Anonymous
2026-09-14 11:28:14
(13 hours ago)
Web App Attack
Brute-Force
Web App Attack
🇮🇳
evicky2002
2026-09-14 06:00:01
(19 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-09-14 04:07:21
(20 hours ago)
35.185.235.161 - - [13/Sep/2026:23:07:19 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (c ...
show more
35.185.235.161 - - [13/Sep/2026:23:07:19 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" 35.185.235.161
35.185.235.161 - - [13/Sep/2026:23:07:19 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 35.185.235.161
35.185.235.161 - - [13/Sep/2026:23:07:19 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" 35.185.235.161
35.185.235.161 - - [13/Sep/2026:23:07:19 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)" 35.185.235.161
35.185.235.161 - - [13/Sep/2026:23:07:19 -0500] "GET /.env.production?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" 35.185.235.161
35.185.235.161 - - [13/Sep/202
...
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
Secure Gateway®️
2026-09-13 22:00:27
(1 day ago)
Report By Secure Gateway Security Team: Unsolicited Connection Attempt
Hacking
🇺🇸
ALSCO®️
2026-09-13 22:00:27
(1 day ago)
Report By ALSCO Security Team: Unauthorized Connection Attempt
Hacking
🇺🇸
JustMeHere
2026-09-13 18:34:12
(1 day ago)
[Sun Sep 13 14:34:07.574457 2026] [security2:error] [pid 60574:tid 60687] [client 35.185.235.161:364 ...
show more
[Sun Sep 13 14:34:07.574457 2026] [security2:error] [pid 60574:tid 60687] [client 35.185.235.161:36442] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "yorknation.com"] [uri "/"] [unique_id "aqbsn0loe64f4voy_aREggAAAIg"]
...
show less
Web App Attack
Anonymous
2026-09-13 18:07:05
(1 day ago)
Automated web scanner. Requested suspicious paths: /.vite/manifest.json | /dist/manifest.json | /z9x ...
show more
Automated web scanner. Requested suspicious paths: /.vite/manifest.json | /dist/manifest.json | /z9x8c7v6b5-debug-trigger-tigzig.com | /dist/.vite/manifest.json | /rclone.conf | /.zshrc | /build/manifest.json | /wp-json | /.bashrc. UTC: 2026-09-13 18:06:25.
show less
Web App Attack
🇺🇸
creechy
2026-09-13 17:41:59
(1 day ago)
35.185.235.161 - - [13/Sep/2026:10:41:54 -0700] "GET /__vite_rsc_findSourceMapURL?filename=file:///r ...
show more
35.185.235.161 - - [13/Sep/2026:10:41:54 -0700] "GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/1.1" 404 779 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
...
show less
Hacking
Bad Web Bot
🇲🇾
Rizzy
2026-09-13 17:38:49
(1 day ago)
Multiple WAF Violations
Brute-Force
Web App Attack
🇺🇸
its101
2026-09-13 15:30:10
(1 day ago)
Automated detection by LockdownAccess security system. Attack type(s): rce, env_grab, config_probe, ...
show more
Automated detection by LockdownAccess security system. Attack type(s): rce, env_grab, config_probe, framework_probe, git_exposure. Reason: Nginx: rce attack. Path targeted: unknown. Blocked in Cloudflare.
show less
Exploited Host
Web App Attack
Anonymous
2026-09-13 15:28:13
(1 day ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 15:01:51
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.185.235.161 (161.235.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.185.235.161 (161.235.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 11:01:46.209903 2026] [security2:error] [pid 19998:tid 19998] [client 35.185.235.161:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||local639.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "local639.com"] [uri "/z9x8c7v6b5-debug-trigger-local639.com"] [unique_id "aqa62m_0L8bRguSln4pENgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇴
clauss
2026-09-13 15:01:00
(1 day ago)
35.185.235.161 - - [13/Sep/2026:18:00:58 +0300] "GET /.git/HEAD HTTP/2.0" 404 21351 "-" "Mozilla/5.0 ...
show more
35.185.235.161 - - [13/Sep/2026:18:00:58 +0300] "GET /.git/HEAD HTTP/2.0" 404 21351 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
35.185.235.161 - - [13/Sep/2026:18:00:59 +0300] "GET /.aws/credentials HTTP/2.0" 404 21352 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
...
show less
Web App Attack
🇫🇷
dynamix
2026-09-13 15:00:52
(1 day ago)
Multiple WAF Violations
Web App Attack
🇫🇷
masterguru
2026-09-13 14:17:22
(1 day ago)
OS File Access Attempt. Matched phrase ".ssh/id_rsa" at ARGS:filename. (930120-135)
Hacking