๐บ๐ธ
[email protected]
2026-09-21 16:48:42
(1 week ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 71h59m58s)
Port Scan
๐บ๐ธ
ArturShelby
2026-09-21 05:53:57
(1 week ago)
Critical file access: /admin/login
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-09-21 05:31:05
(1 week ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.199.148 ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.199.148.92 (US/United States/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 35.199.148.92 (US/United States/92.148.199.35.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
Anonymous
2026-09-21 05:29:20
(1 week ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:59:58
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.199.148.92 (92.148.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.148.92 (92.148.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:59:50.734574 2026] [security2:error] [pid 7641:tid 7641] [client 35.199.148.92:54782] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.pelletisimo.com"] [uri "/@fs/app/.env"] [unique_id "arC5xlt5qozX98Cddz_1MQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-21 04:20:03
(1 week ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-09-21 02:05:34
(1 week ago)
Too many Status 40X (16)
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 01:18:11
(1 week ago)
20 attempts against mh_ha-misbehave-ban on guava
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-21 00:46:30
(1 week ago)
Restricted File Access Attempt. Matched phrase ".gitconfig" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-21 00:15:02
(1 week ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
Anonymous
2026-09-21 00:05:24
(1 week ago)
35.199.148.92 - - [21/Sep/2026:00:05:23 +0000] "GET /host.key HTTP/2.0" 404 16594 "-" "Mozilla/5.0 A ...
show more
35.199.148.92 - - [21/Sep/2026:00:05:23 +0000] "GET /host.key HTTP/2.0" 404 16594 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
35.199.148.92 - - [21/Sep/2026:00:05:23 +0000] "GET /rclone.conf HTTP/2.0" 404 16596 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
35.199.148.92 - - [21/Sep/2026:00:05:23 +0000] "GET /ssl/localhost.key HTTP/2.0" 404 16596 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
35.199.148.92 - - [21/Sep/2026:00:05:23 +0000] "GET /.bashrc HTTP/2.0" 404 16596 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
35.199.148.92 - - [21/Sep/2026:00:05:23 +0000] "GET /z9x8c7v6b5-debug-trigger-pensagarden.com HTTP/2.0" 404 16596 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-20 23:19:20
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.199.148.92 (92.148.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.148.92 (92.148.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 19:19:15.185825 2026] [security2:error] [pid 11172:tid 11267] [client 35.199.148.92:51354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.peluqueriabuhos.com"] [uri "/.git/config"] [unique_id "arBp82nxut6BaHBc-W7XiAAAAQ4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-20 22:58:43
(1 week ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
dalslab ltd
2026-09-20 22:36:58
(1 week ago)
[21/Sep/2026:00:36:57 +0200] - 404 404 - GET https git.dalslab.com "/.github/workflows/deploy.yml" [ ...
show more
[21/Sep/2026:00:36:57 +0200] - 404 404 - GET https git.dalslab.com "/.github/workflows/deploy.yml" [Client 35.199.148.92] [Length 11] [Gzip -] [Sent-to 10.1.1.40] "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "-"
[21/Sep/2026:00:36:57 +0200] - 404 404 - GET https git.dalslab.com "/api/.env" [Client 35.199.148.92] [Length 11] [Gzip -] [Sent-to 10.1.1.40] "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "-"
[21/Sep/2026:00:36:57 +0200] - 404 404 - GET https git.dalslab.com "/api/v2/config" [Client 35.199.148.92] [Length 11] [Gzip -] [Sent-to 10.1.1.40] "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" "-"
[21/Sep/2026:00:36:57 +0200] - 404 404 - GET https git.dalslab.com "/__/firebase/init.json" [Client 35.199.148.92] [Length 11] [Gzip -] [Sent-to 10.1.1.40] "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)" "-"
[21/Sep/2026:00:36:57 +0200] - 404 404 - GET https git.dalslab.com "/z
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:24:05
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.199.148.92 (92.148.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.148.92 (92.148.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:23:58.775272 2026] [security2:error] [pid 30209:tid 30209] [client 35.199.148.92:35348] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pcmec.com"] [uri "/.env"] [unique_id "arBc_u6a2YGcGn_9y4hqiwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack