๐ฎ๐น
VHosting
2026-09-19 09:25:04
(5 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-09-19 08:42:32
(6 hours ago)
[2026-09-1910:42:28 0200]info[cpaneld]35.240.165.54--\"GET/z9x8c7v6b5-debug-trigger-cpanel.gruppobal ...
show more
[2026-09-1910:42:28 0200]info[cpaneld]35.240.165.54--\"GET/z9x8c7v6b5-debug-trigger-cpanel.gruppobalu.comHTTP/1.1\"FAILEDLOGINcpaneld:loginattemptwithoutusername[2026-09-1910:42:29 0200]info[cpaneld]35.240.165.54--\"GET/document.php\?modulepart=systemtools\
show less
Port Scan
Brute-Force
Web App Attack
๐ฌ๐ง
oja
2026-09-18 21:44:47
(17 hours ago)
Aggressive web scanner
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-18 21:38:34
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.240.165.54 (54.165.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.165.54 (54.165.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 17:38:26.502934 2026] [security2:error] [pid 19267:tid 19267] [client 35.240.165.54:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.nyemdr.com"] [uri "/.git/HEAD"] [unique_id "aq2vUm2B8RQOBsoy1xpcpQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-18 11:32:12
(1 day ago)
Portscan: TCP/8080 (5x), TCP/8443 (5x)
Port Scan
๐ซ๐ท
dynamix
2026-09-18 09:26:26
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
kosada.com
2026-09-18 09:13:37
(1 day ago)
Repeated requests for suspicious nonexistent URLs, for example: /.vite/manifest.json (HTTP/2.0 port ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /.vite/manifest.json (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36")
show less
Web App Attack
๐บ๐ธ
etu brutus
2026-09-18 06:01:30
(1 day ago)
35.240.165.54 Blocked by [Attack Vector List]
...
Hacking
Brute-Force
Exploited Host
๐บ๐ธ
OceanTreasure
2026-09-18 06:01:16
(1 day ago)
tcp/8080; Unsolicited SYN to a port that has never been offered on this address (closed, no service ...
show more
tcp/8080; Unsolicited SYN to a port that has never been offered on this address (closed, no service ever) @ 2026-09-18T05:58:41Z
show less
Port Scan
๐ซ๐ฎ
Christopher Hughes
2026-09-18 04:28:46
(1 day ago)
35.240.165.54 - - [18/Sep/2026:05:28:46 +0100] "GET /@fs/.env?url&raw?? HTTP/2.0" 401 410 "-" "Mozil ...
show more
35.240.165.54 - - [18/Sep/2026:05:28:46 +0100] "GET /@fs/.env?url&raw?? HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-09-18 03:31:46
(1 day ago)
35.240.165.54 - - [18/Sep/2026:04:31:46 +0100] "GET /z9x8c7v6b5-debug-trigger-local.tmxnews.co.uk HT ...
show more
35.240.165.54 - - [18/Sep/2026:04:31:46 +0100] "GET /z9x8c7v6b5-debug-trigger-local.tmxnews.co.uk HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-09-18 03:14:02
(1 day ago)
35.240.165.54 - - [18/Sep/2026:04:14:01 +0100] "GET /id_rsa HTTP/2.0" 401 410 "-" "Mozilla/5.0 (comp ...
show more
35.240.165.54 - - [18/Sep/2026:04:14:01 +0100] "GET /id_rsa HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ฎ๐ฉ
sockominfo
2026-09-18 03:00:53
(1 day ago)
Active Response: IP 35.240.165.54 Blocked via Firewall Drop. Threat Score: 3.8/10 (LOW). Confidence: ...
show more
Active Response: IP 35.240.165.54 Blocked via Firewall Drop. Threat Score: 3.8/10 (LOW). Confidence: 30%. CVSS v3.1: 0/10 (None). CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:N. Bayesian Probability: 33%. MITRE ATT&CK: T1016 (System Network Configuration Discovery). Tactic: TA0001. Freshness: Very Fresh. Source Reputation: UNKNOWN. Methodology: CVSS 3.1 + Bayesian + Temporal + Environmental + MITRE ATT&CK + OWASP. Standards: ISO/IEC 27065:2022, NIST SP 800-30, IEEE S&P 2020. Reported by TangerangKota-CSIRT
show less
Hacking
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-09-18 02:55:04
(1 day ago)
35.240.165.54 - - [18/Sep/2026:03:55:03 +0100] "GET /api/attachments/img/avatar/..%2F..%2F..%2F..%2F ...
show more
35.240.165.54 - - [18/Sep/2026:03:55:03 +0100] "GET /api/attachments/img/avatar/..%2F..%2F..%2F..%2F..%2F.env HTTP/2.0" 404 224 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ฉ๐ช
macrob
2026-09-18 02:41:32
(1 day ago)
2026/09/18 02:41:31 [error] 3680940#3680940: *10115047 access forbidden by rule, client: 35.240.165. ...
show more
2026/09/18 02:41:31 [error] 3680940#3680940: *10115047 access forbidden by rule, client: 35.240.165.54, server: binixo.pl, request: "GET /docker/.env HTTP/2.0", host: "binixo.pl", referrer: "https://langflow.binixo.pl/docker/.env"
2026/09/18 02:41:31 [error] 3680943#3680943: *10116438 access forbidden by rule, client: 35.240.165.54, server: binixo.pl, request: "GET /.vite/manifest.json HTTP/2.0", host: "binixo.pl", referrer: "https://langflow.binixo.pl/.vite/manifest.json"
2026/09/18 02:41:31 [error] 3680944#3680944: *10114954 access forbidden by rule, client: 35.240.165.54, server: binixo.pl, request: "GET /infra/.env HTTP/2.0", host: "binixo.pl", referrer: "https://langflow.binixo.pl/infra/.env"
...
show less
Web App Attack