🇩🇪
Gwyneth Llewelyn
2026-09-07 00:51:54
(3 hours ago)
35.190.207.134 - - [07/Sep/2026:01:51:51 +0100] "GET /.env HTTP/2.0" 301 162 "-" "Mozilla/5.0 (Macin ...
show more
35.190.207.134 - - [07/Sep/2026:01:51:51 +0100] "GET /.env HTTP/2.0" 301 162 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
2026/09/07 01:51:52 [error] 380594#380594: *3354498 access forbidden by rule, client: 35.190.207.134, server: zonadetestes.com, request: "GET /.env HTTP/2.0", host: "zonadetestes.com", referrer: "https://www.zonadetestes.com/.env"
35.190.207.134 - - [07/Sep/2026:01:51:52 +0100] "GET /.env HTTP/2.0" 403 1045 "https://www.zonadetestes.com/.env" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
show less
Brute-Force
Web App Attack
🇫🇮
Shaik Sai Meera
2026-09-07 00:20:12
(4 hours ago)
IM360 WAF: Hidden file access
Brute-Force
🇧🇪
cmbplf
2026-09-06 23:07:19
(5 hours ago)
2.341 requests from abuseipdb.com blacklisted IP (1yr5mos2w)
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 22:41:19
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.190.207.134 (134.207.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.190.207.134 (134.207.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:41:14.318498 2026] [security2:error] [pid 8022:tid 8022] [client 35.190.207.134:37302] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||varnadorefamily.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "varnadorefamily.com"] [uri "/z9x8c7v6b5-debug-trigger-varnadorefamily.com"] [unique_id "ap3sCv7IomJtZYnDcX0xIgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
maxxsense
2026-09-06 22:37:12
(6 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.190.207.134 (BE/Belgium/134.207.190. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.190.207.134 (BE/Belgium/134.207.190.35.bc.googleusercontent.com)
show less
SQL Injection
🇷🇴
clauss
2026-09-06 22:24:39
(6 hours ago)
35.190.207.134 - - [07/Sep/2026:01:24:38 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 ...
show more
35.190.207.134 - - [07/Sep/2026:01:24:38 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
35.190.207.134 - - [07/Sep/2026:01:24:39 +0300] "GET /.aws/config HTTP/2.0" 404 12212 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
...
show less
Web App Attack
🇳🇱
Site.eu
2026-09-06 22:20:23
(6 hours ago)
Excessive multi-domain requests
Brute-Force
🇳🇱
homeshowdomain.nl
2026-09-06 22:02:07
(6 hours ago)
Auto-ban: >3000 req/min op 2026-09-06
Web App Attack
SSH
Hacking
🇧🇬
HighWay
2026-09-06 21:40:08
(7 hours ago)
35.190.207.134 - - [06/Sep/2026:21:40:04 +0000] "GET /terraform.tfstate HTTP/1.1" 404 624 "-" "Mozil ...
show more
35.190.207.134 - - [06/Sep/2026:21:40:04 +0000] "GET /terraform.tfstate HTTP/1.1" 404 624 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
35.190.207.134 - - [06/Sep/2026:21:40:04 +0000] "GET /docker-compose.yaml HTTP/1.1" 404 5718 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
35.190.207.134 - - [06/Sep/2026:21:40:04 +0000] "GET /secrets.env HTTP/1.1" 404 5718 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
35.190.207.134 - - [06/Sep/2026:21:40:04 +0000] "GET /z9x8c7v6b5-debug-trigger-webmail.vhelectronics.com HTTP/1.1" 404 5718 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
35.190.207.134 - - [06/Sep/2026:21:40:04 +0000] "GET /serverless.yml HTTP/1.1" 404 5718 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
35.190.207.134 - - [06/Sep/2026:21:40:04 +0000] "POST /graphql HTTP/1.1" 404 7
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 21:16:20
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.190.207.134 (134.207.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.190.207.134 (134.207.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:16:16.084732 2026] [security2:error] [pid 25881:tid 25881] [client 35.190.207.134:41806] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||w360.mx|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "w360.mx"] [uri "/server.key"] [unique_id "ap3YIKGkX1YC7yrpurcVnAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 20:27:13
(8 hours ago)
Portscan: TCP/8443 (3x), TCP/8080 (3x)
Port Scan
🇦🇺
AWW-Admin
2026-09-06 20:10:05
(8 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.190.207.134 (BE/Belgium/134.207.190. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.190.207.134 (BE/Belgium/134.207.190.35.bc.googleusercontent.com)
show less
SQL Injection
🇩🇪
rh24
2026-09-06 18:42:55
(10 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.190.207.134 (BE/B ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.190.207.134 (BE/Belgium/134.207.190.35.bc.googleusercontent.com)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-06 17:55:30
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.190.207.134 (134.207.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.207.134 (134.207.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 13:55:22.108996 2026] [security2:error] [pid 15435:tid 15435] [client 35.190.207.134:37108] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.verdeprofundo.net"] [uri "/.git/config"] [unique_id "ap2pCsA7CiGiel5WgeD3hQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 17:34:34
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.190.207.134 (134.207.190.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.190.207.134 (134.207.190.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 13:34:27.703027 2026] [security2:error] [pid 21954:tid 21954] [client 35.190.207.134:47902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.zydecajun.radio.fm"] [uri "/img../.env"] [unique_id "ap2kIzMbv3RFC3Zb2oy7kAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack