๐ซ๐ฎ
robotstxt
2026-10-05 09:30:27
(1 day ago)
35.194.247.225 - - [05/Oct/2026:09:30:04 +0000] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d ...
show more
35.194.247.225 - - [05/Oct/2026:09:30:04 +0000] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 404 33062 "-" rt="2.619" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot" "-" edge="35.194.247.225" h="directorio.componentescalzado.com" sn="directorio.componentescalzado.com" ru="/cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input" u="/index.php" ucs="-" ua="unix:/var/run/php/ccalzadodir82.sock" us="404" uct="0.000" urt="2.619"
35.194.247.225 - - [05/Oct/2026:09:30:06 +0000] "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 404 33046 "-" rt="1.984" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" "-" edge="35.194.247.225" h="directorio.componentescalzado.com" sn="directorio.componentescalzado.com" ru="/cgi-bin/php?%ADd+all
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-05 09:28:36
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.194.247.225 (225.247.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.247.225 (225.247.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 05:28:31.056872 2026] [security2:error] [pid 17359:tid 17359] [client 35.194.247.225:40244] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||directnic.hookedonhomemadehappiness.com|F|2"] [data ".hookedonhomemadehappiness.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "directnic.hookedonhomemadehappiness.com"] [uri "/z9x8c7v6b5-debug-trigger-directnic.hookedonhomemadehappiness.com"] [unique_id "asNtvxX5gFAemCu1zcAs7gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Takesh
2026-10-05 07:42:41
(1 day ago)
Numbase auto-report: abuseipdb_known_bad_score_96
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-05 04:25:24
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.194.247.225 (225.247.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.247.225 (225.247.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 00:25:18.825212 2026] [security2:error] [pid 13630:tid 13630] [client 35.194.247.225:47568] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.centrodentalsindolor.com"] [uri "/api/fs/read"] [unique_id "asMmriKh0IlXqhyWRfYdRAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-05 04:22:44
(1 day ago)
[ti-26al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-26al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 35.194.247.225 - - [05/Oct/2026:06:22:23 +0200] "GET /forgot-password HTTP/1.1" 404 2065 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.194.247.225 - - [05/Oct/2026:06:22:23 +0200] "GET /signin HTTP/1.1" 404 2065 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.194.247.225 - - [05/Oct/2026:06:22:24 +0200] "GET /z9x8c7v6b5-debug-trigger-corporate.ngurepair.com HTTP/1.1" 404 2065 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
35.194.247.225 - - [05/Oct/2026:06:22:24 +0200] "GET /admin HTTP/1.1" 404 7783 "-" "Mozilla/5.0 (Windows NT 10.0; Win64;
...
show less
Bad Web Bot
Web App Attack
๐จ๐ญ
backslash
2026-10-05 00:06:08
(1 day ago)
block ruleset WAF detection and high score on abuseIPDB 149EB1B42C242111FADBBC2EF8F90219570691E1
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-04 22:44:59
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.194.247.225 (225.247.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.247.225 (225.247.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 18:44:54.351893 2026] [security2:error] [pid 730:tid 730] [client 35.194.247.225:38376] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||websiterescuecontest.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "websiterescuecontest.com"] [uri "/z9x8c7v6b5-debug-trigger-websiterescuecontest.com"] [unique_id "asLW5vwulAmZ3hKHFWg2XAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 22:25:58
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.194.247.225 (225.247.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.247.225 (225.247.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 18:25:54.490993 2026] [security2:error] [pid 2607212:tid 2607266] [client 35.194.247.225:46162] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||pwrcoupling.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pwrcoupling.com"] [uri "/z9x8c7v6b5-debug-trigger-pwrcoupling.com"] [unique_id "asLScjakSV7-e_pIt09kTwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
paissangroup
2026-10-04 22:22:07
(1 day ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-10-04 22:19:22
(1 day ago)
35.194.247.225 - - [05/Oct/2026:06:19:21 +0800] "GET /dist/.env HTTP/1.1" 404 39532 "-" "Mozilla/5.0 ...
show more
35.194.247.225 - - [05/Oct/2026:06:19:21 +0800] "GET /dist/.env HTTP/1.1" 404 39532 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
COMAITE
2026-10-04 21:53:33
(1 day ago)
Common web attack from 35.194.247.225.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 21:44:52
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.194.247.225 (225.247.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.247.225 (225.247.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 17:44:45.695373 2026] [security2:error] [pid 7784:tid 7784] [client 35.194.247.225:36694] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||directnicvpn.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "directnicvpn.com"] [uri "/z9x8c7v6b5-debug-trigger-directnicvpn.com"] [unique_id "asLIzfN51z1C5E7PcT_XIAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ช
vaia.cloud
2026-10-04 21:25:02
(1 day ago)
crowdsecurity/http-cve-2021-41773
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 21:22:39
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.194.247.225 (225.247.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.247.225 (225.247.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 17:22:34.946993 2026] [security2:error] [pid 30053:tid 30053] [client 35.194.247.225:45574] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||dinkusdrums.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dinkusdrums.com"] [uri "/z9x8c7v6b5-debug-trigger-dinkusdrums.com"] [unique_id "asLDmniCmaWtp-5a4FMt_QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 20:56:26
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.194.247.225 (225.247.194.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.247.225 (225.247.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 16:56:21.622516 2026] [security2:error] [pid 980:tid 980] [client 35.194.247.225:58096] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dillydallyvalley.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dillydallyvalley.com"] [uri "/z9x8c7v6b5-debug-trigger-dillydallyvalley.com"] [unique_id "asK9dfX1IpXEJ8MU5ZU3DgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack