๐ฉ๐ช
XICTRON
2026-09-23 00:20:06
(2 days ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐ฎ๐น
eliosbrocchi
2026-09-22 21:51:48
(2 days ago)
35.194.245.95 - - [22/Sep/2026:23:51:46 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTT ...
show more
35.194.245.95 - - [22/Sep/2026:23:51:46 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/2.0" 404 264 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
...
show less
VPN IP
๐บ๐ธ
robotstxt
2026-09-22 20:55:44
(2 days ago)
35.194.245.95 - - [22/Sep/2026:20:55:17 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 36243 "-" "Mo ...
show more
35.194.245.95 - - [22/Sep/2026:20:55:17 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 36243 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "35.194.245.95" edge="162.159.106.182"
35.194.245.95 - - [22/Sep/2026:20:55:18 +0000] "GET /.env.prod HTTP/2.0" 403 2 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "35.194.245.95" edge="162.159.98.41"
35.194.245.95 - - [22/Sep/2026:20:55:18 +0000] "GET /.env.save HTTP/2.0" 403 2 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "35.194.245.95" edge="162.159.98.41"
35.194.245.95 - - [22/Sep/2026:20:55:21 +0000] "GET /.aws/config HTTP/2.0" 403 36299 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "35.194.245.95" edge="162.159.98.41"
35.194.245.95 - - [22/Sep/2026:20:55:21 +0000] "GET /.aws/credentials H
...
show less
Web App Attack
๐ณ๐ฑ
GabrielJST
2026-09-22 20:25:15
(2 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.194.245.95 (TW/Ta ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.194.245.95 (TW/Taiwan/95.245.194.35.bc.googleusercontent.com)
show less
Bad Web Bot
๐ฉ๐ช
bazter.pro
2026-09-22 19:53:18
(2 days ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
oukat
2026-09-22 18:26:57
(2 days ago)
Web bot / web application probing against nginx
Bad Web Bot
Web App Attack
๐ณ๐ด
Bots.go.to.hell
2026-09-22 18:15:39
(2 days ago)
This IP was detected by CrowdSec triggering custom/http-bad-crawler-ban
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 16:18:40
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.194.245.95 (95.245.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.245.95 (95.245.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:18:36.259293 2026] [security2:error] [pid 14139:tid 14139] [client 35.194.245.95:52610] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||macryder.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "macryder.com"] [uri "/z9x8c7v6b5-debug-trigger-macryder.com"] [unique_id "arKqXEx1hVObWHuRCuJh1AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-09-22 16:04:35
(2 days ago)
Scan of vulnerable files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:20:41
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.194.245.95 (95.245.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.245.95 (95.245.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:20:35.331471 2026] [security2:error] [pid 24448:tid 24642] [client 35.194.245.95:43946] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||michaelrandon.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "michaelrandon.com"] [uri "/z9x8c7v6b5-debug-trigger-michaelrandon.com"] [unique_id "arKcw-_9QIngvDelSBg4kAAAAUg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 14:53:01
(2 days ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.194.245.95 - - [22/Sep/2026:16:52:51 +0200] "GET /.env.local HTTP/2.0" 403 350 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
...
show less
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-22 13:45:36
(2 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:21:31
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.194.245.95 (95.245.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.245.95 (95.245.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:21:25.610009 2026] [security2:error] [pid 1376:tid 1376] [client 35.194.245.95:57644] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||miraclepunchy.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "miraclepunchy.com"] [uri "/z9x8c7v6b5-debug-trigger-miraclepunchy.com"] [unique_id "arKA1W6voGPt3zTpBaqs2AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 13:05:29
(2 days ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ท๐ด
clauss
2026-09-22 12:56:51
(2 days ago)
35.194.245.95 - - [22/Sep/2026:15:56:49 +0300] "GET /firebase-adminsdk.json HTTP/2.0" 404 201 "-" "M ...
show more
35.194.245.95 - - [22/Sep/2026:15:56:49 +0300] "GET /firebase-adminsdk.json HTTP/2.0" 404 201 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
35.194.245.95 - - [22/Sep/2026:15:56:50 +0300] "GET /storage/logs/laravel.log HTTP/2.0" 403 146 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
...
show less
Web App Attack