๐ฟ๐ฆ
conure.sh
2026-08-28 12:14:46
(1 hour ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 0s
Web App Attack
Anonymous
2026-08-28 12:10:46
(1 hour ago)
Auto-reported by Fail2Ban (NPM-Auth)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 11:25:52
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.45.239 (239.45.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.45.239 (239.45.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 07:25:46.149256 2026] [security2:error] [pid 8511:tid 8511] [client 35.227.45.239:58228] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "yongmeihu.com"] [uri "/wp-config.php~"] [unique_id "apFwOgBTNmkWCDeF02hn2wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 10:40:41
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.227.45.239 (239.45.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.227.45.239 (239.45.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 06:40:38.198263 2026] [security2:error] [pid 15438:tid 15496] [client 35.227.45.239:45468] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cafeteresemporda.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cafeteresemporda.com"] [uri "/storage/logs/laravel.log"] [unique_id "apFlppNJMqZH17d3gw_zugAAAVY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Celtic
2026-08-28 10:22:35
(3 hours ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-08-28 10:17:10
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.227.45.239 (239.45.227.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.45.239 (239.45.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 06:17:03.486780 2026] [security2:error] [pid 6780:tid 6780] [client 35.227.45.239:38346] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "robotsinme.org"] [uri "/.env"] [unique_id "apFgHwWSKeT8LqNq_DUMCAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
nadnitin
2026-08-27 22:12:30
(15 hours ago)
Automated trigger via Nginx Police. Reason: PATH-PROBER. Trigger Log: 35.227.45.239 - - [28/Aug/2026 ...
show more
Automated trigger via Nginx Police. Reason: PATH-PROBER. Trigger Log: 35.227.45.239 - - [28/Aug/2026:03:42:29 +0530] "GET /.env.backup HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
show less
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-08-27 22:02:28
(15 hours ago)
Auto-ban: >3000 req/min op 2026-08-27
Web App Attack
SSH
Hacking
๐ฉ๐ช
gadix
2026-08-27 20:17:24
(17 hours ago)
[27/Aug/2026:22:17:24.281184 +0200] apCbVD0uOXIrZQMvSXATOwAAAAI 35.227.45.239 54774 127.0.0.1 7081
[ ...
show more
[27/Aug/2026:22:17:24.281184 +0200] apCbVD0uOXIrZQMvSXATOwAAAAI 35.227.45.239 54774 127.0.0.1 7081
[27/Aug/2026:22:17:24.282293 +0200] apCbVD0uOXIrZQMvSXATPAAAAAA 35.227.45.239 54782 127.0.0.1 7081
[27/Aug/2026:22:17:24.283573 +0200] apCbVD0uOXIrZQMvSXATPQAAAAU 35.227.45.239 54808 127.0.0.1 7081
...
show less
Web App Attack
๐ฏ๐ต
VXG-NET
2026-08-27 20:13:35
(17 hours ago)
port=80, indicator_type=info-leak
Hacking
๐ฆ๐น
Starburst SysOp Team
2026-08-27 20:11:11
(17 hours ago)
Host header is a numeric IP address. Pattern match "(?:^( (920350-vie6-1)
Hacking
Bad Web Bot
๐ณ๐ฑ
spirttm
2026-08-27 20:10:49
(17 hours ago)
35.227.45.239 - - [27/Aug/2026:20:10:48 +0000] "GET /.env HTTP/1.1" 404 162 "-" "crusader-worker/1.0 ...
show more
35.227.45.239 - - [27/Aug/2026:20:10:48 +0000] "GET /.env HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
35.227.45.239 - - [27/Aug/2026:20:10:48 +0000] "GET /.env.local HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
35.227.45.239 - - [27/Aug/2026:20:10:48 +0000] "GET /.env.production HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
35.227.45.239 - - [27/Aug/2026:20:10:48 +0000] "GET /.env.prod HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
35.227.45.239 - - [27/Aug/2026:20:10:48 +0000] "GET /.env.bak HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
35.227.45.239 - - [27/Aug/2026:20:10:48 +0000] "GET /.env.backup HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
35.227.45.239 - - [27/Aug/2026:20:10:48 +0000] "GET /.env.dev HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
35.227.45.239 - - [27/Aug/2026:20:10:48 +0000] "GET /.env.example HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
35.227.45.239 - - [27/Aug/2026:20:10:48 +0000] "GET /.env.old HTTP/1.1" 404 162 "-" "crusader-worker/1.0"
35.227.45.239 - - [27/Aug/2026:20
...
show less
Port Scan
Web App Attack
๐จ๐ฆ
aks4226
2026-08-27 20:09:55
(17 hours ago)
Bot search, attacking common web applications.
Web App Attack
๐บ๐ธ
mnsf
2026-08-27 19:05:15
(18 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
Anonymous
2026-08-27 18:05:02
(19 hours ago)
suspicious request in access.log
Web App Attack