π³π±
WeCloudit-Anti-Abuse
2026-09-03 22:45:25
(2 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
π¦πΊ
screwlooseit.com.au
2026-09-03 22:17:19
(30 minutes ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
103.97.200.35.bc.googleusercontent.com
Web App Attack
Anonymous
2026-09-03 22:04:40
(43 minutes ago)
Aggressive web scan
Web App Attack
π¨π
4server
2026-09-03 21:35:02
(1 hour ago)
[ThuSep0323:34:56.4876792026][security2:error][pid1816583:tid1816888][client35.200.97.103:0]ModSecur ...
show more
[ThuSep0323:34:56.4876792026][security2:error][pid1816583:tid1816888][client35.200.97.103:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Matchedphrase\".env\"atREQUEST_URI.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"610\"][id\"960720\"][msg\"Forbiddenfileaccess\"][hostname\"www.cybertelgroup.com\"][uri\"/@fs/app/.env\"][unique_id\"apnoAJqzeoHtgC1SYVgElgAAAUY\"]
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 21:26:37
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.200.97.103 (103.97.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.97.103 (103.97.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:26:32.126803 2026] [security2:error] [pid 19210:tid 19210] [client 35.200.97.103:57232] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.copierscharlotte.com"] [uri "/@fs/.env"] [unique_id "apnmCALt5leW8fAPRFEr7gAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-09-03 21:23:52
(1 hour ago)
Excessive multi-domain requests
Brute-Force
π«π·
Zundapper
2026-09-03 21:08:48
(1 hour ago)
35.200.97.103 - - [03/Sep/2026:23:08:42 +0200] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 404 117 " ...
show more
35.200.97.103 - - [03/Sep/2026:23:08:42 +0200] "GET /@fs/proc/self/environ?raw?? HTTP/1.1" 404 117 "https://www.cnc-step.it/@fs/proc/self/environ?raw??" "Mozilla/5.0 (compatible; TelegramBot/1.0)"
35.200.97.103 - - [03/Sep/2026:23:08:42 +0200] "GET /@fs/root/rootkey.csv?raw?? HTTP/1.1" 404 117 "https://www.cnc-step.it/@fs/root/rootkey.csv?raw??" "Mozilla/5.0 (compatible; OAI-SearchBot/1.4; robots.txt; +https://openai.com/searchbot)"
35.200.97.103 - - [03/Sep/2026:23:08:42 +0200] "GET /@fs/etc/passwd?raw?? HTTP/1.1" 404 178 "https://www.cnc-step.it/@fs/etc/passwd?raw??" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.2743.146 Safari/537.36; compatible; GrokBot/1.0; +https://x.ai/grokbot"
35.200.97.103 - - [03/Sep/2026:23:08:42 +0200] "GET /@fs/app/rootkey.csv?raw?? HTTP/1.1" 404 178 "https://www.cnc-step.it/@fs/app/rootkey.csv?raw??" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_4 like Mac OS X) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.
...
show less
Web App Attack
Port Scan
π§πΎ
lns.bz
2026-09-03 21:07:34
(1 hour ago)
Too many 404 requests [BY]
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 19:47:54
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.97.103 (103.97.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.97.103 (103.97.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 15:47:47.677050 2026] [security2:error] [pid 1591161:tid 1591199] [client 35.200.97.103:20992] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.frmoto.com"] [uri "/@fs/.env"] [unique_id "apnO4y9AW-EQ-tMLAGvmJQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 18:54:28
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.97.103 (103.97.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.97.103 (103.97.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 14:54:20.032352 2026] [security2:error] [pid 11405:tid 11434] [client 35.200.97.103:36750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "conservativedemocrat.com"] [uri "/@fs/.env"] [unique_id "apnCXP4vOTAZSDYUl_yKgQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅π±
TaKeN
2026-09-03 18:54:16
(3 hours ago)
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application pr ...
show more
Automated Wazuh local observation. Wazuh rule 31151 lvl=10 detected repeated HTTP web application probing from this source IP. Observed 4 matching blocked event(s) between 2026-09-03T20:54:16+02:00 and 2026-09-03T20:54:16+02:00. Sample requested paths: /@fs/.env.development, /@fs/home/debian/.aws/credentials, /@fs/root/rootkey.csv, /@fs/root/.aws/credentials.bak.
show less
Web App Attack
Hacking
Anonymous
2026-09-03 18:28:27
(4 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-03 17:59:48
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.200.97.103 (103.97.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.97.103 (103.97.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 13:59:43.508087 2026] [security2:error] [pid 17073:tid 17073] [client 35.200.97.103:16072] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.xtremeautodetailing.com"] [uri "/@fs/app/.env"] [unique_id "apm1j5302NTSrHUATLzMfgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Octopuce
2026-09-03 17:44:42
(5 hours ago)
Aggressive web search of vulnerable pages: /backend/.env /img../.env /admin/.env /v2/.env /uploads.. ...
show more
Aggressive web search of vulnerable pages: /backend/.env /img../.env /admin/.env /v2/.env /uploads../.env ...
show less
Web App Attack
Anonymous
2026-09-03 17:39:41
(5 hours ago)
2026/09/03 17:39:40 [error] 3174955#3174955: *170152 [client 35.200.97.103] ModSecurity: Access deni ...
show more
2026/09/03 17:39:40 [error] 3174955#3174955: *170152 [client 35.200.97.103] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "agentcom.ingeltechgh.com"] [uri "/@fs/etc/passwd"] [unique_id "178845718094.936330"] [ref ""], client: 35.200.97.103, server: srv.ingeltechgh.com, request: "GET /@fs/etc/passwd?raw?? HTTP/1.1", host: "agentcom.ingeltechgh.com"
2026/09/03 17:39:40 [error] 3174953#3174953: *170156 [client 35.200.97.103] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE'
...
show less
Brute-Force