π¨π·
Klicks
2026-09-21 14:18:00
(6 hours ago)
Request URL: https://app.1.com:443/trace.axd
Request path: /trace.axd
User host addr ...
show more
Request URL: https://app.1.com:443/trace.axd
Request path: /trace.axd
User host address: 35.187.33.205
show less
Bad Web Bot
Web App Attack
Web Spam
Anonymous
2026-09-21 14:12:53
(6 hours ago)
"GET /.aws/config HTTP/1.1"
Hacking
Web App Attack
π³π±
Site.eu
2026-09-21 05:38:17
(14 hours ago)
Excessive multi-domain requests
Brute-Force
πΊπΈ
TPI-Abuse
2026-09-21 04:34:54
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.187.33.205 (205.33.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.33.205 (205.33.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 00:34:49.508723 2026] [security2:error] [pid 18223:tid 18223] [client 35.187.33.205:49186] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.luenwowine.com"] [uri "/@fs/app/.env"] [unique_id "arCz6cg2Yq1pdLISgddVuwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 03:33:20
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.187.33.205 (205.33.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.33.205 (205.33.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:33:13.398992 2026] [security2:error] [pid 3215:tid 3215] [client 35.187.33.205:45156] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.fritsknuf.com"] [uri "/userfiles"] [unique_id "arCleUX-HbTrBLfp81oHQAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπ¬
Cloudkul Cloudkul
2026-09-21 03:24:28
(17 hours ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 03:16:55
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.187.33.205 (205.33.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.33.205 (205.33.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 23:16:51.866069 2026] [security2:error] [pid 21351:tid 21351] [client 35.187.33.205:36666] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "astglobalgroup.com"] [uri "/%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env"] [unique_id "arCho8RtqYquy1PEM0KxrgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-21 02:42:35
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.187.33.205 (205.33.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.33.205 (205.33.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 22:42:30.208583 2026] [security2:error] [pid 18777:tid 18777] [client 35.187.33.205:54230] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.freeformbrush.com"] [uri "/@fs/src/.env"] [unique_id "arCZliQ35yQB8gIBEmSM4wAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 01:34:22
(18 hours ago)
Aggressive web scan
Web App Attack
π©πͺ
Marc
2026-09-21 01:28:13
(19 hours ago)
35.187.33.205 - - [21/Sep/2026:03:28:13 +0200] "GET /.aws/config HTTP/2.0" 404 291 "-" "Mozilla/5.0 ...
show more
35.187.33.205 - - [21/Sep/2026:03:28:13 +0200] "GET /.aws/config HTTP/2.0" 404 291 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" 35.187.33.205 - - [21/Sep/2026:03:28:13 +0200] "GET /.aws/credentials HTTP/2.0" 404 269 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" 35.187.33.205 - - [21/Sep/2026:03:28:13 +0200] "GET /.git/config HTTP/2.0" 404 269 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
show less
Brute-Force
Anonymous
2026-09-21 00:13:58
(20 hours ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-09-21 00:07:17
(20 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-path-traversal-probing
Web App Attack
Hacking
π±π»
garmtech.com
2026-09-20 23:49:16
(20 hours ago)
Attempted access to sensitive endpoint (/id_dsa) detected. Automated scan or unauthorized probing.
Web App Attack
Anonymous
2026-09-20 22:05:05
(22 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 21:56:42
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.187.33.205 (205.33.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.187.33.205 (205.33.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 17:56:37.222789 2026] [security2:error] [pid 25491:tid 25491] [client 35.187.33.205:60678] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||themediaplanet.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "themediaplanet.com"] [uri "/z9x8c7v6b5-debug-trigger-themediaplanet.com"] [unique_id "arBWlc4SQzTXkUYid7DWYgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack