🇫🇷
masterguru
2026-09-13 00:01:05
(13 minutes ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-195)
show less
Hacking
🇫🇷
COMAITE
2026-09-12 23:25:26
(48 minutes ago)
Suspicious URL access.
Web App Attack
🇬🇷
setupgr
2026-09-12 23:08:37
(1 hour ago)
(mod_security) mod_security (id:11000010) triggered by 35.196.112.62 (US/United States/South Carolin ...
show more
(mod_security) mod_security (id:11000010) triggered by 35.196.112.62 (US/United States/South Carolina/North Charleston/-/[AS396982 Google LLC]): 1 in the last 86400 secs (CF_ENABLE); Ports: *; Direction: inout; Trigger: LF_MODSEC; Logs: [Sun Sep 13 02:08:35.198969 2026] [security2:error] [pid 2849:tid 2898] [remote 35.196.112.62:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "PerplexityBot" at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec/modsec2.user.conf"] [line "114"] [id "11000010"] [msg "BLOCKED BOT: PerplexityBot on santoriniicon.com"] [severity "ALERT"] [hostname "santoriniicon.com"] [uri "/@fs/.env"] [unique_id "aqXbc3SirQ3ebmWobSgX7wACUQw"]
show less
Port Scan
🇩🇪
NetShield-DE
2026-09-12 23:07:34
(1 hour ago)
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb.
Events: 1. First: 2026-09-13T ...
show more
Auto-report via Fail2Ban aggregation. IP observed in jails: abuseipdb.
Events: 1. First: 2026-09-13T01:07:02+0200. Last: 2026-09-13T01:07:02+0200.
Samples:
- 2026-09-13 00:37:04,911 fail2ban.actions [4095059]: NOTICE [abuseipdb] Ban 35.196.112.62
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 22:47:06
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.196.112.62 (62.112.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.112.62 (62.112.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 18:47:02.616876 2026] [security2:error] [pid 29482:tid 29482] [client 35.196.112.62:42794] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "santagreetingcards.com"] [uri "/.git/HEAD"] [unique_id "aqXWZgdp9E6P23SkgwCa7gAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-12 22:45:02
(1 hour ago)
suspicious request in access.log
Web App Attack
🇧🇷
Halux
2026-09-12 22:19:40
(1 hour ago)
35.196.112.62 Probing protected path or service
Web App Attack
🇩🇪
FeG Deutschland
2026-09-12 22:16:18
(1 hour ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-12 21:59:40
(2 hours ago)
Auto-ban: >3000 req/min op 2026-09-12
Web App Attack
SSH
Hacking
🇩🇪
FD-IX
2026-09-12 21:55:06
(2 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
🇪🇸
pipeline.es
2026-09-12 21:45:36
(2 hours ago)
Web scanning / probing for vulnerable paths | URL: /.well-known/jwks.json | Evidence: sanfrasturismo ...
show more
Web scanning / probing for vulnerable paths | URL: /.well-known/jwks.json | Evidence: sanfrasturismo.com.br 35.196.112.62 - - [12/Sep/2026:23:44:37 +0200] \"GET /.well-known/jwks.json HTTP/2.0\" 404 20956 \"-\" \"Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 21:45:18
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.196.112.62 (62.112.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.196.112.62 (62.112.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 17:45:13.538853 2026] [security2:error] [pid 362:tid 362] [client 35.196.112.62:58740] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sangalgano.info|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sangalgano.info"] [uri "/rclone.conf"] [unique_id "aqXH6amZ3NPsmdiuJspL4QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-12 21:28:57
(2 hours ago)
cloudlinux2 fail2ban: 2026-09-12 23:23:44,973 fail2ban.filter [1606]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-12 23:23:44,973 fail2ban.filter [1606]: INFO [plesk-wordpress] Found 188.213.202.5 - 2026-09-12 23:23:44cloudlinux2 fail2ban: 2026-09-12 23:24:19,522 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 35.196.112.62 - 2026-09-12 23:24:19cloudlinux2 fail2ban: 2026-09-12 23:24:19,510 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 35.196.112.62 - 2026-09-12 23:24:19cloudlinux2 fail2ban: 2026-09-12 23:24:18,788 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 35.196.112.62 - 2026-09-12 23:24:18cloudlinux2 fail2ban: 2026-09-12 23:24:19,500 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 35.196.112.62 - 2026-09-12 23:24:19cloudlinux2 fail2ban: 2026-09-12 23:24:19,541 fail2ban.actions [1606]: NOTICE [plesk-modsecurity] Ban 35.196.112.62cloudlinux2 fail2ban: 2026-09-12 23:24:19,545 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 35.196.112.62 - 2026-09-12 23:24:19cloudlinux2 fail2ban:
show less
Web App Attack
🇳🇱
e.fierstra
2026-09-12 21:21:17
(2 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇺🇸
IndigoRidge
2026-09-12 21:20:49
(2 hours ago)
35.196.112.62 - - [12/Sep/2026:17:20:49 -0400] "GET /files../.env HTTP/1.1" 403 5495 "-" "Mozilla/5. ...
show more
35.196.112.62 - - [12/Sep/2026:17:20:49 -0400] "GET /files../.env HTTP/1.1" 403 5495 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
35.196.112.62 - - [12/Sep/2026:17:20:49 -0400] "GET /static//.env HTTP/1.1" 403 5495 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
35.196.112.62 - - [12/Sep/2026:17:20:49 -0400] "GET /media../.env HTTP/1.1" 403 5495 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
...
show less
Web App Attack