Anonymous
2026-10-06 11:47:55
(7 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.199.125.56 (BR/Brazil/56.125.199.35. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.199.125.56 (BR/Brazil/56.125.199.35.bc.googleusercontent.com)
show less
SQL Injection
Anonymous
2026-10-06 11:00:57
(8 hours ago)
35.199.125.56 detected on srv01
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-06 10:56:18
(8 hours ago)
(mod_security) mod_security (id:218420) triggered by 35.199.125.56 (56.125.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:218420) triggered by 35.199.125.56 (56.125.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:56:01.648255 2026] [security2:error] [pid 29382:tid 29382] [client 35.199.125.56:33810] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)php://(std(in|out|err)|(in|out)put|fd|memory|temp|filter)" at ARGS_NAMES:\\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/21_PHP_PHPGen.conf"] [line "38"] [id "218420"] [rev "2"] [msg "COMODO WAF: PHP Injection Attack: I/O Stream Found||vfflag.info|F|2"] [data "Matched Data: php://input found within ARGS_NAMES:\\x5cxadd allow_url_include=1 \\x5cxadd auto_prepend_file=php://input: \\xadd allow_url_include=1 \\xadd auto_prepend_file=php://input"] [severity "CRITICAL"] [tag "CWAF"] [tag "PHPGen"] [hostname "vfflag.info"] [uri "/index.php"] [unique_id "asTTwUQs8wK05ZFzzui2zwAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-10-06 10:50:50
(8 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 10:13:52
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.125.56 (56.125.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.125.56 (56.125.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:13:46.068257 2026] [security2:error] [pid 29593:tid 29593] [client 35.199.125.56:49178] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "travelto.info"] [uri "/.htpasswd"] [unique_id "asTJ2ncnFf5GW873ByxsnAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-06 09:56:29
(9 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-10-06 09:33:17
(9 hours ago)
35.199.125.56 - - [06/Oct/2026:11:32:50 +0200] "GET /.htpasswd HTTP/2.0" 403 272 "-" "Mozilla/5.0 (c ...
show more
35.199.125.56 - - [06/Oct/2026:11:32:50 +0200] "GET /.htpasswd HTTP/2.0" 403 272 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-10-06 09:20:06
(9 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-06 09:13:58
(9 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 09:10:16
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.125.56 (56.125.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.125.56 (56.125.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 05:10:10.359124 2026] [security2:error] [pid 15313:tid 15313] [client 35.199.125.56:42508] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stormstrips.info"] [uri "/static../.env"] [unique_id "asS68ndzq2gSmQxrYUFknAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-06 09:09:32
(9 hours ago)
35.199.125.56 - - [06/Oct/2026:11:09:26 +0200] "GET /.dockerenv HTTP/2.0" 404 293 "-" "Mozilla/5.0 A ...
show more
35.199.125.56 - - [06/Oct/2026:11:09:26 +0200] "GET /.dockerenv HTTP/2.0" 404 293 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
35.199.125.56 - - [06/Oct/2026:11:09:26 +0200] "GET /api/console/api_server?sense_version=@@SENSE_VERSION&apis=../../../../../../.env HTTP/2.0" 404 293 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
35.199.125.56 - - [06/Oct/2026:11:09:26 +0200] "GET /proc/self/cmdline HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
35.199.125.56 - - [06/Oct/2026:11:09:26 +0200] "GET /static/../../../a/../../../../.env HTTP/2.0" 400 323 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
35.199.125.56 - - [06/Oct/2026:11:09:26 +0200] "GET /api/fs/read?allowOutsideWorkspace=true&path=/proc/self/environ HTTP/2.0" 404 293 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
35
show less
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-10-06 08:54:42
(10 hours ago)
20 attempts against mh_ha-misbehave-ban on pf221116
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 08:47:38
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.125.56 (56.125.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.125.56 (56.125.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 04:47:34.494841 2026] [security2:error] [pid 11489:tid 11489] [client 35.199.125.56:33770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "solarfarms.info"] [uri "/.env.backup"] [unique_id "asS1ppzWvdD9v5THKBPGogAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
maxxsense
2026-10-06 08:34:13
(10 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.199.125.56 (BR/Brazil/56.125.199.35. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.199.125.56 (BR/Brazil/56.125.199.35.bc.googleusercontent.com)
show less
SQL Injection
๐ณ๐ฑ
enpepet
2026-10-06 08:30:37
(10 hours ago)
GENERAL: parametres: [url:env=] UA:Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/) URL:/.env
Port Scan
Hacking
Brute-Force
Bad Web Bot