๐ฉ๐ช
todix
2026-09-24 17:23:14
(9 minutes ago)
Web App Attack Exploid from 35.198.184.104
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 17:19:27
(12 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.198.184.104 (104.184.198.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.184.104 (104.184.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 13:19:22.748185 2026] [security2:error] [pid 223093:tid 223093] [client 35.198.184.104:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.backlogica.com"] [uri "/@fs/app/.env"] [unique_id "arVbmg17mMb4YOZe-mDA8wAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฑ๐ป
garmtech.com
2026-09-24 16:46:12
(46 minutes ago)
Attempted access to sensitive endpoint (/config/master.key) detected. Automated scan or unauthorized ...
show more
Attempted access to sensitive endpoint (/config/master.key) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 16:43:16
(49 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.198.184.104 (104.184.198.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.184.104 (104.184.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 12:43:10.802966 2026] [security2:error] [pid 13316:tid 13316] [client 35.198.184.104:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.area52designs.com"] [uri "/.env.example"] [unique_id "arVTHqAhAT7xRPRjPVbWTQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mashamal
2026-09-24 15:54:07
(1 hour ago)
unauthorized access request
...
Web App Attack
๐บ๐ธ
TAY
2026-09-24 15:17:44
(2 hours ago)
35.198.184.104 - - [24/Sep/2026:23:17:42 +0800] "GET /wp-config.php.bak HTTP/1.1" 301 487 "-" "Mozil ...
show more
35.198.184.104 - - [24/Sep/2026:23:17:42 +0800] "GET /wp-config.php.bak HTTP/1.1" 301 487 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
35.198.184.104 - - [24/Sep/2026:23:17:43 +0800] "GET /wp-config.php.old HTTP/1.1" 301 487 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
35.198.184.104 - - [24/Sep/2026:23:17:43 +0800] "GET /webmail/wp-config.php.bak HTTP/1.1" 404 2050 "https://webmail.aceflora.com/wp-config.php.bak" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
35.198.184.104 - - [24/Sep/2026:23:17:43 +0800] "GET /webmail/wp-config.php.old HTTP/1.1" 404 2050 "https://webmail.aceflora.com/wp-config.php.old" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
35.198.184.104 - - [24/Sep/2026:23:17:43 +0800] "GET
...
show less
Brute-Force
๐ฉ๐ช
itsolon
2026-09-24 14:31:51
(3 hours ago)
[24/Sep/2026:16:31:50 +0200] 179026031015.469327 35.198.184.104 33722 217.154.7.177 443
[24/Sep/2026 ...
show more
[24/Sep/2026:16:31:50 +0200] 179026031015.469327 35.198.184.104 33722 217.154.7.177 443
[24/Sep/2026:16:31:50 +0200] 179026031029.149716 35.198.184.104 33722 217.154.7.177 443
[24/Sep/2026:16:31:50 +0200] 179026031031.250914 35.198.184.104 33722 217.154.7.177 443
[24/Sep/2026:16:31:50 +0200] 179026031061.059217 35.198.184.104 33722 217.154.7.177 443
[24/Sep/2026:16:31:50 +0200] 179026031034.591667 35.198.184.104 33722 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
cloudmax
2026-09-24 14:27:49
(3 hours ago)
Cloudmax Protect [BOT BLOCK] - Suspicious User-Agent. Possible resource abuse, excessive requests, o ...
show more
Cloudmax Protect [BOT BLOCK] - Suspicious User-Agent. Possible resource abuse, excessive requests, or hacking attempt
show less
Bad Web Bot
๐ณ๐ฑ
debestelapp
2026-09-24 13:50:09
(3 hours ago)
Web App Attack
๐จ๐ฆ
polycoda
2026-09-24 12:34:09
(4 hours ago)
๐ฅ VERY AGGRESSIVE SCANNER probed over 100 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack
๐จ๐ฆ
polycoda
2026-09-24 11:41:02
(5 hours ago)
AutoBlock: ๐ก Port Scan (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
Port Scan
Bad Web Bot
Anonymous
2026-09-24 10:42:55
(6 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
Anonymous
2026-09-24 09:25:09
(8 hours ago)
malicious scanning tool activity
Web App Attack
๐ฉ๐ช
TheDjRider
2026-09-24 09:24:08
(8 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-24T09:24:05.863785869Z. Context: http_status=200
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-24 08:59:08
(8 hours ago)
35.198.184.104 - - [24/Sep/2026:08:58:07 +0000] "POST / HTTP/2.0" 403 13817 "-" "Mozilla/5.0 (compat ...
show more
35.198.184.104 - - [24/Sep/2026:08:58:07 +0000] "POST / HTTP/2.0" 403 13817 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "-" edge="35.198.184.104"
35.198.184.104 - - [24/Sep/2026:08:58:08 +0000] "GET /wp-content/cache/autoptimize/js/autoptimize_ef9e7d371c10cd56929782c27cd5ffaa.js HTTP/2.0" 403 165 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.198.184.104"
35.198.184.104 - - [24/Sep/2026:08:58:09 +0000] "GET /assets/manifest.json HTTP/2.0" 403 7739 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.198.184.104"
35.198.184.104 - - [24/Sep/2026:08:58:10 +0000] "GET /asset-manifest.json HTTP/2.0" 403 7739 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.198.184.104"
35.198.184.104 - - [24/Sep/2026:08:58:10 +0000] "GET /dist/manifest.
...
show less
Web App Attack