๐ฉ๐ช
klaus_ph
2026-09-27 14:18:16
(6 hours ago)
2026-09-26 07:04:28,557 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 35.233.157.222
. ...
show more
2026-09-26 07:04:28,557 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 35.233.157.222
...
show less
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-09-22 21:59:24
(4 days ago)
Auto-ban: >3000 req/min op 2026-09-22
Web App Attack
SSH
Hacking
๐ณ๐ฑ
Alt255
2026-09-22 16:47:59
(5 days ago)
[ti-29al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-29al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.233.157.222 - - [22/Sep/2026:18:47:59 +0200] "GET /.env.old HTTP/1.1" 301 6334 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:46:30
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.233.157.222 (222.157.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.157.222 (222.157.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:46:24.213438 2026] [security2:error] [pid 4535:tid 4535] [client 35.233.157.222:51858] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ohiobabe.com"] [uri "/wp-config.php.bak"] [unique_id "arKi0IRpLqdJDSRgtgcMIAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-22 15:09:18
(5 days ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.233.157.222 (US/United States/222.157 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.233.157.222 (US/United States/222.157.233.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.233.157.222 - - [22/Sep/2026:17:09:14 +0200] "GET /wp-config.php.bak HTTP/1.1" 200 12120 "-" "crusader-worker/1.0" "-" host=menu.ilfungarolo.it
show less
Port Scan
๐ฒ๐พ
Rizzy
2026-09-22 14:56:16
(5 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ต๐ฑ
jekob
2026-09-22 14:40:45
(5 days ago)
Automated malicious activity detected (5 events)
Hacking
Web App Attack
๐ช๐ธ
Francisco Vallejo
2026-09-22 14:35:39
(5 days ago)
[Tue Sep 22 16:35:38.767187 2026] [authz_core:error] [pid 135864:tid 136416885470912] [client 35.233 ...
show more
[Tue Sep 22 16:35:38.767187 2026] [authz_core:error] [pid 135864:tid 136416885470912] [client 35.233.157.222:50576] AH01630: client denied by server configuration: proxy:http://localhost:3001/.env.production
[Tue Sep 22 16:35:38.767246 2026] [authz_core:error] [pid 135865:tid 136416944187072] [client 35.233.157.222:50510] AH01630: client denied by server configuration: proxy:http://localhost:3001/_ignition/health-check
[Tue Sep 22 16:35:38.767643 2026] [authz_core:error] [pid 135864:tid 136417455879872] [client 35.233.157.222:50562] AH01630: client denied by server configuration: proxy:http://localhost:3001/.env.prod
[Tue Sep 22 16:35:38.767707 2026] [authz_core:error] [pid 135864:tid 136418403796672] [client 35.233.157.222:50550] AH01630: client denied by server configuration: proxy:http://localhost:3001/wp-config.php.bak
[Tue Sep 22 16:35:38.767710 2026] [authz_core:error] [pid 135865:tid 136417522988736] [client 35.233.157.222:50406] AH01630: client denied by server configuration: p
...
show less
Brute-Force
SSH
๐ณ๐ฑ
Alt255
2026-09-22 13:39:28
(5 days ago)
[ti-12al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail <name>. Example: 35. ...
show more
[ti-12al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail <name>. Example: 35.233.157.222 - - \[22/Sep/2026:15:39:25 +0200\] "GET /.env.backup HTTP/1.1" 403 6485 "-" "crusader-worker/1.0"
35.233.157.222 - - \[22/Sep/2026:15:39:25 +0200\] "GET /.env.dev HTTP/1.1" 403 6485 "-" "crusader-worker/1.0"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-22 13:16:37
(5 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-09-22 11:55:03
(5 days ago)
suspicious request in access.log
Web App Attack
๐ซ๐ท
COMAITE
2026-09-22 11:37:55
(5 days ago)
Suspicious URL access.
Web App Attack
๐ฉ๐ช
kkw
2026-09-22 11:20:45
(5 days ago)
[REDACTED] 35.233.157.222 - - [22/Sep/2026:13:20:45 +0200] "GET /.env.old HTTP/1.1" 403 4484 "-" "cr ...
show more
[REDACTED] 35.233.157.222 - - [22/Sep/2026:13:20:45 +0200] "GET /.env.old HTTP/1.1" 403 4484 "-" "crusader-worker/1.0"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
๐จ๐ญ
leo1305
2026-09-22 11:20:15
(5 days ago)
CrowdSec detection | scenario: http-sensitive-files
Web App Attack
Exploited Host
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-22 11:10:00
(5 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking