🇺🇸
WizardsToolkit
2026-09-14 01:46:53
(13 hours ago)
tried to access server backup files
Web App Attack
🇺🇸
SketchyDude
2026-09-14 00:31:45
(15 hours ago)
Banned by Fail2Ban jail: apache-fakegooglebot
Bad Web Bot
🇬🇧
blik2108
2026-09-14 00:30:17
(15 hours ago)
35.196.91.251 - - [14/Sep/2026:00:30:14 +0000] "GET /z9x8c7v6b5-debug-trigger-solentyachtcharter.com ...
show more
35.196.91.251 - - [14/Sep/2026:00:30:14 +0000] "GET /z9x8c7v6b5-debug-trigger-solentyachtcharter.com HTTP/1.1" 404 3431 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)" "-"
35.196.91.251 - - [14/Sep/2026:00:30:14 +0000] "GET /rclone.conf HTTP/1.1" 404 3431 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" "-"
35.196.91.251 - - [14/Sep/2026:00:30:14 +0000] "GET /build/manifest.json HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-"
35.196.91.251 - - [14/Sep/2026:00:30:14 +0000] "GET /.vite/manifest.json HTTP/1.1" 404 3431 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-"
35.196.91.251 - - [14/Sep/2026:00:30:14 +0000] "POST /graphql HTTP/1.1" 404 3431 "https://solentyachtcharter.com" "Mozilla/5.0 (M
...
show less
Web App Attack
🇺🇸
legionMCCXV
2026-09-14 00:08:30
(15 hours ago)
Non-HTTP protocol data (e.g. MQTT/TLS handshake bytes) sent to HTTP(S) port.
Port Scan
Hacking
🇿🇦
conure.sh
2026-09-13 22:18:53
(17 hours ago)
csagent: score 20.0: secrets grab x2; 1 domain(s) in 1s
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 21:53:07
(17 hours ago)
(mod_security) mod_security (id:210580) triggered by 35.196.91.251 (251.91.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 35.196.91.251 (251.91.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 17:53:02.212936 2026] [security2:error] [pid 6757:tid 6757] [client 35.196.91.251:0] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||puertaalcieloisla.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: ../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "puertaalcieloisla.com"] [uri "/userfiles"] [unique_id "aqcbPm-hVRzSWd49bI70hAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
dtorrer
2026-09-13 20:55:21
(18 hours ago)
General vulnerability scan.
Port Scan
🇳🇱
Site.eu
2026-09-13 16:56:20
(22 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-13 16:20:09
(23 hours ago)
Aggressive web scan
Web App Attack
Anonymous
2026-09-13 15:58:53
(23 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇺🇸
nyt
2026-09-13 15:23:40
(1 day ago)
Empty UA + error, Path Traversal
Web App Attack
🇺🇸
mnsf
2026-09-13 15:05:21
(1 day ago)
Scanning/Probing (11)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 14:13:04
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.196.91.251 (251.91.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.196.91.251 (251.91.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 10:13:00.706946 2026] [security2:error] [pid 15546:tid 15546] [client 35.196.91.251:38836] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||happybookermusic.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "happybookermusic.com"] [uri "/rclone.conf"] [unique_id "aqavbGlfis4Yhdt-liZaUwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Baking333
2026-09-13 00:38:53
(1 day ago)
[redacted] 35.196.91.251 - - [13/Sep/2026:01:38:51 +0100] "GET /@fs/var/task/.env?raw?? HTTP/1.1" 30 ...
show more
[redacted] 35.196.91.251 - - [13/Sep/2026:01:38:51 +0100] "GET /@fs/var/task/.env?raw?? HTTP/1.1" 302 6743 0/69438 "-" "Mozilla/5.0 (compatible; Bytespider; spider-feedback@[redacted]) AppleWebKit/537.36" [redacted] 35.196.91.251 - - [13/Sep/2026:01:38:51 +0100] "GET /@fs/proc/self/cwd/.env?raw?? HTTP/1.1" 302 6743 0/194337 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://[redacted]/)"
show less
Bad Web Bot
Web App Attack
🇫🇷
ELYAZ
2026-09-12 20:36:45
(1 day ago)
(y3) Failed access -byebye- from 35.196.91.251 (US/United States/251.91.196.35.bc.googleusercontent. ...
show more
(y3) Failed access -byebye- from 35.196.91.251 (US/United States/251.91.196.35.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking