๐บ๐ธ
[email protected]
2026-09-21 16:46:32
(13 hours ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 71h59m57s)
Port Scan
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-21 06:15:11
(23 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Web App Attack
Bad Web Bot
Anonymous
2026-09-21 05:55:01
(1 day ago)
XSS Attempt
Hacking
๐ฉ๐ช
itsolon
2026-09-21 05:22:16
(1 day ago)
[21/Sep/2026:07:22:16 +0200] 178996813617.926597 35.196.190.219 43282 217.154.7.177 443
[21/Sep/2026 ...
show more
[21/Sep/2026:07:22:16 +0200] 178996813617.926597 35.196.190.219 43282 217.154.7.177 443
[21/Sep/2026:07:22:16 +0200] 178996813680.906865 35.196.190.219 43282 217.154.7.177 443
[21/Sep/2026:07:22:16 +0200] 17899681366.508865 35.196.190.219 43286 217.154.7.177 443
[21/Sep/2026:07:22:16 +0200] 178996813684.445900 35.196.190.219 43286 217.154.7.177 443
[21/Sep/2026:07:22:16 +0200] 178996813613.586908 35.196.190.219 43282 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
[email protected]
2026-09-21 02:13:22
(1 day ago)
CrowdSec ban: crowdsecurity/http-admin-interface-probing (duration: 71h59m54s)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:50:50
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.196.190.219 (219.190.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.190.219 (219.190.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:50:46.422108 2026] [security2:error] [pid 21893:tid 21893] [client 35.196.190.219:60316] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.ncsgroup96.com"] [uri "/.env.backup"] [unique_id "arB_ZpM6CGGtZ2KW3lgOkQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 23:23:02
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.196.190.219 (219.190.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.190.219 (219.190.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:22:58.643902 2026] [security2:error] [pid 27770:tid 27770] [client 35.196.190.219:48948] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.nedelam.com"] [uri "/@fs/app/.env"] [unique_id "arBq0plvPqh3305z-jyOoQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 23:06:35
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐จ๐ญ
dalslab ltd
2026-09-20 23:01:37
(1 day ago)
[21/Sep/2026:01:01:37 +0200] - 404 404 - GET https auth.dalslab.com "/.git/config" [Client 35.196.19 ...
show more
[21/Sep/2026:01:01:37 +0200] - 404 404 - GET https auth.dalslab.com "/.git/config" [Client 35.196.190.219] [Length 1601] [Gzip -] [Sent-to 10.1.1.240] "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" "-"
[21/Sep/2026:01:01:37 +0200] - 404 404 - GET https auth.dalslab.com "/.aws/config" [Client 35.196.190.219] [Length 1599] [Gzip -] [Sent-to 10.1.1.240] "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "-"
[21/Sep/2026:01:01:37 +0200] - 404 404 - GET https auth.dalslab.com "/.aws/credentials" [Client 35.196.190.219] [Length 1598] [Gzip -] [Sent-to 10.1.1.240] "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" "-"
[21/Sep/2026:01:01:37 +0200] - 404 404 - GET https auth.dalslab.com "/cms/.env" [Client 35.196.190.219] [Length 1599] [Gzip -] [Sent-to 10.1.1.240] "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" "-"
[21/Sep/2026:01:01:37 +0200] - 404 404 -
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-09-20 22:47:33
(1 day ago)
Suspicious URL access.
Web App Attack
๐บ๐ธ
TAY
2026-09-20 22:10:40
(1 day ago)
35.196.190.219 - - [21/Sep/2026:06:10:35 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 404 42794 "-" "Moz ...
show more
35.196.190.219 - - [21/Sep/2026:06:10:35 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 404 42794 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
35.196.190.219 - - [21/Sep/2026:06:10:36 +0800] "GET /_nuxt/../.env HTTP/1.1" 404 42794 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
35.196.190.219 - - [21/Sep/2026:06:10:38 +0800] "GET /static../.env HTTP/1.1" 404 42716 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
35.196.190.219 - - [21/Sep/2026:06:10:39 +0800] "GET /images../.env HTTP/1.1" 404 42716 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
35.196.190.219 - - [21/Sep/2026:06:10:39 +0800] "GET /assets../.env HTTP/1.1" 404 42716 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
35.196.190.219 - - [21/Sep/2026:06:10:38 +0800] "GET /media../.env HTTP/1.1" 404 42716 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://
...
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-20 21:54:37
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.196.190.219 (219.190.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.196.190.219 (219.190.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:54:32.482593 2026] [security2:error] [pid 30984:tid 30984] [client 35.196.190.219:49638] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nesetsv.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nesetsv.com"] [uri "/z9x8c7v6b5-debug-trigger-nesetsv.com"] [unique_id "arBWGEYHIhSPIUiMz8hkLwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 21:33:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.196.190.219 (219.190.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.190.219 (219.190.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:33:43.066407 2026] [security2:error] [pid 1084:tid 1084] [client 35.196.190.219:44332] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "banis-associates.com"] [uri "/.git/config"] [unique_id "arBRNyUqlthxNejBc2xz3AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 21:11:43
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
Anonymous
2026-09-20 20:38:58
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack