๐ฉ๐ช
DyhnenTv
2026-09-24 01:40:39
(15 hours ago)
CrowdSec webserver: crowdsecurity/http-sensitive-files
Web App Attack
Bad Web Bot
๐ฌ๐ง
consul.to
2026-09-23 11:06:45
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-23 09:43:04
(1 day ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
Rocky Mountain Bioengineering Symposium
2026-09-22 08:18:06
(2 days ago)
[Tue Sep 22 02:17:53.224867 2026] [authz_core:error] [pid 2470217:tid 140601601230400] [client 35.24 ...
show more
[Tue Sep 22 02:17:53.224867 2026] [authz_core:error] [pid 2470217:tid 140601601230400] [client 35.240.240.193:50582] AH01630: client denied by server configuration: /var/www/horde/.env.bak
[Tue Sep 22 02:18:06.132424 2026] [authz_core:error] [pid 2470217:tid 140601550874176] [client 35.240.240.193:50582] AH01630: client denied by server configuration: /var/www/horde/.env.dist
[Tue Sep 22 02:18:06.352375 2026] [authz_core:error] [pid 2470217:tid 140601676764736] [client 35.240.240.193:50582] AH01630: client denied by server configuration: /var/www/horde/.env.swp
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 19:20:24
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.240.193 (193.240.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.240.193 (193.240.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:20:17.580215 2026] [security2:error] [pid 1607:tid 1607] [client 35.240.240.193:33512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aticom.net"] [uri "/.git/config"] [unique_id "arGDcQHpdCw0ZsvQKmoNcgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:04:11
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.240.193 (193.240.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.240.193 (193.240.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:04:05.647919 2026] [security2:error] [pid 28716:tid 28716] [client 35.240.240.193:44306] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "athletefirst.org"] [uri "/.git/config"] [unique_id "arFHZXxn-HlPB0hg0x7NFwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 05:24:26
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฉ๐ช
seal
2026-09-16 05:20:28
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
SSH
Brute-Force
๐ท๐ด
clauss
2026-09-15 23:30:45
(1 week ago)
35.240.240.193 - - [16/Sep/2026:02:29:24 +0300] "GET /.git/config HTTP/1.1" 200 314 "-" "Mozilla/5.0 ...
show more
35.240.240.193 - - [16/Sep/2026:02:29:24 +0300] "GET /.git/config HTTP/1.1" 200 314 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
35.240.240.193 - - [16/Sep/2026:02:29:24 +0300] "GET /.env.local HTTP/1.1" 200 314 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Web App Attack
๐น๐ท
ayayntr
2026-09-15 22:12:40
(1 week ago)
[Wed Sep 16 01:12:38.021963 2026] [proxy_fcgi:error] [pid 25480:tid 25635] [client 35.240.240.193:49 ...
show more
[Wed Sep 16 01:12:38.021963 2026] [proxy_fcgi:error] [pid 25480:tid 25635] [client 35.240.240.193:49864] AH01071: Got error 'Primary script unknown'
[Wed Sep 16 01:12:38.232927 2026] [proxy_fcgi:error] [pid 25480:tid 25638] [client 35.240.240.193:49864] AH01071: Got error 'Primary script unknown'
[Wed Sep 16 01:12:38.443144 2026] [proxy_fcgi:error] [pid 25480:tid 25643] [client 35.240.240.193:49864] AH01071: Got error 'Primary script unknown'
[Wed Sep 16 01:12:38.652707 2026] [proxy_fcgi:error] [pid 25480:tid 25645] [client 35.240.240.193:49864] AH01071: Got error 'Primary script unknown'
[Wed Sep 16 01:12:38.862504 2026] [proxy_fcgi:error] [pid 25480:tid 25646] [client 35.240.240.193:49864] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
SSH
๐ช๐ธ
pipeline.es
2026-09-15 21:37:35
(1 week ago)
Web scanning / probing for vulnerable paths | URL: /api/v2/.env | Evidence: 35.240.240.193 - - [15/S ...
show more
Web scanning / probing for vulnerable paths | URL: /api/v2/.env | Evidence: 35.240.240.193 - - [15/Sep/2026:23:36:25 +0200] \"GET /api/v2/.env HTTP/1.1\" 404 43676 \"-\" \"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36\" GEOIP_COUNTRY_CODE=SG | ASN: GOOGLE-CLOUD-PLATFORM | Country: SG
show less
Port Scan
Web App Attack
๐บ๐ธ
alecj.com
2026-09-15 20:53:22
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/appsec-vpatch
Web App Attack
๐ฎ๐น
Inartis
2026-09-15 20:02:08
(1 week ago)
35.240.240.193 - - [15/Sep/2026:22:02:07 +0200] "GET /.git/config HTTP/1.1" 403 179 "-" "Mozilla/5.0 ...
show more
35.240.240.193 - - [15/Sep/2026:22:02:07 +0200] "GET /.git/config HTTP/1.1" 403 179 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-15 18:31:31
(1 week ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-15 17:28:25
(1 week ago)
(modsecurity) srv103 ModSecurity 35.240.240.193 (SG/Singapore/193.240.240.35.bc.googleusercontent.co ...
show more
(modsecurity) srv103 ModSecurity 35.240.240.193 (SG/Singapore/193.240.240.35.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack