π©πͺ
zumbo.net
2026-10-04 08:01:28
(1 hour ago)
[Sun Oct 04 11:01:26.782866 2026] [proxy_fcgi:error] [pid 460400:tid 460408] [client 35.194.130.72:0 ...
show more
[Sun Oct 04 11:01:26.782866 2026] [proxy_fcgi:error] [pid 460400:tid 460408] [client 35.194.130.72:0] AH01071: Got error 'Primary script unknown'
[Sun Oct 04 11:01:26.814678 2026] [proxy_fcgi:error] [pid 488239:tid 488259] [client 35.194.130.72:0] AH01071: Got error 'Primary script unknown'
[Sun Oct 04 11:01:26.838885 2026] [proxy_fcgi:error] [pid 460400:tid 460429] [client 35.194.130.72:0] AH01071: Got error 'Primary script unknown'
[Sun Oct 04 11:01:26.839668 2026] [proxy_fcgi:error] [pid 460401:tid 460448] [client 35.194.130.72:0] AH01071: Got error 'Primary script unknown'
[Sun Oct 04 11:01:27.053183 2026] [proxy_fcgi:error] [pid 460400:tid 460406] [client 35.194.130.72:0] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
π¬π§
Apache
2026-10-04 06:12:52
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.194.130.72 (TW/Taiwan/72.130.194.35.bc.googl ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.130.72 (TW/Taiwan/72.130.194.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
π¬π§
consul.to
2026-10-04 00:41:26
(8 hours ago)
Web attack/malicious scanning detected
Web App Attack
π©πͺ
netclix.gr
2026-10-03 20:04:12
(13 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.194.130.72 (TW/Taiwan/72.130.194.35. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.194.130.72 (TW/Taiwan/72.130.194.35.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
π¦πΊ
2000cn.com.au
2026-10-03 09:11:20
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
πΊπΈ
TPI-Abuse
2026-10-03 03:02:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.194.130.72 (72.130.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.130.72 (72.130.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 23:02:02.646736 2026] [security2:error] [pid 24609:tid 24609] [client 35.194.130.72:60462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.skintherapynola.com"] [uri "/files../.env"] [unique_id "asBwKmSwU5iLreR4uX_PdgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-03 00:28:47
(1 day ago)
git/env leak probe
Web App Attack
π©πͺ
itsolon
2026-10-02 23:34:26
(1 day ago)
[03/Oct/2026:01:34:25 +0200] 17909840659.444112 35.194.130.72 53408 217.154.7.177 443
[03/Oct/2026:0 ...
show more
[03/Oct/2026:01:34:25 +0200] 17909840659.444112 35.194.130.72 53408 217.154.7.177 443
[03/Oct/2026:01:34:26 +0200] 179098406667.126109 35.194.130.72 53408 217.154.7.177 443
[03/Oct/2026:01:34:26 +0200] 179098406623.684436 35.194.130.72 53408 217.154.7.177 443
[03/Oct/2026:01:34:26 +0200] 179098406646.243305 35.194.130.72 53408 217.154.7.177 443
[03/Oct/2026:01:34:26 +0200] 179098406665.463678 35.194.130.72 53408 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
π«π·
dynamix
2026-10-02 23:03:10
(1 day ago)
Multiple WAF Violations
Web App Attack
π©πͺ
zUnlegit
2026-10-02 20:49:18
(1 day ago)
Automated web scanner requested sensitive path: /config/env/aws_credentials.env
Web App Attack
π©πͺ
itsolon
2026-10-02 19:59:28
(1 day ago)
[02/Oct/2026:21:59:27 +0200] 179097116739.280623 35.194.130.72 44212 217.154.7.177 443
[02/Oct/2026: ...
show more
[02/Oct/2026:21:59:27 +0200] 179097116739.280623 35.194.130.72 44212 217.154.7.177 443
[02/Oct/2026:21:59:27 +0200] 179097116783.739989 35.194.130.72 44212 217.154.7.177 443
[02/Oct/2026:21:59:27 +0200] 179097116734.200547 35.194.130.72 44212 217.154.7.177 443
[02/Oct/2026:21:59:27 +0200] 179097116792.958506 35.194.130.72 44212 217.154.7.177 443
[02/Oct/2026:21:59:28 +0200] 179097116866.685412 35.194.130.72 44212 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 17:35:51
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.194.130.72 (72.130.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.130.72 (72.130.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 13:35:45.287265 2026] [security2:error] [pid 24743:tid 24766] [client 35.194.130.72:60898] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||skillscredentials.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "skillscredentials.com"] [uri "/z9x8c7v6b5-debug-trigger-skillscredentials.com"] [unique_id "ar_rccF-ytgIc4TGogvU1QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
itsolon
2026-10-02 17:23:38
(1 day ago)
[02/Oct/2026:19:23:36 +0200] 179096181630.279056 35.194.130.72 39226 217.154.7.177 443
[02/Oct/2026: ...
show more
[02/Oct/2026:19:23:36 +0200] 179096181630.279056 35.194.130.72 39226 217.154.7.177 443
[02/Oct/2026:19:23:37 +0200] 179096181763.869610 35.194.130.72 39226 217.154.7.177 443
[02/Oct/2026:19:23:37 +0200] 179096181771.321284 35.194.130.72 39226 217.154.7.177 443
[02/Oct/2026:19:23:37 +0200] 179096181775.508897 35.194.130.72 39226 217.154.7.177 443
[02/Oct/2026:19:23:37 +0200] 179096181733.674905 35.194.130.72 39226 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
π¬π§
Apache
2026-10-02 16:53:28
(1 day ago)
(mod_security) mod_security (id:218420) triggered by 35.194.130.72 (TW/Taiwan/72.130.194.35.bc.googl ...
show more
(mod_security) mod_security (id:218420) triggered by 35.194.130.72 (TW/Taiwan/72.130.194.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-02 16:53:05
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.194.130.72 (72.130.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.130.72 (72.130.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 12:52:59.770399 2026] [security2:error] [pid 9424:tid 9424] [client 35.194.130.72:43680] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hazelzito.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hazelzito.com"] [uri "/z9x8c7v6b5-debug-trigger-hazelzito.com"] [unique_id "ar_ha8qKV8bFeSWrve-ZRwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack