๐ณ๐ฑ
Savvii
2026-09-19 05:31:44
(9 hours ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-18 22:31:46
(16 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐จ๐ญ
dalslab ltd
2026-09-18 20:14:49
(19 hours ago)
2026/09/18 22:14:48 [error] 949#949: *1960437 limiting requests, excess: 200.390 by zone "rl_per_ip" ...
show more
2026/09/18 22:14:48 [error] 949#949: *1960437 limiting requests, excess: 200.390 by zone "rl_per_ip", client: 35.227.57.98, server: auth.dalslab.com, request: "GET /infra/.env HTTP/2.0", host: "auth.dalslab.com"
2026/09/18 22:14:48 [error] 949#949: *1960437 limiting requests, excess: 200.320 by zone "rl_per_ip", client: 35.227.57.98, server: auth.dalslab.com, request: "GET /public/env.js HTTP/2.0", host: "auth.dalslab.com"
2026/09/18 22:14:48 [error] 949#949: *1960437 limiting requests, excess: 200.480 by zone "rl_per_ip", client: 35.227.57.98, server: auth.dalslab.com, request: "GET /config/.env HTTP/2.0", host: "auth.dalslab.com"
2026/09/18 22:14:48 [error] 949#949: *1960437 limiting requests, excess: 200.370 by zone "rl_per_ip", client: 35.227.57.98, server: auth.dalslab.com, request: "GET /scripts/.env HTTP/2.0", host: "auth.dalslab.com"
2026/09/18 22:14:48 [error] 949#949: *1960437 limiting requests, excess: 200.170 by zone "rl_per_ip", client: 35.227.57.98, server: auth.dalslab.c
...
show less
Brute-Force
SSH
๐ง๐ท
dermatovirtual
2026-09-18 16:12:52
(23 hours ago)
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web ...
show more
Dermato Virtual CSIRT: Malicious web exploit/scanning probes against app.dermatovirtual.com.br (Web Server Ports 80/443). 85 unauthorized requests recorded between 2026-09-17 16:08:24 UTC and 2026-09-17 16:08:36 UTC (rate: ~85 req/min). Edge perimeter firewall drop active.
Log sample:
[2026-09-17 16:08:35 UTC] IP: 35.227.57.98 - W3C IIS (Port 443): GET /@fs/.env -> HTTP 404 [CLIENT: 35.227.57.98]
[2026-09-17 16:08:36 UTC] IP: 35.227.57.98 - W3C IIS (Port 443): GET /project/.env -> HTTP 404 [CLIENT: 35.227.57.98]
[2026-09-17 16:08:36 UTC] IP: 35.227.57.98 - W3C IIS (Port 443): GET /server/.env -> HTTP 404 [CLIENT: 35.227.57.98]
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-18 15:14:24
(1 day ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
Shouddy Tarano
2026-09-18 15:07:26
(1 day ago)
[Fri Sep 18 09:07:20.024930 2026] [authz_core:error] [pid 3264211:tid 139792352225024] [client 35.22 ...
show more
[Fri Sep 18 09:07:20.024930 2026] [authz_core:error] [pid 3264211:tid 139792352225024] [client 35.227.57.98:35582] AH01630: client denied by server configuration: /var/www/ccmApi/public/docker
[Fri Sep 18 09:07:20.916226 2026] [authz_core:error] [pid 3264211:tid 139792293476096] [client 35.227.57.98:35582] AH01630: client denied by server configuration: /var/www/ccmApi/public/config.js
[Fri Sep 18 09:07:22.989124 2026] [authz_core:error] [pid 3394191:tid 139792427759360] [client 35.227.57.98:35626] AH01630: client denied by server configuration: /var/www/ccmApi/public/server-info
[Fri Sep 18 09:07:22.992002 2026] [authz_core:error] [pid 3264212:tid 139792066971392] [client 35.227.57.98:35616] AH01630: client denied by server configuration: /var/www/ccmApi/public/@fs
[Fri Sep 18 09:07:24.578651 2026] [authz_core:error] [pid 3264432:tid 139792276756224] [client 35.227.57.98:35598] AH01630: client denied by server configuration: /var/www/ccmApi/public/api
...
show less
DDoS Attack
Web Spam
Brute-Force
Web App Attack
๐จ๐ญ
dalslab ltd
2026-09-18 12:46:06
(1 day ago)
[18/Sep/2026:14:46:04 +0200] - 404 404 - GET https ai.dalslab.com "/static/manifest.json" [Client 35 ...
show more
[18/Sep/2026:14:46:04 +0200] - 404 404 - GET https ai.dalslab.com "/static/manifest.json" [Client 35.227.57.98] [Length 22] [Gzip -] [Sent-to 10.1.1.246] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-"
[18/Sep/2026:14:46:04 +0200] - 405 405 - POST https ai.dalslab.com "/graphql" [Client 35.227.57.98] [Length 31] [Gzip -] [Sent-to 10.1.1.246] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "https://ai.dalslab.com"
[18/Sep/2026:14:46:04 +0200] - 405 405 - POST https ai.dalslab.com "/api/graphql" [Client 35.227.57.98] [Length 31] [Gzip -] [Sent-to 10.1.1.246] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "https://ai.dalslab.com"
[18/Sep/2026:14:46:04 +0200] - 405 405 - POST https ai.dalslab.com "/v1/graphql" [Client 35.227.57.98] [Length 31] [Gzip -] [Sent-to 10.1.1.246]
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-18 11:32:17
(1 day ago)
Portscan: TCP/8443 (5x), TCP/8080 (5x), TCP/443, TCP/80
Port Scan
Anonymous
2026-09-18 08:46:44
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฉ๐ช
london2038.com
2026-09-18 08:35:56
(1 day ago)
Probing for exploits
35.227.57.98 - - [18/Sep/2026:10:35:54 +0200] "GET /config.json HTTP/2.0" 422 0 ...
show more
Probing for exploits
35.227.57.98 - - [18/Sep/2026:10:35:54 +0200] "GET /config.json HTTP/2.0" 422 0 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
35.227.57.98 - - [18/Sep/2026:10:35:54 +0200] "GET /config.js HTTP/2.0" 422 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 03:01:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.227.57.98 (98.57.227.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.227.57.98 (98.57.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 23:00:56.862233 2026] [security2:error] [pid 2772:tid 2772] [client 35.227.57.98:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.empoweruamerica.org"] [uri "/.github/.env"] [unique_id "aqypaACylqAt1jA1r39Z3gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-18 02:50:04
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
zcampbell
2026-09-18 02:03:11
(1 day ago)
Web vulnerability scanning: probing for exposed sensitive files (id_rsa). Detected and blocked autom ...
show more
Web vulnerability scanning: probing for exposed sensitive files (id_rsa). Detected and blocked automatically.
show less
Web App Attack
Bad Web Bot
๐ซ๐ท
SpaceHost-Server
2026-09-17 22:22:27
(1 day ago)
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-09-17 21:10:07
(1 day ago)
Web attack/malicious scanning detected
Web App Attack