๐ณ๐ฑ
MyGlobalFlowers
2026-09-17 06:19:34
(1 minute ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
Lino Project
2026-09-17 05:49:05
(32 minutes ago)
35.254.70.86 - - [17/Sep/2026:07:49:01 +0200] "GET /.env.production HTTP/2.0" 403 50 "-" "Mozilla/5. ...
show more
35.254.70.86 - - [17/Sep/2026:07:49:01 +0200] "GET /.env.production HTTP/2.0" 403 50 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-17 05:47:13
(33 minutes ago)
20 attempts against mh-misbehave-ban on choy
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
sc user
2026-09-17 05:21:43
(59 minutes ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
๐ณ๐ฑ
Savvii
2026-09-17 05:09:38
(1 hour ago)
20 attempts against mh-misbehave-ban on ethyl
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2026-09-17 05:04:48
(1 hour ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-17 04:48:25
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.254.70.86 (86.70.254.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.254.70.86 (86.70.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 00:48:20.725918 2026] [security2:error] [pid 19574:tid 19574] [client 35.254.70.86:57416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "linguistes.com"] [uri "/chatbot/.env"] [unique_id "aqtxFC6TGth1knmPUGao5wAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-17 04:46:49
(1 hour ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 03:24:06
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.254.70.86 (86.70.254.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.254.70.86 (86.70.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 23:24:00.405923 2026] [security2:error] [pid 31033:tid 31033] [client 35.254.70.86:42278] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jambmaster.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jambmaster.com"] [uri "/rclone.conf"] [unique_id "aqtdULGZgJd7Pujd70IbOAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Phenix Info
2026-09-17 03:14:25
(3 hours ago)
SmallGuard.fr - Forbidden Ext.
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-17 03:00:03
(3 hours ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.254.70.86 - - [17/Sep/2026:04:59:54 +0200] "GET /internal/.env HTTP/2.0" 403 346 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
netclix.gr
2026-09-17 02:50:38
(3 hours ago)
(bot_kill_mega) Aggressive Bot Blocked: Baiduspider 35.254.70.86 (US/United States/86.70.254.35.bc.g ...
show more
(bot_kill_mega) Aggressive Bot Blocked: Baiduspider 35.254.70.86 (US/United States/86.70.254.35.bc.googleusercontent.com): 1 in the last 4600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.254.70.86 - - [17/Sep/2026:05:50:36 +0300] "GET /.github/.env HTTP/2.0" 403 146 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
show less
Port Scan
๐บ๐ธ
H24
2026-09-17 02:35:04
(3 hours ago)
/admin/.env /@fs/home/ubuntu/.aws/credentials /dashboard/.env /@fs/proc/self/cwd/.env /@fs/app/.env ...
show more
/admin/.env /@fs/home/ubuntu/.aws/credentials /dashboard/.env /@fs/proc/self/cwd/.env /@fs/app/.env /static//home/user/.env /config/.env.php /.git/HEAD /laravel/.env /js../.env
show less
Web App Attack
๐ฉ๐ช
netclix.gr
2026-09-17 02:33:57
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.254.70.86 (US/United States/86.70.25 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.254.70.86 (US/United States/86.70.254.35.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐ฌ๐ง
cg-design.co.uk
2026-09-17 02:18:01
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.254.70.86 (US/United States/86.70.25 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.254.70.86 (US/United States/86.70.254.35.bc.googleusercontent.com)
show less
SQL Injection