๐ฉ๐ช
klaus_ph
2026-09-23 16:44:17
(4 days ago)
2026-09-23 02:18:03,808 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 35.193.126.32
.. ...
show more
2026-09-23 02:18:03,808 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 35.193.126.32
...
show less
Bad Web Bot
๐ฉ๐ช
konseptit
2026-09-20 14:58:47
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 35.193.126.32 (US/United States/32.126. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.193.126.32 (US/United States/32.126.193.35.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-20 14:50:45
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.193.126.32 (32.126.193.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.193.126.32 (32.126.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:50:37.150895 2026] [security2:error] [pid 28788:tid 28788] [client 35.193.126.32:47268] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||intergeovial.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "intergeovial.com"] [uri "/z9x8c7v6b5-debug-trigger-intergeovial.com"] [unique_id "aq_yvUSm90_lBzvV3wC0iAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-20 14:36:19
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
interbiznw.com
2026-09-20 14:35:05
(1 week ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:31:42
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.193.126.32 (32.126.193.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.193.126.32 (32.126.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:31:38.368641 2026] [security2:error] [pid 25551:tid 25551] [client 35.193.126.32:42640] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||garyrankin.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "garyrankin.com"] [uri "/rclone.conf"] [unique_id "aq_uSj8eLCAH8Ut4VRzDgAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 14:30:04
(1 week ago)
CrowdSec decision: crowdsecurity/http-bad-user-agent (origin: crowdsec)
Port Scan
Anonymous
2026-09-20 14:15:05
(1 week ago)
$f2bV_matches
Brute-Force
Web App Attack
๐ซ๐ท
ecode hosting
2026-09-20 14:14:05
(1 week ago)
Domain : ecodehost.com
Rule : env
2026-09-20 14:11:46 10.100.1.20 GET /.env.example - 443 - 35.193.1 ...
show more
Domain : ecodehost.com
Rule : env
2026-09-20 14:11:46 10.100.1.20 GET /.env.example - 443 - 35.193.126.32 HTTP/2 Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; https://kimi.ai/) - ecodehost.com 301 0 0 161 392 300 - -
show less
Hacking
SQL Injection
๐จ๐ญ
dalslab ltd
2026-09-20 13:58:15
(1 week ago)
35.193.126.32 - - [20/Sep/2026:15:58:13 +0200] "POST / HTTP/1.1" 405 154 "-" "Mozilla/5.0 AppleWebKi ...
show more
35.193.126.32 - - [20/Sep/2026:15:58:13 +0200] "POST / HTTP/1.1" 405 154 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
35.193.126.32 - - [20/Sep/2026:15:58:13 +0200] "POST /graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.193.126.32 - - [20/Sep/2026:15:58:13 +0200] "POST /api/graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.193.126.32 - - [20/Sep/2026:15:58:13 +0200] "POST /v1/graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.193.126.32 - - [20/Sep/2026:15:58:15 +0200] "GET /..%2f.env HTTP/1.1" 400 154 "-" "-"
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:50:50
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.193.126.32 (32.126.193.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.193.126.32 (32.126.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:50:45.967565 2026] [security2:error] [pid 16361:tid 16367] [client 35.193.126.32:47352] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "colinkyffinmusic.com"] [uri "/.env.bak"] [unique_id "aq_ktdjQaG5a9ci0_dxh9wAAAYI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-09-20 13:42:43
(1 week ago)
Common web attack from 35.193.126.32.
Web App Attack
Anonymous
2026-09-20 13:40:58
(1 week ago)
35.193.126.32 - - [20/Sep/2026:15:40:44 +0200] "GET /.bash_profile HTTP/2.0" 403 268 "-" "Mozilla/5. ...
show more
35.193.126.32 - - [20/Sep/2026:15:40:44 +0200] "GET /.bash_profile HTTP/2.0" 403 268 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
๐ง๐ช
brechtr
2026-09-20 13:39:14
(1 week ago)
[Press84-BanHammer] 404 flood โ 30 hits in 60s โ Sourced from: brechtryckaert.com โ Request: GET /ap ...
show more
[Press84-BanHammer] 404 flood โ 30 hits in 60s โ Sourced from: brechtryckaert.com โ Request: GET /app/.env
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-20 13:28:26
(1 week ago)
Try to access /ssl/localhost.key
Web App Attack