๐ซ๐ท
ELYAZ
2026-09-30 18:28:43
(4 days ago)
(y3) Failed access -byebye- from 35.240.181.165 (SG/Singapore/165.181.240.35.bc.googleusercontent.co ...
show more
(y3) Failed access -byebye- from 35.240.181.165 (SG/Singapore/165.181.240.35.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
๐ฌ๐ง
Yosi
2026-09-30 18:07:35
(4 days ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ฉ๐ช
yvoictra
2026-09-30 17:23:32
(4 days ago)
Bloqueado automรกticamente por CrowdSec. Escenario: crowdsecurity/http-bad-user-agent
Web App Attack
Anonymous
2026-09-30 15:43:00
(4 days ago)
35.240.181.165 - - [30/Sep/2026:05:37:43 -0500] "GET /.env.js HTTP/1.1" 403 199 "-" "Mozilla/5.0 (co ...
show more
35.240.181.165 - - [30/Sep/2026:05:37:43 -0500] "GET /.env.js HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 35.240.181.165
35.240.181.165 - - [30/Sep/2026:06:39:21 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" 35.240.181.165
35.240.181.165 - - [30/Sep/2026:06:39:21 -0500] "GET /.env.example HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" 35.240.181.165
35.240.181.165 - - [30/Sep/2026:06:39:21 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 35.240.181.165
35.240.181.165 - - [30/Sep/2026:06:39:21 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" 35.240.181.165
35.240.181.165 - - [30/Sep/2026:06:39:22 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible;
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
XICTRON
2026-09-30 15:05:08
(4 days ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-30 15:00:10
(4 days ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.240.181.165 - - [30/Sep/2026:17:00:00 +0200] "GET /laravel/.env HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:48:35
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 35.240.181.165 (165.181.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.181.165 (165.181.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:48:29.925297 2026] [security2:error] [pid 7688:tid 7709] [client 35.240.181.165:59476] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||yubasutterphotographer.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "yubasutterphotographer.com"] [uri "/z9x8c7v6b5-debug-trigger-yubasutterphotographer.com"] [unique_id "ar0hPbelAtFaQpwdQ63EWQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-30 14:20:04
(4 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-30 12:23:16
(4 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-30 11:35:14
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 35.240.181.165 (165.181.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.181.165 (165.181.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:35:08.495624 2026] [security2:error] [pid 30840:tid 30840] [client 35.240.181.165:59760] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||casagrotto.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "casagrotto.com"] [uri "/z9x8c7v6b5-debug-trigger-casagrotto.com"] [unique_id "arzz7JS24Vqp-W4Pr7uVQgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-30 10:45:15
(4 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 10:28:08
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.240.181.165 (165.181.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.181.165 (165.181.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:28:04.104688 2026] [security2:error] [pid 11181:tid 11181] [client 35.240.181.165:49912] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.yoshiyukiya.com|F|2"] [data ".yoshiyukiya.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.yoshiyukiya.com"] [uri "/z9x8c7v6b5-debug-trigger-www.yoshiyukiya.com"] [unique_id "arzkNKoHGSHERlvf8rtijwAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
OceanTreasure
2026-09-30 07:11:20
(5 days ago)
tcp/8080; Unsolicited SYN to a port that has never been offered on this address (closed, no service ...
show more
tcp/8080; Unsolicited SYN to a port that has never been offered on this address (closed, no service ever) @ 2026-09-30T07:10:00Z
show less
Port Scan