π¦πΊ
2000cn.com.au
2026-09-24 00:12:49
(7 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
πΊπΈ
interbiznw.com
2026-09-24 00:11:42
(8 minutes ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
π³π±
Savvii
2026-09-23 23:49:12
(30 minutes ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-23 23:35:08
(44 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.200.57.171 (171.57.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.57.171 (171.57.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 19:35:00.958824 2026] [security2:error] [pid 8791:tid 8791] [client 35.200.57.171:56898] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bostonlog.com"] [uri "/.htpasswd"] [unique_id "arRiJJhykgdLNP1YnPSOGwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 23:28:11
(51 minutes ago)
Web application attack detected.
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-23 23:18:20
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.200.57.171 (171.57.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.200.57.171 (171.57.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 19:18:16.892140 2026] [security2:error] [pid 24146:tid 24146] [client 35.200.57.171:58416] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bouldercorporate.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bouldercorporate.com"] [uri "/z9x8c7v6b5-debug-trigger-bouldercorporate.com"] [unique_id "arReOB3fEd9HjQ4SIoIWogAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2026-09-23 23:10:26
(1 hour ago)
4.880 requests from abuseipdb.com blacklisted IP (2mos1w6d)
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-23 22:55:17
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.200.57.171 (171.57.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.200.57.171 (171.57.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 18:55:09.981446 2026] [security2:error] [pid 19148:tid 19148] [client 35.200.57.171:45490] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||boxfactorylofts.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "boxfactorylofts.com"] [uri "/z9x8c7v6b5-debug-trigger-boxfactorylofts.com"] [unique_id "arRYzdGnKVAHBjWDoRNsmAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
sc user
2026-09-23 22:46:06
(1 hour ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
π«π·
Stara
2026-09-23 22:32:55
(1 hour ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
π©πͺ
TheDjRider
2026-09-23 22:18:09
(2 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-23T22:18:06.819096878Z. Context: http_status=200
show less
Web App Attack
πΊπΈ
Penny Packer
2026-09-23 22:15:29
(2 hours ago)
Fail2Ban apache-tripwires
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-23 22:15:09
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.200.57.171 (171.57.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.200.57.171 (171.57.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 18:15:01.886691 2026] [security2:error] [pid 10067:tid 10067] [client 35.200.57.171:37624] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||braintechsoftwaresolutions.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "braintechsoftwaresolutions.com"] [uri "/z9x8c7v6b5-debug-trigger-braintechsoftwaresolutions.com"] [unique_id "arRPZRLctti9ylCH3k1LTAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 22:08:45
(2 hours ago)
git/env leak probe
Web App Attack
Anonymous
2026-09-23 21:49:50
(2 hours ago)
35.200.57.171 - - [23/Sep/2026:23:49:48 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; ...
show more
35.200.57.171 - - [23/Sep/2026:23:49:48 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.200.57.171 - - [23/Sep/2026:23:49:49 +0200] "GET /z9x8c7v6b5-debug-trigger-brasfox.com HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
35.200.57.171 - - [23/Sep/2026:23:49:49 +0200] "GET /signin HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.200.57.171 - - [23/Sep/2026:23:49:49 +0200] "GET /users/login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.200.57.171 - - [23/Sep/2026:23:49:49 +0200] "GET /auth/login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.200.57.1
...
show less
Bad Web Bot
Web App Attack