π©πͺ
big-cloud.nl
2026-09-30 14:36:10
(40 minutes ago)
Try to access /%2eenv
Web App Attack
π«π·
masterguru
2026-09-30 14:22:46
(53 minutes ago)
URL file extension is restricted by policy. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. (920440-131)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-09-30 14:02:03
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.199.77.246 (246.77.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.77.246 (246.77.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:01:59.285739 2026] [security2:error] [pid 7688:tid 7698] [client 35.199.77.246:36190] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.busybeerestaurant.com|F|2"] [data ".busybeerestaurant.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.busybeerestaurant.com"] [uri "/z9x8c7v6b5-debug-trigger-www.busybeerestaurant.com"] [unique_id "ar0WV7elAtFaQpwdQ63CWAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-09-30 13:45:42
(1 hour ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-30 13:19:30
(1 hour ago)
Aggressive web scan
Web App Attack
πΊπΈ
mnsf
2026-09-30 13:05:26
(2 hours ago)
Too many Status 40X (17)
Brute-Force
Web App Attack
Anonymous
2026-09-30 12:52:59
(2 hours ago)
Portscan: TCP/8443 (9x), TCP/8080 (9x)
Port Scan
Anonymous
2026-09-30 12:50:06
(2 hours ago)
| [Dangerous/Brazil] Aggressive IP 35.199.77.246 (~30 hits). Type: DoS Defender- Web server 400 erro ...
show more
| [Dangerous/Brazil] Aggressive IP 35.199.77.246 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
π¬π§
consul.to
2026-09-30 12:48:33
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
kosada.com
2026-09-30 12:39:42
(2 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /login (HTTP/1.1 port 443, user agen ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /login (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36")
show less
Web App Attack
πΊπΈ
robotstxt
2026-09-30 12:25:19
(2 hours ago)
35.199.77.246 - - [30/Sep/2026:12:24:26 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 36418 "https: ...
show more
35.199.77.246 - - [30/Sep/2026:12:24:26 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 36418 "https://www.blimburnseeds.com/.vite/manifest.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "35.199.77.246" edge="162.159.106.183"
35.199.77.246 - - [30/Sep/2026:12:24:26 +0000] "GET /.ssh/config HTTP/2.0" 403 36418 "https://www.blimburnseeds.com/.ssh/config" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "35.199.77.246" edge="104.22.10.218"
35.199.77.246 - - [30/Sep/2026:12:24:27 +0000] "GET /.zshrc HTTP/2.0" 403 2 "https://www.blimburnseeds.com/.zshrc" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "35.199.77.246" edge="104.22.10.218"
35.199.77.246 - - [30/Sep/2026:12:24:28 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/2.0" 403 36394 "https://www.blimburnseeds.com/@fs/..%252f..%252f..%252f..%252f..%252f
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 12:20:01
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.199.77.246 (246.77.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.77.246 (246.77.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:19:56.933160 2026] [security2:error] [pid 2168:tid 2168] [client 35.199.77.246:50874] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.buckinghambluesbar.com.buckinghambar.com|F|2"] [data ".buckinghambluesbar.com.buckinghambar.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.buckinghambluesbar.com.buckinghambar.com"] [uri "/z9x8c7v6b5-debug-trigger-www.buckinghambluesbar.com.buckinghambar.com"] [unique_id "arz-bJHnU1WVDy6XDhMbpgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Octopuce
2026-09-30 11:43:40
(3 hours ago)
Aggressive web search of vulnerable pages: /_nuxt/../.env /laravel/.env /storage/.env /wp/.env /api/ ...
show more
Aggressive web search of vulnerable pages: /_nuxt/../.env /laravel/.env /storage/.env /wp/.env /api/openapi.json ...
show less
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-09-30 11:32:29
(3 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
π³π±
Alt255
2026-09-30 11:01:14
(4 hours ago)
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-07al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.199.77.246 - - [30/Sep/2026:13:00:56 +0200] "GET /media../.env HTTP/1.1" 403 5787 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
...
show less
Bad Web Bot
Web App Attack