๐จ๐ฆ
zXero
2026-09-23 12:41:35
(1 day ago)
Fail2Ban automatic report - jail: recidive
Brute-Force
SSH
DDoS Attack
๐ฒ๐ฝ
octageeks.com
2026-09-23 04:23:07
(1 day ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ฉ๐ช
itsolon
2026-09-23 03:38:19
(1 day ago)
[23/Sep/2026:05:38:17 +0200] 179013469736.054974 35.221.205.199 0 217.154.7.177 443
[23/Sep/2026:05: ...
show more
[23/Sep/2026:05:38:17 +0200] 179013469736.054974 35.221.205.199 0 217.154.7.177 443
[23/Sep/2026:05:38:17 +0200] 179013469776.411547 35.221.205.199 0 217.154.7.177 443
[23/Sep/2026:05:38:17 +0200] 179013469796.914863 35.221.205.199 0 217.154.7.177 443
[23/Sep/2026:05:38:17 +0200] 179013469763.459255 35.221.205.199 0 217.154.7.177 443
[23/Sep/2026:05:38:19 +0200] 179013469954.695118 35.221.205.199 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ช๐ธ
masterguru
2026-09-23 00:21:46
(1 day ago)
BAD BOT - Detected and Blocked.. Matched phrase "OAI-SearchBot" at REQUEST_HEADERS:user-agent. (1100 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "OAI-SearchBot" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
๐ซ๐ท
SpaceHost-Server
2026-09-22 22:25:17
(1 day ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 21:01:12
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 35.221.205.199 (199.205.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 35.221.205.199 (199.205.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:01:04.262991 2026] [security2:error] [pid 15783:tid 15783] [client 35.221.205.199:47166] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.spmbookings.com"] [uri "/.env"] [unique_id "arLskAOb2t_c7j0pGXL__AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 20:45:49
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.221.205.199 (199.205.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.205.199 (199.205.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:45:42.678245 2026] [security2:error] [pid 5348:tid 5348] [client 35.221.205.199:44600] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.spiritofacorn.com|F|2"] [data ".spiritofacorn.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.spiritofacorn.com"] [uri "/z9x8c7v6b5-debug-trigger-www.spiritofacorn.com"] [unique_id "arLo9sblASAHA5CJN3-SnQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
antlac1
2026-09-22 18:46:41
(1 day ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ฉ๐ช
itsolon
2026-09-22 18:27:58
(1 day ago)
[22/Sep/2026:20:27:57 +0200] 179010167784.848234 35.221.205.199 44876 217.154.7.177 443
[22/Sep/2026 ...
show more
[22/Sep/2026:20:27:57 +0200] 179010167784.848234 35.221.205.199 44876 217.154.7.177 443
[22/Sep/2026:20:27:57 +0200] 179010167722.919181 35.221.205.199 44876 217.154.7.177 443
[22/Sep/2026:20:27:57 +0200] 179010167749.139062 35.221.205.199 44876 217.154.7.177 443
[22/Sep/2026:20:27:57 +0200] 179010167770.913824 35.221.205.199 44876 217.154.7.177 443
[22/Sep/2026:20:27:58 +0200] 17901016787.439842 35.221.205.199 44876 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-22 18:12:25
(1 day ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 17:35:08
(1 day ago)
35.221.205.199 - - [22/Sep/2026:17:35:08 +0000] "-" 400 166 "-" "-"
35.221.205.199 - - [22/Sep/2026: ...
show more
35.221.205.199 - - [22/Sep/2026:17:35:08 +0000] "-" 400 166 "-" "-"
35.221.205.199 - - [22/Sep/2026:17:35:08 +0000] "-" 400 166 "-" "-"
35.221.205.199 - - [22/Sep/2026:17:35:08 +0000] "-" 400 166 "-" "-"
...
show less
Brute-Force
๐ฉ๐ช
macrob
2026-09-22 16:46:33
(2 days ago)
2026/09/22 16:46:31 [error] 1636368#1636368: *25619007 access forbidden by rule, client: 35.221.205. ...
show more
2026/09/22 16:46:31 [error] 1636368#1636368: *25619007 access forbidden by rule, client: 35.221.205.199, server: behemoti.com, request: "GET /.vite/manifest.json HTTP/2.0", host: "behemoti.com"
2026/09/22 16:46:32 [error] 1636367#1636367: *25619026 access forbidden by rule, client: 35.221.205.199, server: behemoti.com, request: "GET /dist/.vite/manifest.json HTTP/2.0", host: "behemoti.com"
2026/09/22 16:46:32 [error] 1636363#1636363: *25619056 access forbidden by rule, client: 35.221.205.199, server: behemoti.com, request: "GET /config/firebase-admin.json HTTP/2.0", host: "behemoti.com"
...
show less
Web App Attack
Anonymous
2026-09-22 16:30:03
(2 days ago)
CrowdSec decision: crowdsecurity/http-probing (origin: crowdsec)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:28:15
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.221.205.199 (199.205.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.205.199 (199.205.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:28:08.316884 2026] [security2:error] [pid 27559:tid 27559] [client 35.221.205.199:54600] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||grimone.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "grimone.com"] [uri "/z9x8c7v6b5-debug-trigger-grimone.com"] [unique_id "arKeiK7DyvOld_fYmDGYLAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Swiptly
2026-09-22 15:01:24
(2 days ago)
Bot scanning for environment files .env .env/\*
...
Web App Attack