π·π΄
iulianh
2026-09-18 06:36:58
(2 hours ago)
80,443
Brute-Force
SSH
π©πͺ
4server
2026-09-18 05:28:04
(3 hours ago)
[FriSep1807:27:59.5168312026][security2:error][pid3150818:tid3150834][client35.197.252.161:0]ModSecu ...
show more
[FriSep1807:27:59.5168312026][security2:error][pid3150818:tid3150834][client35.197.252.161:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(\?:/\(\?:\^\|/\)\\\\\\\\.\(env\|git\|svn\|hg\|DS_Store\)\|/\(\?:wp-config\|\\\\\\\\.htaccess\|\\\\\\\\.htpasswd\)\|\\\\\\\\.\(\?:sql\|bak\|old\|log\)\$\)\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"156\"][id\"960720\"][msg\"Forbiddenfileaccessattempt\"][severity\"CRITICAL\"][hostname\"www.cxservices.ch.136-243-54-122.cpanel.site\"][uri\"/.env.bak\"][unique_id\"aqzL3_ZP-85EBw3cFyz5HwAAAAI\"]
show less
Port Scan
Brute-Force
Web App Attack
πΊπΈ
cwytech
2026-09-18 03:26:30
(5 hours ago)
Fleet-wide ban from the Ghostfleet π». Triggered by scenario: cwy/http-honeypath-sniper-crit.
Bad Web Bot
Web App Attack
π¦πΊ
2000cn.com.au
2026-09-18 03:18:37
(6 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
π³π±
Site.eu
2026-09-17 22:16:58
(11 hours ago)
Excessive 404/403 errors
Brute-Force
π©πͺ
IVski.com
2026-09-17 21:41:48
(11 hours ago)
IVski WAF | Automated IoT/router reconnaissance scan.
Hacking
Brute-Force
Web App Attack
π©πͺ
lolyay
2026-09-17 20:35:38
(12 hours ago)
35.197.252.161 - - [17/Sep/2026:20:35:37 +0000] "GET /.git/config HTTP/1.1" 200 4 "-" "Mozilla/5.0 ( ...
show more
35.197.252.161 - - [17/Sep/2026:20:35:37 +0000] "GET /.git/config HTTP/1.1" 200 4 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.197.252.161 - - [17/Sep/2026:20:35:37 +0000] "GET /.env HTTP/1.1" 200 4 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
Bad Web Bot
π©πͺ
webanyone
2026-09-17 19:17:45
(14 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
Anonymous
2026-09-17 17:12:17
(16 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: GB, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: GB, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-09-17 17:01:12
(16 hours ago)
Excessive multi-domain requests
Brute-Force
πΊπΈ
TPI-Abuse
2026-09-17 14:29:46
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.197.252.161 (161.252.197.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.197.252.161 (161.252.197.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 10:29:41.208591 2026] [security2:error] [pid 23615:tid 23615] [client 35.197.252.161:43566] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.curts.net.greighhouse.com"] [uri "/.git/config"] [unique_id "aqv5VdzzVisaLwb33nRYYwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 13:26:37
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.197.252.161 (161.252.197.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.197.252.161 (161.252.197.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 09:26:29.664066 2026] [security2:error] [pid 16054:tid 16054] [client 35.197.252.161:41356] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.cursos.logosformacion.net"] [uri "/.git/config"] [unique_id "aqvqhZiajThzyNDxQeKCTwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πͺπΈ
robotstxt
2026-09-17 12:44:21
(20 hours ago)
35.197.252.161 - - [17/Sep/2026:12:43:53 +0000] "POST / HTTP/1.1" 403 19369 "-" "Mozilla/5.0 (Macint ...
show more
35.197.252.161 - - [17/Sep/2026:12:43:53 +0000] "POST / HTTP/1.1" 403 19369 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.197.252.161"
35.197.252.161 - - [17/Sep/2026:12:43:54 +0000] "POST / HTTP/1.1" 403 19369 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.197.252.161"
35.197.252.161 - - [17/Sep/2026:12:43:54 +0000] "GET /.git/config HTTP/1.1" 403 19114 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.197.252.161"
35.197.252.161 - - [17/Sep/2026:12:43:55 +0000] "GET /.env HTTP/1.1" 403 19112 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.197.252.161"
35.197.252.161 - - [17/Sep/2026:12:43:55 +0000] "GET /.env.local HTTP/1.1" 403 1911
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 12:04:48
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.197.252.161 (161.252.197.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.197.252.161 (161.252.197.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 08:04:44.146790 2026] [security2:error] [pid 27650:tid 27650] [client 35.197.252.161:37446] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.curriculum-web.com.creartest.com"] [uri "/.git/config"] [unique_id "aqvXXGSAgKr8vnFKwT71_wAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-09-17 10:56:29
(22 hours ago)
Restricted File Access Attempt. Matched phrase ".git/" at REQUEST_FILENAME. (930130-201)
Hacking
Web App Attack