๐ฉ๐ช
ghostwarriors
2026-09-11 18:20:21
(2 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-11 18:18:37
(2 hours ago)
35.185.2.46 - - [11/Sep/2026:20:18:33 +0200] "GET /runtime-config.js HTTP/2.0" 404 295 "-" "Mozilla/ ...
show more
35.185.2.46 - - [11/Sep/2026:20:18:33 +0200] "GET /runtime-config.js HTTP/2.0" 404 295 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
35.185.2.46 - - [11/Sep/2026:20:18:33 +0200] "GET /terraform.tfstate HTTP/2.0" 404 295 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
35.185.2.46 - - [11/Sep/2026:20:18:33 +0200] "GET /.ssh/id_rsa HTTP/2.0" 404 295 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
35.185.2.46 - - [11/Sep/2026:20:18:33 +0200] "GET /openapi.json HTTP/2.0" 404 295 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
35.185.2.46 - - [11/Sep/2026:20:18:33 +0200] "GET /docker-compose.yaml HTTP/2.0" 404 295 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
35.185.2.46 - - [11/Sep/2026:20:18:33 +0200] "GET /api/openapi.json HTTP/2.0" 404 295 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
35.185.2.46 - - [11/Sep/2
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-11 18:08:24
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.2.46 (46.2.185.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.2.46 (46.2.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 14:08:17.518720 2026] [security2:error] [pid 2511573:tid 2511593] [client 35.185.2.46:35194] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "theaquifer.org"] [uri "/@fs/.env"] [unique_id "aqRDkZ9_LDr2u9C1XsWdiAAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-11 18:04:59
(2 hours ago)
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 (compatible; Byt ...
show more
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36 | path: /.env.local (+3 more) | 2026-09-11 18:04 UTC
show less
Bad Web Bot
๐ฎ๐น
CoreTech srl
2026-09-11 17:58:56
(2 hours ago)
cloudlinux2 fail2ban: 2026-09-11 19:53:43,904 fail2ban.filter [1606]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-11 19:53:43,904 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 217.160.25.237 - 2026-09-11 19:53:43cloudlinux2 fail2ban: 2026-09-11 19:53:55,222 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 35.185.2.46 - 2026-09-11 19:53:55cloudlinux2 fail2ban: 2026-09-11 19:53:55,315 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 35.185.2.46 - 2026-09-11 19:53:55cloudlinux2 fail2ban: 2026-09-11 19:53:55,234 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 35.185.2.46 - 2026-09-11 19:53:55cloudlinux2 fail2ban: 2026-09-11 19:53:55,485 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 35.185.2.46 - 2026-09-11 19:53:55cloudlinux2 fail2ban: 2026-09-11 19:53:55,199 fail2ban.filter [1606]: INFO [plesk-modsecurity] Found 35.185.2.46 - 2026-09-11 19:53:55cloudlinux2 fail2ban: 2026-09-11 19:53:55,573 fail2ban.filter [1606]: INFO [recidive] Found 35.185.2.46 - 2026-09-11 19:53:55cloudlinux2 fai
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 17:50:24
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.185.2.46 (46.2.185.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 35.185.2.46 (46.2.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:50:16.587379 2026] [security2:error] [pid 15774:tid 15774] [client 35.185.2.46:41600] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||templeantiques.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "templeantiques.org"] [uri "/rclone.conf"] [unique_id "aqQ_WOTRoA9g3bHWPXOvlgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
melroy89
2026-09-11 17:41:42
(2 hours ago)
35.185.2.46 - - [11/Sep/2026:19:41:39 +0200] "GET /assets/manifest.json HTTP/2.0" 403 64 "-" "Mozil ...
show more
35.185.2.46 - - [11/Sep/2026:19:41:39 +0200] "GET /assets/manifest.json HTTP/2.0" 403 64 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "techwiki.org" 0.000
35.185.2.46 - - [11/Sep/2026:19:41:39 +0200] "GET /environment.js HTTP/2.0" 403 93 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" "techwiki.org" 0.000
35.185.2.46 - - [11/Sep/2026:19:41:39 +0200] "GET /actuator HTTP/2.0" 403 93 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "techwiki.org" 0.000
35.185.2.46 - - [11/Sep/2026:19:41:39 +0200] "GET /actuator/configprops HTTP/2.0" 403 512 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" "techwiki.org" 0.003
35.185.2.46 - - [11/Sep/2026:19:41:39 +0200] "GET /wp-json HTTP/2.0" 403 512 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" "techwiki.org" 0.001
35.185.2.46 - - [11/Sep/
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 17:31:47
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.2.46 (46.2.185.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.2.46 (46.2.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 13:31:40.896730 2026] [security2:error] [pid 31335:tid 31335] [client 35.185.2.46:38588] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tcmu.org"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqQ6_HVOzG_JqOvZ02wjeQAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-11 17:02:13
(3 hours ago)
Multiple WAF Violations
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-11 16:50:02
(3 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
Anonymous
2026-09-11 16:49:07
(3 hours ago)
35.185.2.46 - - [11/Sep/2026:18:49:05 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 1 ...
show more
35.185.2.46 - - [11/Sep/2026:18:49:05 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
35.185.2.46 - - [11/Sep/2026:18:49:05 +0200] "GET /api%2F.env HTTP/1.1" 403 124 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
35.185.2.46 - - [11/Sep/2026:18:49:06 +0200] "GET /user/login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
35.185.2.46 - - [11/Sep/2026:18:49:06 +0200] "GET /reset-password HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
35.185.2.46 - - [11/Sep/2026:18:49:06 +0200] "GET /register HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
35.185.2.46 - - [11/Sep/2026:18:49:06 +0200] "GET /forgot-pa
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-11 16:25:23
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.2.46 (46.2.185.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.2.46 (46.2.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 12:25:20.034434 2026] [security2:error] [pid 20904:tid 20904] [client 35.185.2.46:47984] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sullstars.org"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqQrcC06s33-6UT30LawugAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-11 16:20:03
(4 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-11 16:19:07
(4 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-11 16:17:19
(4 hours ago)
Web attack/malicious scanning detected
Web App Attack