๐ฆ๐บ
CalmBrain
2026-10-03 16:01:05
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-02 15:19:56
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.245.176.194 (194.176.245.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.176.194 (194.176.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 11:19:51.829296 2026] [security2:error] [pid 29172:tid 29172] [client 35.245.176.194:60030] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.rentaroller.com.au"] [uri "/storage/.env"] [unique_id "ar_Ll9dnFYGhNdI9nZlWNgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-10-02 14:33:53
(3 days ago)
{"level":"info","ts":1790951630.8404071,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790951630.8404071,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.245.176.194","remote_port":"54364","client_ip":"35.245.176.194","proto":"HTTP/2.0","method":"GET","host":"status.chromatix.com.au","uri":"/0u8plikn7h771gn2b14l","headers":{"Cookie":["REDACTED"],"Accept-Encoding":["gzip"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"],"Accept":["*/*"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"status.chromatix.com.au","ech":false}},"bytes_read":0,"user_id":"","duration":0.000111062,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1790951630.84068,"logger":
...
show less
DDoS Attack
Web App Attack
๐ฌ๐ง
consul.to
2026-10-02 13:18:36
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-10-02 12:47:57
(3 days ago)
[Fri Oct 02 22:47:57.198480 2026] [security2:error] [pid 653863] [client 35.245.176.194:48454] [clie ...
show more
[Fri Oct 02 22:47:57.198480 2026] [security2:error] [pid 653863] [client 35.245.176.194:48454] [client 35.245.176.194] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 30)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "balcomberetreat.com.au"] [uri "/userfiles"] [unique_id "ar-n_ShyiTPZ7Kb6cW1QjwAAAA0"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 11:35:03
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.245.176.194 (194.176.245.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.176.194 (194.176.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:34:54.547120 2026] [security2:error] [pid 27192:tid 27192] [client 35.245.176.194:44120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ashtangayogamelbourne.com.au"] [uri "/public../.env"] [unique_id "ar-W3owyBzK6NKL7g64_WQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
rubixstudios
2026-10-02 10:23:05
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฆ๐บ
paulshipley.com.au
2026-10-02 09:56:48
(3 days ago)
[Fri Oct 02 19:56:48.012186 2026] [security2:error] [pid 640053] [client 35.245.176.194:41668] [clie ...
show more
[Fri Oct 02 19:56:48.012186 2026] [security2:error] [pid 640053] [client 35.245.176.194:41668] [client 35.245.176.194] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "levellagiftware.com.au"] [uri "/media../.env"] [unique_id "ar9_4Lrl2D34qqQ338ARMQAAAAs"]
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 09:03:37
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.245.176.194 (194.176.245.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.176.194 (194.176.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 05:03:30.072342 2026] [security2:error] [pid 16950:tid 16950] [client 35.245.176.194:39946] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.comsew.com.au"] [uri "/%2e%2e/.env"] [unique_id "ar9zYoxC-HwuEslI5wunygAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 08:54:48
(3 days ago)
Aggressive web scan
Web App Attack
๐ธ๐ฌ
simpeg-adm.bandung.go.id
2026-10-02 08:22:52
(3 days ago)
02/Oct/2026:08:22:51 +0000;35.245.176.194;"/model/info"
02/Oct/2026:08:22:51 +0000;35.245.176.194;"/ ...
show more
02/Oct/2026:08:22:51 +0000;35.245.176.194;"/model/info"
02/Oct/2026:08:22:51 +0000;35.245.176.194;"/q52io3nyjwktxral8ixz"
02/Oct/2026:08:22:51 +0000;35.245.176.194;"/dist/.vite/manifest.json"
02/Oct/2026:08:22:51 +0000;35.245.176.194;"/dist/manifest.json"
02/Oct/2026:08:22:51 +0000;35.245.176.194;"/.vite/manifest.json"
02/Oct/2026:08:22:51 +0000;35.245.176.194;"/c9e3p2ljnhh2xas4r349"
02/Oct/2026:08:22:51 +0000;35.245.176.194;"/z9x8c7v6b5-debug-trigger-vendors.bottlebrushfilms.com.au"
...
show less
Web Spam
Brute-Force
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-10-02 07:29:44
(3 days ago)
[Fri Oct 02 17:29:43.884238 2026] [security2:error] [pid 581018] [client 35.245.176.194:59300] [clie ...
show more
[Fri Oct 02 17:29:43.884238 2026] [security2:error] [pid 581018] [client 35.245.176.194:59300] [client 35.245.176.194] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "bermanfamily.com.au"] [uri "/"] [unique_id "ar9dZ6u7xOKrRW_KfD6K9QAAAAU"]
...
show less
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-10-02 07:27:16
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐ฆ๐บ
screwlooseit.com.au
2026-10-02 07:21:16
(3 days ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/194.176.245.35.bc.googleuserconte ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/194.176.245.35.bc.googleusercontent.com
show less
Web App Attack
๐ฆ๐บ
artful
2026-10-02 07:11:00
(3 days ago)
Excessive errors ~2.3k in recent hours
Web App Attack