๐บ๐ธ
thieuleu
2026-10-03 02:42:00
(16 hours ago)
Unauthorized connection attempt blocked by firewall policy. Web application hardening active.
Brute-Force
Exploited Host
๐ฉ๐ช
Fahreddin Ergin
2026-10-03 00:58:49
(18 hours ago)
2026-10-02 17:07:48,798 fail2ban.actions [579]: NOTICE [traefik-flood] Ban 35.195.177.5
2026 ...
show more
2026-10-02 17:07:48,798 fail2ban.actions [579]: NOTICE [traefik-flood] Ban 35.195.177.5
2026-10-02 17:07:52,770 fail2ban.actions [579]: NOTICE [traefik-botscan] Ban 35.195.177.5
2026-10-03 00:58:48,962 fail2ban.actions [579]: NOTICE [traefik-flood] Ban 35.195.177.5
...
show less
Brute-Force
SSH
๐ช๐ธ
robotstxt
2026-10-02 21:02:08
(21 hours ago)
35.195.177.5 - - [02/Oct/2026:21:01:47 +0000] "GET /.env.example HTTP/2.0" 403 16246 "https://studio ...
show more
35.195.177.5 - - [02/Oct/2026:21:01:47 +0000] "GET /.env.example HTTP/2.0" 403 16246 "https://studio.temporada-alta.com/.env.example" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
35.195.177.5 - - [02/Oct/2026:21:01:47 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/2.0" 403 16267 "https://studio.temporada-alta.com/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw??" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
35.195.177.5 - - [02/Oct/2026:21:01:48 +0000] "GET /.env.production HTTP/2.0" 403 16248 "https://studio.temporada-alta.com/.env.production" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
35.195.177.5 - - [02/Oct/2026:21:01:48 +0000] "GET /.env.local HTTP/2.0" 403 16246 "https://studio.temporada-alta.com/.env.local" "Mozilla/5.0 (compatible; Bytespider; spider-feedback
...
show less
Web App Attack
๐ฉ๐ช
33three
2026-10-02 18:27:38
(1 day ago)
Fail2Ban jail WebAttack triggered
Brute-Force
๐ช๐ธ
robotstxt
2026-10-02 16:41:31
(1 day ago)
35.195.177.5 - - [02/Oct/2026:16:40:36 +0000] "GET /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+% ...
show more
35.195.177.5 - - [02/Oct/2026:16:40:36 +0000] "GET /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 404 16291 "https://web.temporada-alta.com/cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
35.195.177.5 - - [02/Oct/2026:16:40:37 +0000] "GET /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 404 16285 "https://web.temporada-alta.com/cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
35.195.177.5 - - [02/Oct/2026:16:40:38 +0000] "GET /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/2.0" 404 16286 "https://web.temporada-alta.com/cgi-bin/php-cgi?-d+allow_url_include%3don+-d+a
...
show less
Bad Web Bot
๐ง๐ช
boxed-it
2026-10-02 16:13:00
(1 day ago)
GET /config/prod.exs (Tarpitted for 32m46s, wasted 115.31kB)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 15:50:46
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.195.177.5 (5.177.195.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.177.5 (5.177.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:50:39.752240 2026] [security2:error] [pid 19076:tid 19076] [client 35.195.177.5:41246] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.thesowersfamily.com"] [uri "/.htpasswd"] [unique_id "ar_SzxdJefIeX6rvt0N0dgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-02 14:45:11
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐ช๐ธ
robotstxt
2026-10-02 14:04:37
(1 day ago)
35.195.177.5 - - [02/Oct/2026:14:04:30 +0000] "GET /images../.env HTTP/2.0" 403 16246 "https://sales ...
show more
35.195.177.5 - - [02/Oct/2026:14:04:30 +0000] "GET /images../.env HTTP/2.0" 403 16246 "https://sales.temporada-alta.com/images../.env" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
35.195.177.5 - - [02/Oct/2026:14:04:30 +0000] "GET /build../.env HTTP/2.0" 403 16247 "https://sales.temporada-alta.com/build../.env" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
35.195.177.5 - - [02/Oct/2026:14:04:31 +0000] "GET /dist../.env HTTP/2.0" 403 16241 "https://sales.temporada-alta.com/dist../.env" "CCBot/2.0 (https://commoncrawl.org/faq/)"
35.195.177.5 - - [02/Oct/2026:14:04:31 +0000] "GET /assets../.env HTTP/2.0" 403 16242 "https://sales.temporada-alta.com/assets../.env" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
35.195.177.5 - - [02/Oct/2026:14:04:31 +0000] "GET /public../.env HTTP/
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 13:50:48
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.195.177.5 (5.177.195.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.177.5 (5.177.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 09:50:40.385248 2026] [security2:error] [pid 17726:tid 17726] [client 35.195.177.5:40452] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.shahngalu.com"] [uri "/.env"] [unique_id "ar-2sF9kZQ7VHBQMliVbGwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
masterguru
2026-10-02 13:49:10
(1 day ago)
BAD BOT - Detected and Blocked.. Matched phrase "ChatGPT-User" at REQUEST_HEADERS:user-agent. (11000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "ChatGPT-User" at REQUEST_HEADERS:user-agent. (1100000-169)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 12:56:39
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.195.177.5 (5.177.195.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.195.177.5 (5.177.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:56:33.500873 2026] [security2:error] [pid 9496:tid 9496] [client 35.195.177.5:58976] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stablechase.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stablechase.com"] [uri "/z9x8c7v6b5-debug-trigger-stablechase.com"] [unique_id "ar-qAUw3TAGrWeYM-wBfjgAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-10-02 12:26:58
(1 day ago)
35.195.177.5 - - [02/Oct/2026:11:20:10 +0000] "GET /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto ...
show more
35.195.177.5 - - [02/Oct/2026:11:20:10 +0000] "GET /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 404 16283 "https://invoice.temporada-alta.com/cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
35.195.177.5 - - [02/Oct/2026:11:20:11 +0000] "GET /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/2.0" 404 16283 "https://invoice.temporada-alta.com/cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input" "CCBot/2.0 (https://commoncrawl.org/faq/)"
35.195.177.5 - - [02/Oct/2026:11:20:12 +0000] "GET /cgi-bin/php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/2.0" 404 16281 "https://invoice.temporada-alta.com/cgi-bin/php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, lik
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 12:14:45
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.195.177.5 (5.177.195.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.195.177.5 (5.177.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:14:38.091838 2026] [security2:error] [pid 24468:tid 24468] [client 35.195.177.5:52428] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.troop9weymouth.com|F|2"] [data ".troop9weymouth.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.troop9weymouth.com"] [uri "/z9x8c7v6b5-debug-trigger-www.troop9weymouth.com"] [unique_id "ar-gLrrO06GLSw_MHebAmQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 11:58:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.195.177.5 (5.177.195.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.177.5 (5.177.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:58:22.817706 2026] [security2:error] [pid 1992:tid 1992] [client 35.195.177.5:43966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.solcargomiami.com"] [uri "/web.config"] [unique_id "ar-cXkKKjA_Ydl1wPxTAmQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack