Anonymous
2026-09-22 01:48:05
(1 day ago)
Unauthorized SSH login attempts
Brute-Force
SSH
๐ฉ๐ช
33three
2026-09-22 01:39:43
(1 day ago)
Fail2Ban jail WebAttack triggered
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-21 23:35:28
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.254.153.239 (239.153.254.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.153.239 (239.153.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:35:22.838478 2026] [security2:error] [pid 7883:tid 7883] [client 35.254.153.239:38396] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.indieheaven.io"] [uri "/docker/.env"] [unique_id "arG_On_AaSrvSiPWl-ViSgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-09-21 21:08:07
(2 days ago)
2026-09-21 23:05:59 GET /.git/HEAD [301] && 2026-09-21 23:05:59 GET /app/.env [301] && 2026-09-21 23 ...
show more
2026-09-21 23:05:59 GET /.git/HEAD [301] && 2026-09-21 23:05:59 GET /app/.env [301] && 2026-09-21 23:05:59 GET /.env [301] && 265 more within 20 minutes
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-21 20:05:25
(2 days ago)
35.254.153.239 - - [21/Sep/2026:20:04:41 +0000] "POST / HTTP/2.0" 403 21818 "-" "Mozilla/5.0 (compat ...
show more
35.254.153.239 - - [21/Sep/2026:20:04:41 +0000] "POST / HTTP/2.0" 403 21818 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" "-" edge="35.254.153.239"
35.254.153.239 - - [21/Sep/2026:20:04:41 +0000] "GET /config.json HTTP/2.0" 403 18848 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "-" edge="35.254.153.239"
35.254.153.239 - - [21/Sep/2026:20:04:41 +0000] "GET /z9x8c7v6b5-debug-trigger-www.im365.io HTTP/2.0" 403 18869 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" "-" edge="35.254.153.239"
35.254.153.239 - - [21/Sep/2026:20:04:41 +0000] "GET /.aws/config HTTP/2.0" 403 18852 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "-" edge="35.254.153.239"
35.254.153.239 - - [21/Sep/2026:20:04:41 +0000] "GET /.aws/credentials HTTP/2.0" 403 18861 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" "-" edge="35.254.15
...
show less
Web App Attack
๐บ๐ธ
Player Unknown
2026-09-21 19:54:02
(2 days ago)
35.254.153.239 - - [21/Sep/2026:12:54:01 -0700] "GET /settings.js HTTP/1.1" 404 153 "-" "Mozilla/5.0 ...
show more
35.254.153.239 - - [21/Sep/2026:12:54:01 -0700] "GET /settings.js HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
35.254.153.239 - - [21/Sep/2026:12:54:01 -0700] "GET /configuration.js HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
35.254.153.239 - - [21/Sep/2026:12:54:01 -0700] "GET /environment.js HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
35.254.153.239 - - [21/Sep/2026:12:54:01 -0700] "GET /credentials.js HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
35.254.153.239 - - [21/Sep/2026:12:54:01 -0700] "GET /config.js HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
35.254.153.239 - - [21/Sep/2026:12:54:01 -0700] "GET /config.json.js HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; cohere-ai; +
...
show less
Brute-Force
SSH
๐ฌ๐ง
consul.to
2026-09-21 18:53:22
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-21 18:37:57
(2 days ago)
Excessive 404/403 errors
Brute-Force
๐ฎ๐น
VHosting
2026-09-21 17:45:03
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-21 15:20:36
(2 days ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ksol-hostmaster
2026-09-21 15:13:29
(2 days ago)
2026/09/21 17:13:28 [error] 24319#897482: *887487 limiting requests, excess: 0.983 by zone "crawler" ...
show more
2026/09/21 17:13:28 [error] 24319#897482: *887487 limiting requests, excess: 0.983 by zone "crawler", client: 35.254.153.239, server: ksol.io, request: "GET /userfiles?path=../../../.env HTTP/2.0", host: "ksol.io"
...
show less
Bad Web Bot
๐ต๐ฑ
mscode.pl
2026-09-21 14:09:14
(2 days ago)
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: MANAGED_CHALLENGE
ASN: 396982 (Goo ...
show more
Triggered Cloudflare WAF (firewallManaged) from US.
Action taken: MANAGED_CHALLENGE
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Zone: s3.selify.io
Endpoint: /functionRouter
UA: Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)
show less
Bad Web Bot
๐ฉ๐ช
LRob
2026-09-21 14:01:34
(2 days ago)
This address is enumerating paths that do not exist on our sites โ asking for scripts, plugins, admi ...
show more
This address is enumerating paths that do not exist on our sites โ asking for scripts, plugins, admin consoles or endpoints the sites never had, one after another. This is vulnerability scanning: looking for something to exploit. Blocked; please check the machine behind it for a scanner or malware. | method: GET (+1 more) | path: /z9x8c7v6b5-debug-trigger-webmail.media-kit.io (+9 more) | ua: Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler) (+8 more) | 2026-09-21 14:01 UTC
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 13:36:38
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.254.153.239 (239.153.254.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.254.153.239 (239.153.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 09:36:35.266539 2026] [security2:error] [pid 31590:tid 31741] [client 35.254.153.239:34014] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.sonatro.io|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.sonatro.io"] [uri "/rclone.conf"] [unique_id "arEy40hJT6ECqOD8hpC7jwAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 13:09:44
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.254.153.239 (239.153.254.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.153.239 (239.153.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 09:09:38.476486 2026] [security2:error] [pid 32348:tid 32348] [client 35.254.153.239:57512] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.meet.evolute.io"] [uri "/@fs/app/.env"] [unique_id "arEsknwWk1nQsVKA9ud0HQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack