πΊπΈ
[email protected]
2026-10-02 10:34:58
(18 hours ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 72h0m0s)
Port Scan
π³π±
Savvii
2026-10-01 13:58:26
(1 day ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 13:46:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.198.53.150 (150.53.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.53.150 (150.53.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:46:03.282434 2026] [security2:error] [pid 10478:tid 10478] [client 35.198.53.150:40436] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globalpackets.net"] [uri "/.htpasswd"] [unique_id "ar5kG26UP0_MCnhpI2U_fAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-10-01 13:44:26
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.198.53.150 (BR/Brazil/150.53.198.3 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.198.53.150 (BR/Brazil/150.53.198.35.bc.googleusercontent.com): 1 in the last 3600 secs (0-195)
show less
Hacking
π©πͺ
Bedios GmbH
2026-10-01 13:38:37
(1 day ago)
Login credentials theft attempt
Hacking
πͺπΈ
pipeline.es
2026-10-01 12:41:35
(1 day ago)
Web scanning / probing for vulnerable paths | URL: /.env.old | Evidence: microsites.grupoeuropa.com ...
show more
Web scanning / probing for vulnerable paths | URL: /.env.old | Evidence: microsites.grupoeuropa.com 35.198.53.150 - - [01/Oct/2026:14:40:10 +0200] \"GET /.env.old HTTP/1.1\" 403 210 \"-\" \"Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email])\" GEOIP_COUNTRY_CODE=BR | ASN: GOOGLE-CLOUD-PLATFORM | Country: BR
show less
Port Scan
Web App Attack
π«π·
masterguru
2026-10-01 12:35:42
(1 day ago)
Restricted File Access Attempt. Matched phrase "compose.yml" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack
π©πͺ
Gwyneth Llewelyn
2026-10-01 12:29:28
(1 day ago)
2026/10/01 13:29:25 [error] 3532286#3532286: *1942802 access forbidden by rule, client: 35.198.53.15 ...
show more
2026/10/01 13:29:25 [error] 3532286#3532286: *1942802 access forbidden by rule, client: 35.198.53.150, server: gwynethllewelyn.net, request: "GET /admin%2F.env HTTP/2.0", host: "gwynethllewelyn.net"
2026/10/01 13:29:26 [error] 3532286#3532286: *1942824 access forbidden by rule, client: 35.198.53.150, server: gwynethllewelyn.net, request: "GET /dashboard%2F.env HTTP/2.0", host: "gwynethllewelyn.net"
2026/10/01 13:29:26 [error] 3532286#3532286: *1942826 access forbidden by rule, client: 35.198.53.150, server: gwynethllewelyn.net, request: "GET /settings%2F.env HTTP/2.0", host: "gwynethllewelyn.net"
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 12:23:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.198.53.150 (150.53.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.53.150 (150.53.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:23:10.471528 2026] [security2:error] [pid 949:tid 949] [client 35.198.53.150:40052] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.gizmolabs.net"] [uri "/css../.env"] [unique_id "ar5QrkfZ5Dp5MNEons0ZTwAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
dot.mg
2026-10-01 12:19:02
(1 day ago)
Bad behaviour
Web Spam
Anonymous
2026-10-01 12:09:46
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
π¬π§
noise.agency
2026-10-01 12:03:38
(1 day ago)
35.198.53.150 (BR/Brazil/150.53.198.35.bc.googleusercontent.com), more than 10 Apache 403 hits
Hacking
π«π·
masterguru
2026-10-01 12:02:20
(1 day ago)
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.198.53.150 (BR/Brazil/150.53.198.3 ...
show more
(modsec_5080) ModSec 5080: Infrastructure subdomain probe from 35.198.53.150 (BR/Brazil/150.53.198.35.bc.googleusercontent.com): 2 in the last 3600 secs (0-196)
show less
Hacking
π«π·
dynamix
2026-10-01 11:44:24
(1 day ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
[email protected]
2026-10-01 11:39:18
(1 day ago)
CrowdSec ban: crowdsecurity/http-admin-interface-probing (duration: 71h59m55s)
Web App Attack