Anonymous
2026-09-23 13:11:40
(11 minutes ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 11:31:00
(1 hour ago)
35.197.89.124 - - [22/Sep/2026:19:34:09 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (co ...
show more
35.197.89.124 - - [22/Sep/2026:19:34:09 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" 162.159.120.231
35.197.89.124 - - [22/Sep/2026:19:34:09 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" 108.162.245.226
35.197.89.124 - - [22/Sep/2026:19:34:09 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" 108.162.245.226
35.197.89.124 - - [22/Sep/2026:19:34:09 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" 108.162.245.226
35.197.89.124 - - [22/Sep/2026:19:34:10 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" 162.159.120.230
35.197.89.124 - - [22/Sep/2026:19:34:10 -0500] "GET /.env.producti
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(7 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ซ๐ฎ
mnazibo
2026-09-23 04:00:08
(9 hours ago)
Date: 23/Sep/2026 06:06:35 | Reported IP: 35.197.89.124 mod_security | id: 911100 930100 930110 9301 ...
show more
Date: 23/Sep/2026 06:06:35 | Reported IP: 35.197.89.124 mod_security | id: 911100 930100 930110 930120 930130 932160 932250 933160 934100 934130 942550 | US/group.my_domain/- | Connections: 137 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /agent/.env; /agents/.env; /ai/.env; /api/designer/v1/file-content; /api/.env.bak; /api/inngest; /api/templates/preview; /api/v1/.env; /api/v1/validate/code; /apps/.env; /auth/.env; /.bash_profile; /bot/.env; /.boto; /chatbot/.env; /client/.env; /cmd/.env; /cms/.env; /common/.env; /conf/.env; /config/database.yml; /config.env; /config.json; /config.py; /config/secrets.yml; /config.toml; /config.yaml; /dashboard/.env; /data/.env; /deploy/.env; /dev/.env; /.docker/config.json; /.docker/.env; /.env_1; /.env.development; /.env.docker; /env/.env; /.env.live; /.env.prod.bak; /.env.production.bak; /.env_sample; /.env.stage; /.env.staging; /.env.test; /.env.www; /etc/.env; /files../.env; /firebase-config.js
show less
SQL Injection
Brute-Force
Bad Web Bot
๐ฉ๐ช
itsolon
2026-09-23 01:51:40
(11 hours ago)
[23/Sep/2026:03:51:39 +0200] 179012829993.957125 35.197.89.124 51688 217.154.7.177 443
[23/Sep/2026: ...
show more
[23/Sep/2026:03:51:39 +0200] 179012829993.957125 35.197.89.124 51688 217.154.7.177 443
[23/Sep/2026:03:51:39 +0200] 179012829941.195334 35.197.89.124 51688 217.154.7.177 443
[23/Sep/2026:03:51:39 +0200] 179012829922.619515 35.197.89.124 51688 217.154.7.177 443
[23/Sep/2026:03:51:39 +0200] 179012829991.246121 35.197.89.124 51688 217.154.7.177 443
[23/Sep/2026:03:51:40 +0200] 179012830043.339056 35.197.89.124 51688 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-22 22:33:27
(14 hours ago)
35.197.89.124 - - [23/Sep/2026:06:33:25 +0800] "GET /img../.env HTTP/1.1" 404 297602 "-" "DuckAssist ...
show more
35.197.89.124 - - [23/Sep/2026:06:33:25 +0800] "GET /img../.env HTTP/1.1" 404 297602 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-22 21:38:53
(15 hours ago)
(modsecurity) srv101 ModSecurity 35.197.89.124 (US/United States/124.89.197.35.bc.googleusercontent. ...
show more
(modsecurity) srv101 ModSecurity 35.197.89.124 (US/United States/124.89.197.35.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-22 21:13:06
(16 hours ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-22 20:09:35
(17 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ฉ๐ช
TheDjRider
2026-09-22 18:19:43
(19 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-22T18:19:39.602437776Z. Context: http_status=301, http_status=200
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:29:45
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.197.89.124 (124.89.197.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.197.89.124 (124.89.197.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:29:41.490726 2026] [security2:error] [pid 25482:tid 25482] [client 35.197.89.124:33730] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||goatedlottosecrets.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "goatedlottosecrets.com"] [uri "/z9x8c7v6b5-debug-trigger-goatedlottosecrets.com"] [unique_id "arK7BWeWCo_jAy2ZgYStXwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
GoodOldTOS
2026-09-22 17:26:38
(19 hours ago)
Highly suspect IP
Hacking
Web App Attack
Anonymous
2026-09-22 16:46:33
(20 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฉ๐ช
itsolon
2026-09-22 16:23:22
(21 hours ago)
[22/Sep/2026:18:23:21 +0200] 179009420173.238901 35.197.89.124 58912 217.154.7.177 443
[22/Sep/2026: ...
show more
[22/Sep/2026:18:23:21 +0200] 179009420173.238901 35.197.89.124 58912 217.154.7.177 443
[22/Sep/2026:18:23:22 +0200] 179009420289.823539 35.197.89.124 58906 217.154.7.177 443
[22/Sep/2026:18:23:22 +0200] 179009420241.220628 35.197.89.124 58906 217.154.7.177 443
[22/Sep/2026:18:23:22 +0200] 17900942024.061345 35.197.89.124 58906 217.154.7.177 443
[22/Sep/2026:18:23:22 +0200] 179009420244.074600 35.197.89.124 58906 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ณ๐ด
Bots.go.to.hell
2026-09-22 16:08:55
(21 hours ago)
This IP was detected by CrowdSec triggering custom/http-bad-crawler-ban
Web App Attack
Bad Web Bot