π¨π¦
zXero
2026-09-18 12:10:32
(1 day ago)
Fail2Ban automatic report - jail: recidive
Brute-Force
SSH
DDoS Attack
π©πͺ
Holger
2026-09-14 16:05:46
(5 days ago)
WordPress WebAttack
Brute-Force
Web App Attack
π¨π¦
zXero
2026-09-14 10:43:18
(5 days ago)
Fail2Ban automatic report - jail: recidive
Brute-Force
SSH
DDoS Attack
πΊπΈ
JustMeHere
2026-09-14 00:27:28
(6 days ago)
[Sun Sep 13 20:27:20.082793 2026] [security2:error] [pid 60737:tid 60784] [client 35.229.20.236:5199 ...
show more
[Sun Sep 13 20:27:20.082793 2026] [security2:error] [pid 60737:tid 60784] [client 35.229.20.236:51990] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "account2.yorknation.com"] [uri "/"] [unique_id "aqc_aBIPbeFzE50wWg5YKgAAANM"]
...
show less
Web App Attack
πΊπΈ
JustMeHere
2026-09-13 21:21:51
(6 days ago)
[Sun Sep 13 17:21:46.544716 2026] [security2:error] [pid 60737:tid 60771] [client 35.229.20.236:3442 ...
show more
[Sun Sep 13 17:21:46.544716 2026] [security2:error] [pid 60737:tid 60771] [client 35.229.20.236:34420] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "163.yorknation.com"] [uri "/"] [unique_id "aqcT6hIPbeFzE50wWg4yHwAAAMY"]
...
show less
Web App Attack
πΊπΈ
[email protected]
2026-09-13 19:47:56
(6 days ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-09-13T19:47:56Z
Brute-Force
Anonymous
2026-09-13 18:40:19
(6 days ago)
(mod_security) mod_security triggered on hostname [redacted] 35.229.20.236 (US/United States/236.20. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.229.20.236 (US/United States/236.20.229.35.bc.googleusercontent.com)
show less
SQL Injection
πΊπΈ
[email protected]
2026-09-13 18:32:35
(6 days ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-09-13T18:32:35Z
Brute-Force
πΊπΈ
TPI-Abuse
2026-09-13 18:03:53
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.229.20.236 (236.20.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.20.236 (236.20.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 14:03:47.725710 2026] [security2:error] [pid 29836:tid 29836] [client 35.229.20.236:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||totalsafe-security.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "totalsafe-security.com"] [uri "/z9x8c7v6b5-debug-trigger-totalsafe-security.com"] [unique_id "aqblg_FqNtGdU3VxgAKl5AAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-09-13 17:51:11
(6 days ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
[email protected]
2026-09-13 17:21:23
(6 days ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-09-13T17:21:23Z
Brute-Force
π΅πΉ
Subnet Phantom Veil
2026-09-13 17:00:24
(6 days ago)
[CRITICAL][Security Alert] Targeted exploit scanning against Textbook Vulnerabilities. Bot hunting f ...
show more
[CRITICAL][Security Alert] Targeted exploit scanning against Textbook Vulnerabilities. Bot hunting for PHP backdoors. [Method]: => GET. [Request]: => /panel. Access revoked. [User-Agent]: Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0. [OS]: Unknown. [IP Address]: 35.229.20.236.[RPS] 13+ requests-per-second (RPS) overshoot. [IoA Datetime]: 2026-09-13 14:13:03 UTC.
show less
Bad Web Bot
Hacking
Port Scan
Web App Attack
πΊπΈ
[email protected]
2026-09-13 16:33:04
(6 days ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-09-13T16:33:04Z
Brute-Force
πΊπΈ
[email protected]
2026-09-13 15:44:31
(6 days ago)
Fail2Ban jail apache-json-scanners detected activity on 2026-09-13T15:44:31Z
Brute-Force
π«π·
Baking333
2026-09-13 15:35:12
(6 days ago)
[redacted] 35.229.20.236 - - [13/Sep/2026:16:35:11 +0100] "GET /.github/.env HTTP/1.1" 302 6768 0/97 ...
show more
[redacted] 35.229.20.236 - - [13/Sep/2026:16:35:11 +0100] "GET /.github/.env HTTP/1.1" 302 6768 0/97963 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://[redacted]/)" [redacted] 35.229.20.236 - - [13/Sep/2026:16:35:11 +0100] "GET / HTTP/1.1" 200 7987 0/102228 "https://[redacted]/.github/.env" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://[redacted]/)"
show less
Bad Web Bot
Web App Attack