Anonymous
2026-09-22 01:55:04
(1 day ago)
Multiple pen test attempts.
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-21 23:05:47
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 23:05:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.195.9.254 (254.9.195.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.9.254 (254.9.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:05:19.120352 2026] [security2:error] [pid 1831:tid 1831] [client 35.195.9.254:37264] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "adampayments.com"] [uri "/.env.example"] [unique_id "arG4L_aDVXmyHihXRvmXmAAAAGQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-09-21 22:17:53
(1 day ago)
Malicious activity from IP detected: crowdsecurity/thinkphp-cve-2018-20062.
Web App Attack
Hacking
๐ธ๐ช
vaia.cloud
2026-09-21 22:10:01
(1 day ago)
crowdsecurity/http-cve-2021-41773
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:22:27
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.195.9.254 (254.9.195.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.9.254 (254.9.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:22:19.076016 2026] [security2:error] [pid 6975:tid 7150] [client 35.195.9.254:33388] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.sailcleaner.com"] [uri "/server/.env"] [unique_id "arGD62XN0yRc26kAdtCGVwAAAkM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 18:30:52
(1 day ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-09-21 15:30:48
(2 days ago)
{"level":"info","ts":1790004647.016131,"logger":"http.log.access.log1","msg":"handled request","requ ...
show more
{"level":"info","ts":1790004647.016131,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.195.9.254","remote_port":"56910","client_ip":"35.195.9.254","proto":"HTTP/2.0","method":"GET","host":"status.narscosmetics.com","uri":"/assets/.env","headers":{"Cookie":["REDACTED"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"Accept-Encoding":["gzip"],"User-Agent":["Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"],"Accept":["*/*"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.narscosmetics.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000158373,"size":0,"status":429,"resp_headers":{"Retry-After":["1"],"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"]}}
{"level":"info","ts":1790004647.0177336,"logger":"http.log.access.lo
...
show less
DDoS Attack
Web App Attack
๐ฉ๐ช
maxpower
2026-09-21 15:29:13
(2 days ago)
(junkbot) REGOLA 8 - Junk Bot Blocked 35.195.9.254 (BE/Belgium/254.9.195.35.bc.googleusercontent.com ...
show more
(junkbot) REGOLA 8 - Junk Bot Blocked 35.195.9.254 (BE/Belgium/254.9.195.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.195.9.254 - - [21/Sep/2026:17:29:10 +0200] "GET /z9x8c7v6b5-debug-trigger-mail.s2servizi.com HTTP/2.0" 200 12125 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "-" host=mail.s2servizi.com
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-21 15:17:22
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.195.9.254 (254.9.195.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.9.254 (254.9.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:17:15.607131 2026] [security2:error] [pid 9041:tid 9041] [client 35.195.9.254:57766] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.salazartransfers.com"] [uri "/@fs/.env"] [unique_id "arFKe0nNZLyGbFMAVzzSKQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-09-21 15:01:05
(2 days ago)
Malicious activity from IP detected: crowdsecurity/http-probing.
Web App Attack
Hacking
๐ซ๐ท
COMAITE
2026-09-21 14:55:59
(2 days ago)
Suspicious URL access.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:55:45
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.195.9.254 (254.9.195.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.9.254 (254.9.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:55:38.909650 2026] [security2:error] [pid 26545:tid 26545] [client 35.195.9.254:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.marshallcurry.com"] [uri "/css../.env"] [unique_id "arFFaiPnZGlOOzXqJ4GlRAAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 14:32:55
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-09-21 14:30:08
(2 days ago)
Bad bot identified by user agent
Bad Web Bot