๐ง๐ช
cmbplf
2026-10-01 05:28:55
(4 days ago)
323 requests with url.path *.env
104 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
Anonymous
2026-10-01 05:22:10
(4 days ago)
35.198.25.224 - - [01/Oct/2026:00:20:40 -0500] "GET /.env.js HTTP/1.1" 301 257 "-" "Mozilla/5.0 (Mac ...
show more
35.198.25.224 - - [01/Oct/2026:00:20:40 -0500] "GET /.env.js HTTP/1.1" 301 257 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot" 172.71.255.123
35.198.25.224 - - [01/Oct/2026:00:20:40 -0500] "GET /.env.production HTTP/1.1" 301 265 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 104.23.254.52
35.198.25.224 - - [01/Oct/2026:00:20:41 -0500] "GET /.env.local HTTP/1.1" 301 260 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" 104.23.254.52
35.198.25.224 - - [01/Oct/2026:00:20:41 -0500] "GET /.env.backup HTTP/1.1" 301 261 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" 104.23.254.52
35.198.25.224 - - [01/Oct/2026:00:20:41 -0500] "GET /.env.bak HTTP/1.1" 301 258 "-" "Mozilla/5.0 (compatible;
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 03:30:49
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.198.25.224 (224.25.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.25.224 (224.25.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 23:30:41.796439 2026] [security2:error] [pid 14576:tid 14576] [client 35.198.25.224:48644] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ablogisticsgroup.com"] [uri "/.env.js"] [unique_id "ar3T4eXvNtQ52Egzfx0_sAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-10-01 03:15:07
(4 days ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.198.25. ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.198.25.224 (BR/Brazil/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 35.198.25.224 (BR/Brazil/224.25.198.35.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 02:27:05
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.198.25.224 (224.25.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.25.224 (224.25.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 22:27:00.960408 2026] [security2:error] [pid 2303:tid 2303] [client 35.198.25.224:57994] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.abilityimprinting.com"] [uri "/wp-config.php.bak"] [unique_id "ar3E9Ojhd6IcarOFeoxAVQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 01:45:28
(4 days ago)
IP matched detection query 50 and more bad rqs apache.
Hacking
Bad Web Bot
Brute-Force
Web App Attack
๐ซ๐ท
โจ
2026-10-01 01:42:11
(4 days ago)
Domain : ability6.com
Rule : hack
2026-10-01 01:40:49 ***hidden-privacy*** GET /z9x8c7v6b5-debug-tri ...
show more
Domain : ability6.com
Rule : hack
2026-10-01 01:40:49 ***hidden-privacy*** GET /z9x8c7v6b5-debug-trigger-ability6.com - 443 - 35.198.25.224 HTTP/2 Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; https://developers.facebook.com/docs/sharing/webmasters/crawler) - ability6.com 404 0 0 104872 466 1180 - -
show less
Hacking
SQL Injection
Brute-Force
Anonymous
2026-10-01 01:25:34
(4 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-01 00:09:54
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 35.198.25.224 (224.25.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.198.25.224 (224.25.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 20:09:47.467423 2026] [security2:error] [pid 15383:tid 15383] [client 35.198.25.224:44592] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||homehealth101.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "homehealth101.com"] [uri "/z9x8c7v6b5-debug-trigger-homehealth101.com"] [unique_id "ar2kyySalfy1sbh_Err1awAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-09-30 23:49:16
(4 days ago)
Repeated requests for suspicious nonexistent URLs, for example: /model/info (HTTP port 443, user age ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /model/info (HTTP port 443, user agent: "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)")
show less
Web App Attack
๐ซ๐ท
dynamix
2026-09-30 22:57:56
(4 days ago)
Multiple WAF Violations
Web App Attack
๐จ๐ฆ
Mediashaker
2026-09-30 21:41:44
(4 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.198.25.224 (BR/Br ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.198.25.224 (BR/Brazil/224.25.198.35.bc.googleusercontent.com)
show less
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-09-30 16:14:56
(4 days ago)
[cb-01vi] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-01vi] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.198.25.224 - - [30/Sep/2026:18:14:45 +0200] "GET /.ssh/id_ed25519 HTTP/2.0" 403 346 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:39:41
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.198.25.224 (224.25.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.198.25.224 (224.25.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:39:35.513438 2026] [security2:error] [pid 25935:tid 25935] [client 35.198.25.224:46802] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.lucid-events.com|F|2"] [data ".lucid-events.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.lucid-events.com"] [uri "/z9x8c7v6b5-debug-trigger-www.lucid-events.com"] [unique_id "ar0tN5aliTxueS6D1EsiDgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:42:38
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.198.25.224 (224.25.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.198.25.224 (224.25.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:42:32.097505 2026] [security2:error] [pid 12864:tid 12864] [client 35.198.25.224:40312] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||69strains.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "69strains.com"] [uri "/z9x8c7v6b5-debug-trigger-69strains.com"] [unique_id "ar0f2HpDZMyOHx5QaiNvdQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack