/2 (POST) | Endpoint: /cgi-bin/php-cgi | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot โข Generated by: github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐ฉ๐ช
LRob
2026-10-02 15:15:27
(6 days ago)
Vulnerability scanning | method: GET, POST | path: /z9x8c7v6b5-debug-trigger-mail.lusineagaz.net, /k ...
show more
Vulnerability scanning | method: GET, POST | path: /z9x8c7v6b5-debug-trigger-mail.lusineagaz.net, /kuffrze5zrgoi2pf3y3o, /assets/manifest.json (+16 more) | ua: Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/), Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot), Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0 (+6 more)
show less
Port Scan
Web App Attack
๐ซ๐ท
masterguru
2026-10-02 14:08:12
(6 days ago)
Too much 404 requests in 1 minute. Operator GE matched 10 at IP:block_script. (46020-193)
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-02 14:07:03
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.195.119.54 (54.119.195.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.119.54 (54.119.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:06:59.606423 2026] [security2:error] [pid 11732:tid 11732] [client 35.195.119.54:36802] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "xirin.net"] [uri "/css../.env"] [unique_id "ar-6gyld9UMIdakSNpnGMQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Tamsy
2026-10-02 14:05:25
(6 days ago)
HTTPD - 4xx scan
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-02 13:46:04
(6 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-02 13:42:18
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.195.119.54 (54.119.195.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.119.54 (54.119.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:42:10.774069 2026] [security2:error] [pid 5494:tid 5494] [client 35.195.119.54:54578] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "robotrodeo.net"] [uri "/.htpasswd"] [unique_id "ar-0sneZb5DmpJSqpN-NqAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:13:31
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.195.119.54 (54.119.195.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.119.54 (54.119.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:13:27.578972 2026] [security2:error] [pid 13776:tid 13776] [client 35.195.119.54:55634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.whysong.net"] [uri "/.htpasswd"] [unique_id "ar-t9wSm3H4xv4zt0nDUOQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
oja
2026-10-02 12:47:11
(6 days ago)
Aggressive web scanner
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 11:37:13
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.195.119.54 (54.119.195.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.119.54 (54.119.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:37:08.945579 2026] [security2:error] [pid 23208:tid 23208] [client 35.195.119.54:34114] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.royalchess.net"] [uri "/src/.env"] [unique_id "ar-XZDzQQlAfgcvAElWncQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
valornode
2026-10-02 11:25:35
(6 days ago)
Detected by CrowdSec on www.iambrayden.net-47d88224: CrowdSec: crowdsecurity/grafana-cve-2021-43798 ...
show more
Detected by CrowdSec on www.iambrayden.net-47d88224: CrowdSec: crowdsecurity/grafana-cve-2021-43798 | ASN: 396982 (GOOGLE-CLOUD-PLATFORM) | Country: BE | Range: 35.192.0.0/14
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-10-02 10:50:06
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.195.119.54 (54.119.195.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.119.54 (54.119.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 06:49:58.839499 2026] [security2:error] [pid 7790:tid 7790] [client 35.195.119.54:49914] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "valuechains4poor.net"] [uri "/static../.env"] [unique_id "ar-MViFQQ915QyX1CBaGMQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
pscriptos
2026-10-02 10:22:59
(6 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking