Anonymous
2026-09-14 13:09:11
(1 day ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Back ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Backup file probing, Cloud secrets probing, Directory traversal
show less
Bad Web Bot
Web App Attack
๐จ๐ญ
dalslab ltd
2026-09-14 07:49:34
(2 days ago)
2026/09/14 09:49:33 [error] 857#857: *1374520 limiting requests, excess: 200.260 by zone "rl_per_ip" ...
show more
2026/09/14 09:49:33 [error] 857#857: *1374520 limiting requests, excess: 200.260 by zone "rl_per_ip", client: 35.196.97.13, server: auth.dalslab.com, request: "GET /awsconfiguration.json HTTP/2.0", host: "auth.dalslab.com"
2026/09/14 09:49:33 [error] 857#857: *1374520 limiting requests, excess: 200.260 by zone "rl_per_ip", client: 35.196.97.13, server: auth.dalslab.com, request: "GET /amplify_outputs.json HTTP/2.0", host: "auth.dalslab.com"
2026/09/14 09:49:33 [error] 857#857: *1374520 limiting requests, excess: 200.540 by zone "rl_per_ip", client: 35.196.97.13, server: auth.dalslab.com, request: "GET /awsConfig.js HTTP/2.0", host: "auth.dalslab.com"
2026/09/14 09:49:33 [error] 857#857: *1374520 limiting requests, excess: 200.120 by zone "rl_per_ip", client: 35.196.97.13, server: auth.dalslab.com, request: "GET /__/firebase/init.json HTTP/2.0", host: "auth.dalslab.com"
2026/09/14 09:49:33 [error] 857#857: *1374520 limiting requests, excess: 200.050 by zone "rl_per_ip", client: 35.196.9
...
show less
Brute-Force
SSH
๐ฎ๐ณ
evicky2002
2026-09-14 06:00:01
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฌ๐ง
openstrike.co.uk
2026-09-14 05:14:03
(2 days ago)
167 attacks on VC URLs, config grabbing URLs (type 2), password/key grabbing URLs, env grabbing URLs ...
show more
167 attacks on VC URLs, config grabbing URLs (type 2), password/key grabbing URLs, env grabbing URLs (type 2), directory traversals, env grabbing URLs, PHP URLs:
GET /.git/HEAD HTTP/1.1
GET /src/amplifyconfiguration.json HTTP/1.1
GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/1.1
GET /_image?href=/proc/self/environ HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
GET /build../.env HTTP/1.1
GET /app_dev.php/_profiler HTTP/1.1
show less
Hacking
Web App Attack
๐บ๐ธ
wbsouza
2026-09-14 03:49:20
(2 days ago)
CrowdSec: crowdsecurity/http-path-traversal-probing โ automated firewall drops on self-hosted IDS se ...
show more
CrowdSec: crowdsecurity/http-path-traversal-probing โ automated firewall drops on self-hosted IDS sensor
show less
Hacking
๐บ๐ธ
[email protected]
2026-09-14 03:48:01
(2 days ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 71h59m51s)
Port Scan
๐บ๐ธ
NXTwoThou
2026-09-13 20:38:23
(2 days ago)
/api/health
Web App Attack
๐ง๐ฌ
HighWay
2026-09-13 18:06:07
(2 days ago)
35.196.97.13 - - [13/Sep/2026:18:06:02 +0000] "GET /wp-json HTTP/1.1" 404 770 "-" "Mozilla/5.0 (comp ...
show more
35.196.97.13 - - [13/Sep/2026:18:06:02 +0000] "GET /wp-json HTTP/1.1" 404 770 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
35.196.97.13 - - [13/Sep/2026:18:06:03 +0000] "GET /login HTTP/1.1" 404 770 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.196.97.13 - - [13/Sep/2026:18:06:03 +0000] "GET /auth/login HTTP/1.1" 404 770 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.196.97.13 - - [13/Sep/2026:18:06:03 +0000] "POST /graphql HTTP/1.1" 404 770 "https://vhelectronics.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.196.97.13 - - [13/Sep/2026:18:06:03 +0000] "GET /user/login HTTP/1.1" 404 770 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.196.97.13 - - [13/Sep/2026:18:0
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-13 17:59:04
(2 days ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
[email protected]
2026-09-13 17:58:02
(2 days ago)
CrowdSec ban: crowdsecurity/http-crawl-non_statics (duration: 71h59m58s)
Web App Attack
๐ณ๐ฑ
tmiland
2026-09-13 17:04:29
(2 days ago)
(nginx_444) Nginx 444 35.196.97.13 (US/United States/13.97.196.35.bc.googleusercontent.com): 5 in th ...
show more
(nginx_444) Nginx 444 35.196.97.13 (US/United States/13.97.196.35.bc.googleusercontent.com): 5 in the last 3600 secs; IP: 35.196.97.13; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.196.97.13 - - [13/Sep/2026:19:04:27 +0200] "GET /.aws/credentials HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" 35.196.97.13 - - [13/Sep/2026:19:04:27 +0200] "GET /.git/HEAD HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)" 35.196.97.13 - - [13/Sep/2026:19:04:27 +0200] "GET /.gitlab-ci.yml HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)" 35.196.97.13 - - [13/Sep/2026:19:04:28 +0200] "GET /.gitlab-ci.yml HTTP/1.1" 444 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)" 35.196.97.13 - - [13/Sep/2026:19:04:28 +0200] "GET
show less
Brute-Force
๐บ๐ธ
SketchyDude
2026-09-13 16:46:18
(2 days ago)
Banned by Fail2Ban jail: apache-fakegooglebot
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-13 16:14:30
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.196.97.13 (13.97.196.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.196.97.13 (13.97.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 12:14:26.940140 2026] [security2:error] [pid 15583:tid 15583] [client 35.196.97.13:46528] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pghsea.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pghsea.com"] [uri "/z9x8c7v6b5-debug-trigger-pghsea.com"] [unique_id "aqbL4lGC3R6R23lppvY3XgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-09-13 15:52:38
(2 days ago)
Login credentials theft attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-13 15:33:00
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.196.97.13 (13.97.196.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.196.97.13 (13.97.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 11:32:52.320486 2026] [security2:error] [pid 5467:tid 5484] [client 35.196.97.13:34832] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||petsentiments.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "petsentiments.com"] [uri "/z9x8c7v6b5-debug-trigger-petsentiments.com"] [unique_id "aqbCJJh7huCwG3bDrG7ZqwAAAUw"]
show less
Brute-Force
Bad Web Bot
Web App Attack