๐ณ๐ฑ
Site.eu
2026-09-17 05:24:41
(2 hours ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
YF
2026-09-17 05:15:31
(2 hours ago)
Distributed subnet attack โ coordinated scanning from multiple IPs in the same /24
DDoS Attack
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-17 05:02:52
(2 hours ago)
[ti-02ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.241.92.167 - - [17/Sep/2026:07:02:49 +0200] "GET /.git/config HTTP/1.1" 301 613 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-17 03:26:28
(4 hours ago)
Excessive 404/403 errors
Brute-Force
๐ฉ๐ช
jack252
2026-09-17 03:20:52
(4 hours ago)
2026/09/17 05:20:50 [error] 1262#1262: *117488 open() "/etc/nginx/html/mailer/.env" failed (2: No su ...
show more
2026/09/17 05:20:50 [error] 1262#1262: *117488 open() "/etc/nginx/html/mailer/.env" failed (2: No such file or directory), client: 35.241.92.167, server: smarthomeklar.de, request: "GET /mailer/.env HTTP/1.1", host: "www.smarthomeklar.de"
2026/09/17 05:20:50 [error] 1262#1262: *117488 open() "/etc/nginx/html/mail/.env" failed (2: No such file or directory), client: 35.241.92.167, server: smarthomeklar.de, request: "GET /mail/.env HTTP/1.1", host: "www.smarthomeklar.de"
2026/09/17 05:20:51 [error] 1262#1262: *117488 open() "/etc/nginx/html/mailing/.env" failed (2: No such file or directory), client: 35.241.92.167, server: smarthomeklar.de, request: "GET /mailing/.env HTTP/1.1", host: "www.smarthomeklar.de"
...
show less
Brute-Force
Bad Web Bot
๐ธ๐ช
vaia.cloud
2026-09-17 02:15:03
(5 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐บ๐ธ
rdpguard.com
2026-09-17 00:00:13
(7 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
๐ณ๐ฑ
homeshowdomain.nl
2026-09-16 22:02:07
(9 hours ago)
Auto-ban: >3000 req/min op 2026-09-16
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-16 18:30:44
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.241.92.167 (167.92.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.92.167 (167.92.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 14:30:38.042064 2026] [security2:error] [pid 8395:tid 8395] [client 35.241.92.167:55970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.sandboarding.infojeffreysbay.com"] [uri "/.git/config"] [unique_id "aqrgTrNqjnj9UmBadN-eHQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Greg Poulson
2026-09-16 17:15:20
(14 hours ago)
Our website was hit by this DDOS at a rate of 62 in 5 minutes.
DDoS Attack
Web Spam
Brute-Force
๐ณ๐ฑ
ConsulHosting
2026-09-16 16:10:31
(15 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-16 16:10:01
(15 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐ณ๐ฑ
SchorelWeb
2026-09-16 16:09:43
(15 hours ago)
Cluster member (Omitted) (FR/France/-) said, TEMPDENY 35.241.92.167, Reason:[(Suspicious403) Suspici ...
show more
Cluster member (Omitted) (FR/France/-) said, TEMPDENY 35.241.92.167, Reason:[(Suspicious403) Suspicious activity detected 35.241.92.167 (HK/Hong Kong/167.92.241.35.bc.googleusercontent.com): 2 in the last 3600 secs]
show less
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-16 16:09:01
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.241.92.167 (167.92.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.241.92.167 (167.92.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 12:08:58.282284 2026] [security2:error] [pid 6249:tid 6249] [client 35.241.92.167:50554] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.samelsner.com|F|2"] [data ".env.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.samelsner.com"] [uri "/.env.bak"] [unique_id "aqq_GumNBG1qirVKHjoT2gAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 15:58:36
(15 hours ago)
35.241.92.167 - - [16/Sep/2026:10:58:34 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Window ...
show more
35.241.92.167 - - [16/Sep/2026:10:58:34 -0500] "GET /.env HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 162.158.193.108
35.241.92.167 - - [16/Sep/2026:10:58:34 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 162.158.193.108
35.241.92.167 - - [16/Sep/2026:10:58:34 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 162.158.193.108
35.241.92.167 - - [16/Sep/2026:10:58:34 -0500] "GET /.env.staging HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" 162.158.193.49
35.241.92.167 - - [16/Sep/2026:10:58:34 -0500] "GET /.env.development HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) A
...
show less
Brute-Force
Bad Web Bot
Web App Attack