๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-21 06:34:57
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-21 06:08:00
(1 day ago)
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02 ...
show more
Fail2Ban - [WAF]ModSecurity OWASP CRS rule violation on nginx-modsecurity ... [ice01,ice02,wa01,wa02]
show less
Hacking
SQL Injection
Web App Attack
๐ฉ๐ช
Live Home Cams
2026-09-21 06:00:30
(1 day ago)
WebApp brute force attack detected. Multiple file scanning attempts from 35.240.121.48. Detected by ...
show more
WebApp brute force attack detected. Multiple file scanning attempts from 35.240.121.48. Detected by fail2ban.
show less
Web App Attack
Brute-Force
๐ช๐ธ
masterguru
2026-09-21 05:47:52
(1 day ago)
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:user-agent. (1100000- ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
๐ซ๐ท
Omar Martรญnez
2026-09-21 05:42:08
(1 day ago)
[Sun Sep 20 23:42:06.023965 2026] [core:error] [pid 244381:tid 139864842831424] [remote 35.240.121.4 ...
show more
[Sun Sep 20 23:42:06.023965 2026] [core:error] [pid 244381:tid 139864842831424] [remote 35.240.121.48:42366] AH10244: invalid URI path (/%2e%2e/.env)
[Sun Sep 20 23:42:06.433086 2026] [core:error] [pid 244381:tid 139864784082496] [remote 35.240.121.48:42366] AH10244: invalid URI path (/public/plugins/alertlist/../../../../../../../../proc/self/environ)
...
show less
Phishing
Email Spam
Blog Spam
๐ฟ๐ฆ
conure.sh
2026-09-21 05:08:19
(1 day ago)
csagent: score 21.2: 404 noise floor x5, secrets grab x1, spoofed crawler UA x1; 1 domain(s) in 3s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:58:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.240.121.48 (48.121.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.121.48 (48.121.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:58:36.844044 2026] [security2:error] [pid 21881:tid 21881] [client 35.240.121.48:43888] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.hijamadirectory.com"] [uri "/admin/.env"] [unique_id "arC5fEY_FR7UYb6c18fk6gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-21 04:57:02
(1 day ago)
Fail2Ban - [WAF]ModSecurity rule violation on modsecurity ... [wa02]
Hacking
SQL Injection
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 04:16:12
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.240.121.48 (48.121.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.121.48 (48.121.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:16:04.717357 2026] [security2:error] [pid 29780:tid 29780] [client 35.240.121.48:43430] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.spyasociados.com"] [uri "/@fs/src/.env"] [unique_id "arCvhFVdd7uPvHqxhqej_wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-09-21 03:54:30
(1 day ago)
Aggressive web search of vulnerable pages: /docker-compose.yml /api/console/api_server?sense_version ...
show more
Aggressive web search of vulnerable pages: /docker-compose.yml /api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../.. ...
show less
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-09-21 03:35:10
(1 day ago)
Login credentials theft attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 02:47:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.240.121.48 (48.121.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.121.48 (48.121.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:47:48.178158 2026] [security2:error] [pid 18783:tid 18783] [client 35.240.121.48:39848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.horse7.com"] [uri "/.git/config"] [unique_id "arCa1Crp0nDm6cwOz2FaZAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-21 02:18:44
(1 day ago)
[ti-02ra] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02ra] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.240.121.48 - - [21/Sep/2026:04:18:37 +0200] "GET /deploy/.env HTTP/2.0" 404 79912 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 02:18:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.240.121.48 (48.121.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.121.48 (48.121.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:18:10.534183 2026] [security2:error] [pid 22863:tid 22863] [client 35.240.121.48:33014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.homehealth101.com"] [uri "/.env"] [unique_id "arCT4sxo-MgHnnxW_4-CGAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 00:48:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.240.121.48 (48.121.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.121.48 (48.121.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 20:48:25.069859 2026] [security2:error] [pid 17184:tid 17184] [client 35.240.121.48:59380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "home.agingworkforcenews.com"] [uri "/server/.env"] [unique_id "arB-2RCfKGG9LXAlPenaegAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack