๐จ๐ฆ
zXero
2026-09-23 12:41:57
(3 hours ago)
Fail2Ban automatic report - jail: recidive
Brute-Force
SSH
DDoS Attack
Anonymous
2026-09-23 10:28:25
(5 hours ago)
35.240.242.202 - - [22/Sep/2026:09:54:52 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "Mozilla/5.0 Ap ...
show more
35.240.242.202 - - [22/Sep/2026:09:54:52 -0500] "GET /.env.old HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" 35.240.242.202
35.240.242.202 - - [22/Sep/2026:09:54:52 -0500] "GET /.env.save HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" 35.240.242.202
35.240.242.202 - - [22/Sep/2026:09:54:52 -0500] "GET /.env.prod HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" 35.240.242.202
35.240.242.202 - - [22/Sep/2026:09:54:52 -0500] "GET /.env.bak HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" 35.240.242.202
35.240.242.202 - - [22/Sep/2026:09:54:53 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" 35.240.242.202
35.240.242.202 - - [22/Sep/2026:09:54:56 -0500] "GET
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐น
penguin-solutions.at
2026-09-23 03:37:06
(12 hours ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-23 02:39:45
(13 hours ago)
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.240.242.202 - - [23/Sep/2026:04:39:24 +0200] "GET /.env.prod HTTP/2.0" 301 398 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 02:00:17
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.242.202 (202.242.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.242.202 (202.242.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 22:00:11.299181 2026] [security2:error] [pid 24547:tid 24547] [client 35.240.242.202:35798] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.sovereignstartups.com|F|2"] [data ".sovereignstartups.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.sovereignstartups.com"] [uri "/z9x8c7v6b5-debug-trigger-www.sovereignstartups.com"] [unique_id "arMyq7vuQkhXCYSet2Nd-wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-22 22:25:27
(17 hours ago)
Brute-Force
Web App Attack
๐บ๐ธ
robotstxt
2026-09-22 22:24:48
(17 hours ago)
35.240.242.202 - - [22/Sep/2026:22:23:48 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 17352 " ...
show more
35.240.242.202 - - [22/Sep/2026:22:23:48 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 17352 "https://www.internationalcannabisawards.com/dist/.vite/manifest.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.240.242.202"
35.240.242.202 - - [22/Sep/2026:22:23:50 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/2.0" 403 17815 "https://www.internationalcannabisawards.com/@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw??" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" edge="35.240.242.202"
35.240.242.202 - - [22/Sep/2026:22:23:50 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/2.0" 403 17815 "https://www.internationalcannabisawards.com/@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw??" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" "-" edge="35.240.242.202"
...
show less
Web App Attack
๐ฉ๐ช
updown.io
2026-09-22 20:33:33
(19 hours ago)
{"level":"info","ts":1790109205.4524677,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790109205.4524677,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.240.242.202","remote_port":"35960","client_ip":"35.240.242.202","proto":"HTTP/2.0","method":"POST","host":"www-status.retailreload.com","uri":"/api/v1/validate/code","headers":{"Content-Length":["166"],"Accept-Encoding":["gzip"],"Content-Type":["application/json"],"User-Agent":["Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"],"Cookie":["REDACTED"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"www-status.retailreload.com","ech":false}},"bytes_read":0,"user_id":"","duration":0.000166779,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1790109205.453409,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.240.242.202","remote_port":"35960","client_ip":"35.240.242.202","proto":"HTTP/2.0","metho
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
oralunal
2026-09-22 20:19:51
(19 hours ago)
IP banned by Fail2Ban in jail ah-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐ฉ๐ช
TheDjRider
2026-09-22 19:19:11
(20 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-22T19:19:05.350079741Z. Context: http_status=301, http_status=200
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-22 19:14:28
(20 hours ago)
35.240.242.202 - - [22/Sep/2026:19:14:12 +0000] "GET / HTTP/2.0" 403 30630 "https://fireflycomms.com ...
show more
35.240.242.202 - - [22/Sep/2026:19:14:12 +0000] "GET / HTTP/2.0" 403 30630 "https://fireflycomms.com/" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "-" edge="35.240.242.202"
35.240.242.202 - - [22/Sep/2026:19:14:15 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 2 "https://fireflycomms.com/.vite/manifest.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" "-" edge="35.240.242.202"
35.240.242.202 - - [22/Sep/2026:19:14:16 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 2 "https://fireflycomms.com/dist/.vite/manifest.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36" "-" edge="35.240.242.202"
35.240.242.202 - - [22/Sep/2026:19:14:17 +0000] "GET /wp-content/plugins/stop-user-enumeration/frontend/js/frontend.js?ver=1.7.8 HTTP/2.0" 403 2 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML,
...
show less
Web App Attack
๐บ๐ธ
robotstxt
2026-09-22 18:49:43
(21 hours ago)
35.240.242.202 - - [22/Sep/2026:18:48:39 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 17352 " ...
show more
35.240.242.202 - - [22/Sep/2026:18:48:39 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 17352 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.240.242.202"
35.240.242.202 - - [22/Sep/2026:18:48:40 +0000] "GET /.env.prod HTTP/2.0" 403 17815 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "-" edge="35.240.242.202"
35.240.242.202 - - [22/Sep/2026:18:48:41 +0000] "GET /.env.save HTTP/2.0" 403 17815 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "-" edge="35.240.242.202"
35.240.242.202 - - [22/Sep/2026:18:48:41 +0000] "GET /admin/.env HTTP/2.0" 403 17815 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "-" edge="35.240.242.202"
35.240.242.202 - - [22/Sep/2026:18:48:41 +0000] "GET /api/.env HTTP/2.0" 403 17815 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ฉ๐ช
IVski.com
2026-09-22 18:46:21
(21 hours ago)
IVski WAF | Next.js Server Action probe
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:45:03
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.242.202 (202.242.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.242.202 (202.242.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:44:58.475236 2026] [security2:error] [pid 28626:tid 28630] [client 35.240.242.202:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||raytbrown.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "raytbrown.com"] [uri "/z9x8c7v6b5-debug-trigger-raytbrown.com"] [unique_id "arK-mmTn39H8zON2YPF7JwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:23:18
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.242.202 (202.242.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.242.202 (202.242.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:23:15.380921 2026] [security2:error] [pid 18563:tid 18563] [client 35.240.242.202:44772] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sophcomp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sophcomp.com"] [uri "/z9x8c7v6b5-debug-trigger-sophcomp.com"] [unique_id "arK5gy9oWlXEZPLKDZoaGwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack