Anonymous
2026-09-20 15:32:41
(2 days ago)
35.185.161.106 - - [20/Sep/2026:17:32:36 +0200] "GET /__/firebase/init.json HTTP/1.1" 404 53586
35.1 ...
show more
35.185.161.106 - - [20/Sep/2026:17:32:36 +0200] "GET /__/firebase/init.json HTTP/1.1" 404 53586
35.185.161.106 - - [20/Sep/2026:17:32:36 +0200] "GET /z9x8c7v6b5-debug-trigger-lecontrarien.com HTTP/1.1" 404 53586
35.185.161.106 - - [20/Sep/2026:17:32:36 +0200] "GET /config.json HTTP/1.1" 404 53586
35.185.161.106 - - [20/Sep/2026:17:32:37 +0200] "GET /debug/vars HTTP/1.1" 404 53586
35.185.161.106 - - [20/Sep/2026:17:32:37 +0200] "GET /config.js HTTP/1.1" 404 53586
35.185.161.106 - - [20/Sep/2026:17:32:37 +0200] "GET /info.php HTTP/1.1" 404 53586
35.185.161.106 - - [20/Sep/2026:17:32:38 +0200] "GET /graphql HTTP/1.1" 404 53586
35.185.161.106 - - [20/Sep/2026:17:32:38 +0200] "GET /debug/pprof HTTP/1.1" 404 53586
35.185.161.106 - - [20/Sep/2026:17:32:38 +0200] "GET /swagger.json HTTP/1.1" 404 53586
35.185.161.106 - - [20/Sep/2026:17:32:39 +0200] "GET /env.js HTTP/1.1" 404 53586
...
show less
Web Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 15:10:21
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.185.161.106 (106.161.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.185.161.106 (106.161.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:10:15.999162 2026] [security2:error] [pid 3413:tid 3413] [client 35.185.161.106:35688] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lebarca.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lebarca.com"] [uri "/z9x8c7v6b5-debug-trigger-lebarca.com"] [unique_id "aq_3V8XjgQu3_dvKg1SBtwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:02:10
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.185.161.106 (106.161.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.161.106 (106.161.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:02:06.863657 2026] [security2:error] [pid 8244:tid 8244] [client 35.185.161.106:44786] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "leadinglogan.com"] [uri "/config/.env"] [unique_id "aq_nXgZ3mS_3W_fLdNbZpQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-20 13:47:22
(2 days ago)
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 (compatible; Ama ...
show more
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot) (+6 more) | path: /.aws/config (+13 more) | 2026-09-20 13:47 UTC
show less
Bad Web Bot
Anonymous
2026-09-20 13:35:19
(2 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
IndigoRidge
2026-09-20 13:34:53
(2 days ago)
35.185.161.106 - - [20/Sep/2026:09:34:52 -0400] "GET /config/.env HTTP/1.1" 404 5750 "-" "Mozilla/5. ...
show more
35.185.161.106 - - [20/Sep/2026:09:34:52 -0400] "GET /config/.env HTTP/1.1" 404 5750 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
35.185.161.106 - - [20/Sep/2026:09:34:52 -0400] "GET /.aws/credentials HTTP/1.1" 404 5750 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
35.185.161.106 - - [20/Sep/2026:09:34:53 -0400] "GET /.env HTTP/1.1" 404 5750 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
...
show less
Web App Attack
Anonymous
2026-09-20 13:30:09
(2 days ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:29:32
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.185.161.106 (106.161.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.161.106 (106.161.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:29:26.963101 2026] [security2:error] [pid 1465:tid 1465] [client 35.185.161.106:58886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lahamradio.com"] [uri "/src/.env"] [unique_id "aq_ftvY7xdqeir6hSL2ORgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Mediashaker
2026-09-20 12:50:47
(2 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.185.161.106 (TW/T ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.185.161.106 (TW/Taiwan/106.161.185.35.bc.googleusercontent.com)
show less
Bad Web Bot
๐ช๐ธ
robotstxt
2026-09-20 12:43:43
(2 days ago)
35.185.161.106 - - [20/Sep/2026:12:43:07 +0000] "GET /.env.prod HTTP/2.0" 403 49649 "-" "Mozilla/5.0 ...
show more
35.185.161.106 - - [20/Sep/2026:12:43:07 +0000] "GET /.env.prod HTTP/2.0" 403 49649 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" "-"
35.185.161.106 - - [20/Sep/2026:12:43:10 +0000] "GET /.aws/config HTTP/2.0" 403 49580 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "-"
35.185.161.106 - - [20/Sep/2026:12:43:11 +0000] "GET /.git/config HTTP/2.0" 403 49648 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "-"
35.185.161.106 - - [20/Sep/2026:12:43:11 +0000] "GET /.env HTTP/2.0" 403 49638 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" "-"
35.185.161.106 - - [20/Sep/2026:12:43:11 +0000] "GET /.git/HEAD HTTP/2.0" 403 49646 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "-"
...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-09-20 12:11:37
(2 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
nyt
2026-09-20 12:11:09
(2 days ago)
Sensitive File Probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 12:10:37
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.185.161.106 (106.161.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.161.106 (106.161.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:10:32.805848 2026] [security2:error] [pid 5557:tid 5557] [client 35.185.161.106:49404] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "chandlerowen.com"] [uri "/.env.backup"] [unique_id "aq_NOLRs2gmeAm2ENhilpQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-20 12:07:31
(2 days ago)
35.185.161.106 - - [20/Sep/2026:08:07:31 -0400] "GET /.aws/credentials HTTP/1.1" 403 377 "https://ca ...
show more
35.185.161.106 - - [20/Sep/2026:08:07:31 -0400] "GET /.aws/credentials HTTP/1.1" 403 377 "https://caribbeannewmedia.com/.aws/credentials" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
NoaQT
2026-09-20 11:55:10
(2 days ago)
2026-09-20T11:55:09.925707+00:00 ingress-1 haproxy[16887]: 35.185.161.106:33826 [20/Sep/2026:11:55:0 ...
show more
2026-09-20T11:55:09.925707+00:00 ingress-1 haproxy[16887]: 35.185.161.106:33826 [20/Sep/2026:11:55:09.925] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 58/58/0/0/0 0/0 "GET https://benigarautomocion.com/.bashrc HTTP/2.0"
2026-09-20T11:55:10.113235+00:00 ingress-1 haproxy[16887]: 35.185.161.106:33826 [20/Sep/2026:11:55:10.112] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 58/58/0/0/0 0/0 "POST https://benigarautomocion.com/v1/graphql HTTP/2.0"
2026-09-20T11:55:10.125909+00:00 ingress-1 haproxy[16887]: 35.185.161.106:33826 [20/Sep/2026:11:55:10.125] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 58/58/0/0/0 0/0 "GET https://benigarautomocion.com/.aws/credentials HTTP/2.0"
2026-09-20T11:55:10.126776+00:00 ingress-1 haproxy[16887]: 35.185.161.106:33826 [20/Sep/2026:11:55:10.125] https_in~ https_in/<NOSRV> 0/-1/-1/-1/0 429 225 - - PR-- 58/58/0/0/0 0/0 "GET https://benigarautomocion.com/.aws/config HTTP/2.0"
2026-09-20T11:55:10.168220+00:00 ingress-1 haproxy[
...
show less
DDoS Attack