๐ฎ๐น
Progetto1
2026-10-07 06:30:07
(3 days ago)
Multiple exploit attempts
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
masterguru
2026-10-07 06:23:06
(3 days ago)
OS File Access Attempt. Matched phrase "proc/self/environ" at ARGS:0. (930120-164)
Hacking
๐ซ๐ท
phoenix1jl96
2026-10-07 04:41:14
(3 days ago)
2026/10/07 06:41:12 [error] 13476#13476: *97775 open() "/home/user-data/www/default/cgi-bin/php-cgi. ...
show more
2026/10/07 06:41:12 [error] 13476#13476: *97775 open() "/home/user-data/www/default/cgi-bin/php-cgi.exe" failed (2: No such file or directory), client: 35.201.134.129, server: box.ledemon.us, request: "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0", host: "livechat.ledemon.us"
2026/10/07 06:41:13 [error] 13476#13476: *97775 open() "/home/user-data/www/default/cgi-bin/php" failed (2: No such file or directory), client: 35.201.134.129, server: box.ledemon.us, request: "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0", host: "livechat.ledemon.us"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
๐บ๐ธ
masterguru
2026-10-07 02:02:52
(3 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "PerplexityBot" at REQUEST_HEADERS:User-Agent. (1100 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "PerplexityBot" at REQUEST_HEADERS:User-Agent. (1100000-163)
show less
Bad Web Bot
๐บ๐ธ
conrad10781
2026-10-07 00:23:49
(3 days ago)
nginx-4xx
Web App Attack
๐บ๐ธ
CBJ
2026-10-06 19:24:02
(4 days ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐ซ๐ท
phoenix1jl96
2026-10-06 12:08:59
(4 days ago)
2026/10/06 14:08:58 [error] 13476#13476: *64814 open() "/home/user-data/www/default/cgi-bin/php-cgi. ...
show more
2026/10/06 14:08:58 [error] 13476#13476: *64814 open() "/home/user-data/www/default/cgi-bin/php-cgi.exe" failed (2: No such file or directory), client: 35.201.134.129, server: box.ledemon.us, request: "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0", host: "2fa.ledemon.us"
2026/10/06 14:08:58 [error] 13476#13476: *64814 open() "/home/user-data/www/default/cgi-bin/php" failed (2: No such file or directory), client: 35.201.134.129, server: box.ledemon.us, request: "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0", host: "2fa.ledemon.us"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
๐ช๐ธ
masterguru
2026-10-06 12:02:31
(4 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:User-Agent. (1100000-122)
Bad Web Bot
๐บ๐ธ
masterguru
2026-10-06 11:07:20
(4 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "ChatGPT-User" at REQUEST_HEADERS:user-agent. (11000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "ChatGPT-User" at REQUEST_HEADERS:user-agent. (1100000-169)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-06 10:59:57
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.201.134.129 (129.134.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.134.129 (129.134.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:59:50.159057 2026] [security2:error] [pid 14417:tid 14417] [client 35.201.134.129:54636] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "plaisance.us"] [uri "/api/system/fileView"] [unique_id "asTUpi8NH7QxfLJOV2y4fwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-10-06 10:50:05
(4 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
SketchyDude
2026-10-06 10:48:47
(4 days ago)
Banned by Fail2Ban jail: apache-fakegooglebot
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-06 10:42:37
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.201.134.129 (129.134.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.134.129 (129.134.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:42:31.771038 2026] [security2:error] [pid 711:tid 711] [client 35.201.134.129:35014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "odessatexas.us"] [uri "/.htpasswd"] [unique_id "asTQl36IgZayLYwPz9xEtAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
netman
2026-10-06 10:28:27
(4 days ago)
35.201.134.129 netmanagement.us - [06/Oct/2026:10:28:12 +0000] "GET / HTTP/2.0" 200 257732 "-" "Mozi ...
show more
35.201.134.129 netmanagement.us - [06/Oct/2026:10:28:12 +0000] "GET / HTTP/2.0" 200 257732 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.201.134.129 netmanagement.us - [06/Oct/2026:10:28:13 +0000] "GET /szcmaj7ggylq85fvnpj6 HTTP/2.0" 404 158 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
35.201.134.129 netmanagement.us - [06/Oct/2026:10:28:13 +0000] "GET /assets/manifest.json HTTP/2.0" 404 158 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.201.134.129 netmanagement.us - [06/Oct/2026:10:28:13 +0000] "GET /dist/manifest.json HTTP/2.0" 404 158 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.201.134.129 netmanagement.us - [06/Oct/2026:10:28:13 +0000] "GET /z9x8c7v6b5-debug-trigger-netmanagement.us HTTP/2.0"
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 09:55:32
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.201.134.129 (129.134.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.134.129 (129.134.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 05:55:27.616360 2026] [security2:error] [pid 31047:tid 31047] [client 35.201.134.129:33290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "malinka.us"] [uri "/.htpasswd"] [unique_id "asTFj_NilSe27Sr9tjGl_AAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack