๐ง๐ช
taivas.nl
2026-08-29 04:33:12
(2 hours ago)
Many_bad_calls
Web App Attack
๐บ๐ธ
snappic
2026-08-28 11:39:43
(18 hours ago)
Scanning for config [GET /config.json.js] [Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compat ...
show more
Scanning for config [GET /config.json.js] [Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; meta-externalagent/1.1; +https://developers.facebook.com/docs/sharing/webmasters/crawler)]
show less
Bad Web Bot
Web App Attack
๐ญ๐บ
DumaNet
2026-08-28 11:36:00
(19 hours ago)
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 28. 11:38:15
Source IP: 35.196 ...
show more
Web app attack attempts, scanning for vulnerability.
Date: 2026 Aug 28. 11:38:15
Source IP: 35.196.155.112
Portion of the log(s):
35.196.155.112 - [28/Aug/2026:11:38:15 +0200] "GET /@fs/.env.local?raw?? HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Discordbot/2.0; +https://discordapp.com)"
35.196.155.112 - [28/Aug/2026:11:38:15 +0200] "GET /@fs/.env.staging?raw?? HTTP/1.1" 404 153 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +https://www.anthropic.com/claude-user)"
35.196.155.112 - [28/Aug/2026:11:38:15 +0200] "GET /@fs/root/rootkey.csv?raw?? HTTP/1.1" 404 153 "-" "Mozilla/5.0 (compatible; GPTBot/1.2; +https://openai.com/gptbot)"
35.196.155.112 - [28/Aug/2026:11:38:15 +0200] "GET /@fs/app/rootkey.csv?raw?? HTTP/1.1" 404 555 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 14_5) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.855.163 Safari/537.36; compatible; WhatsApp/10.0.2.1"
35.196.155.112 - [28/Aug/2026:11:38:15
show less
Web App Attack
๐จ๐ฆ
polycoda
2026-08-28 11:27:41
(19 hours ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based)
Hacking
Bad Web Bot
Web App Attack
๐ง๐พ
lns.bz
2026-08-28 11:12:15
(19 hours ago)
Too many 404 requests [BY]
Web App Attack
๐ฉ๐ช
David Ferneding
2026-08-28 10:59:49
(19 hours ago)
Blocked by UFW (TCP on 80)
Source port: 37340
TTL: 59
Packet length: 60
TOS: 0x00
This report (for ...
show more
Blocked by UFW (TCP on 80)
Source port: 37340
TTL: 59
Packet length: 60
TOS: 0x00
This report (for 35.196.155.112) was generated by:
https://github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
Web App Attack
๐บ๐ธ
mnsf
2026-08-28 10:05:19
(20 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
๐ซ๐ท
Eldeberen
2026-08-28 08:59:14
(21 hours ago)
Vulnerability scan attempt through HTTP protocol
Web App Attack
๐ณ๐ฑ
mieg
2026-08-28 08:11:42
(22 hours ago)
Web vulnerability probing
Brute-Force
Web App Attack
๐บ๐ธ
CBJ
2026-08-28 06:57:54
(23 hours ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 05:45:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.196.155.112 (112.155.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.155.112 (112.155.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 01:45:07.957573 2026] [security2:error] [pid 25886:tid 25886] [client 35.196.155.112:23790] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcontacts.ccancun.co"] [uri "/@fs/.env"] [unique_id "apEgYxfz3NpDtFGoM8mqdAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
openstrike.co.uk
2026-08-28 05:14:17
(1 day ago)
138 attacks on VC URLs, PHP URLs, env grabbing URLs, config grabbing URLs (type 2), password grabbin ...
show more
138 attacks on VC URLs, PHP URLs, env grabbing URLs, config grabbing URLs (type 2), password grabbing URLs:
GET /.git/config HTTP/1.1
GET /config/aws.php HTTP/1.1
GET /aws/.env HTTP/1.1
GET /config/aws.json HTTP/1.1
GET /api/.aws/credentials HTTP/1.1
show less
Hacking
Web App Attack
๐ง๐ช
taivas.nl
2026-08-28 05:02:09
(1 day ago)
Bad_requests
Bad Web Bot
๐ช๐ธ
offensivesentinel
2026-08-28 04:59:00
(1 day ago)
ModSecurity rule violation on iesmonterroso.org
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-28 04:30:47
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.196.155.112 (112.155.196.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.155.112 (112.155.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 00:30:43.269603 2026] [security2:error] [pid 21407:tid 21413] [client 35.196.155.112:25690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.otemaetk.com"] [uri "/@fs/.env"] [unique_id "apEO884O4UYG69XXolgX4QAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack