๐บ๐ธ
ph
2026-09-20 15:17:27
(1 hour ago)
Bad web bot attempting to run wp-json on non-WP site
Hacking
Bad Web Bot
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-20 15:14:33
(1 hour ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
LRob
2026-09-20 14:58:21
(1 hour ago)
Declared crawler ignoring robots.txt and the refusals it is given | path: /css../.env (+12 more) | 2 ...
show more
Declared crawler ignoring robots.txt and the refusals it is given | path: /css../.env (+12 more) | 2026-09-20 14:58 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-20 14:58:00
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.223.216.8 (8.216.223.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.223.216.8 (8.216.223.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:57:55.778960 2026] [security2:error] [pid 16996:tid 16996] [client 35.223.216.8:50956] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "modeltdr.com"] [uri "/etc/.env"] [unique_id "aq_0c_8dudOOyigJ2426RAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:35:31
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.223.216.8 (8.216.223.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.223.216.8 (8.216.223.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:35:27.339989 2026] [security2:error] [pid 16363:tid 16427] [client 35.223.216.8:38700] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kd9uri.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kd9uri.com"] [uri "/rclone.conf"] [unique_id "aq_vLwhP2Ec8aTqJGSvfqAAAAgg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-09-20 14:22:48
(1 hour ago)
[20/Sep/2026:16:22:47 +0200] 178991416732.620467 35.223.216.8 60230 217.154.7.177 443
[20/Sep/2026:1 ...
show more
[20/Sep/2026:16:22:47 +0200] 178991416732.620467 35.223.216.8 60230 217.154.7.177 443
[20/Sep/2026:16:22:47 +0200] 178991416757.552241 35.223.216.8 60230 217.154.7.177 443
[20/Sep/2026:16:22:47 +0200] 178991416753.996176 35.223.216.8 51462 217.154.7.177 443
[20/Sep/2026:16:22:47 +0200] 178991416773.435483 35.223.216.8 60230 217.154.7.177 443
[20/Sep/2026:16:22:47 +0200] 17899141670.741079 35.223.216.8 60230 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-09-20 14:07:19
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-20 13:49:30
(2 hours ago)
Aggressive web scan
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-20 13:47:13
(2 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:47:03
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.223.216.8 (8.216.223.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.223.216.8 (8.216.223.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:46:55.694506 2026] [security2:error] [pid 11061:tid 11061] [client 35.223.216.8:59986] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||genevaatlantic.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "genevaatlantic.com"] [uri "/z9x8c7v6b5-debug-trigger-genevaatlantic.com"] [unique_id "aq_jz4HB2hdAs1K5zKlqogAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-20 13:33:17
(2 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-20 13:30:03
(2 hours ago)
CrowdSec decision: crowdsecurity/http-crawl-non_statics (origin: crowdsec)
Port Scan
๐ซ๐ท
COMAITE
2026-09-20 13:24:40
(2 hours ago)
Suspicious URL access.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:04:05
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.223.216.8 (8.216.223.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.223.216.8 (8.216.223.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:03:59.542144 2026] [security2:error] [pid 8357:tid 8357] [client 35.223.216.8:37972] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidquiroa.com"] [uri "/.env.production"] [unique_id "aq_Zv4ueaT3p33ZTWm2-ZgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
dalslab ltd
2026-09-20 13:02:31
(3 hours ago)
35.223.216.8 - - [20/Sep/2026:15:02:26 +0200] "POST /graphql HTTP/1.1" 405 556 "http://dalslab.com" ...
show more
35.223.216.8 - - [20/Sep/2026:15:02:26 +0200] "POST /graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.223.216.8 - - [20/Sep/2026:15:02:26 +0200] "POST /api/graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.223.216.8 - - [20/Sep/2026:15:02:26 +0200] "POST /v1/graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.223.216.8 - - [20/Sep/2026:15:02:26 +0200] "POST / HTTP/1.1" 405 154 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
35.223.216.8 - - [20/Sep/2026:15:02:30 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 154 "-" "-"
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack