๐ธ๐ช
vaia.cloud
2026-10-02 15:20:01
(2 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐ซ๐ฎ
oh.mg
2026-10-02 14:51:37
(2 hours ago)
35.199.79.184 - - [02/Oct/2026:16:51:32 +0200] "GET /auth.json HTTP/1.0" 403 2221 "-" "Mozilla/5.0 ( ...
show more
35.199.79.184 - - [02/Oct/2026:16:51:32 +0200] "GET /auth.json HTTP/1.0" 403 2221 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
35.199.79.184 - - [02/Oct/2026:16:51:35 +0200] "GET /appsettings.json HTTP/1.0" 403 2221 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
35.199.79.184 - - [02/Oct/2026:16:51:35 +0200] "GET /appsettings.Production.json HTTP/1.0" 403 844 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
35.199.79.184 - - [02/Oct/2026:16:51:35 +0200] "GET /settings.json HTTP/1.0" 403 844 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
35.199.79.184 - - [02/Oct/2026:16:51:36 +0200] "GET /env.js HTTP/1.0" 403 844 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-02 14:14:04
(3 hours ago)
Excessive 404/403 errors
Brute-Force
๐ฉ๐ช
updown.io
2026-10-02 13:47:31
(3 hours ago)
{"level":"info","ts":1790948846.2233763,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790948846.2233763,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.199.79.184","remote_port":"57892","client_ip":"35.199.79.184","proto":"HTTP/2.0","method":"GET","host":"status.lucidtales.coop","uri":"/manifest.json","headers":{"Accept-Encoding":["gzip, deflate, br, zstd"],"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"],"Sec-Ch-Ua-Platform":["\"Android\""],"Accept-Language":["en-US,en;q=0.9"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"Upgrade-Insecure-Requests":["1"],"Sec-Ch-Ua":["\"Chromium\";v=\"153\", \"Google Chrome\";v=\"153\", \"Not_A Brand\";v=\"8\""],"Sec-Fetch-Site":["none"],"P
...
show less
DDoS Attack
Web App Attack
๐ช๐ธ
pipeline.es
2026-10-02 09:44:02
(8 hours ago)
Web scanning / probing for vulnerable paths | URL: /.htpasswd | Evidence: morgana.travel 35.199.79.1 ...
show more
Web scanning / probing for vulnerable paths | URL: /.htpasswd | Evidence: morgana.travel 35.199.79.184 - - [02/Oct/2026:11:42:53 +0200] \"GET /.htpasswd HTTP/1.1\" 403 211 \"https://www.morgana.travel/.htpasswd\" \"Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot\" GEOIP_COUNTRY_CODE=BR | ASN: GOOGLE-CLOUD-PLATFORM | Country: BR
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 05:54:46
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.79.184 (184.79.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.79.184 (184.79.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 01:54:39.149677 2026] [security2:error] [pid 11669:tid 11669] [client 35.199.79.184:35192] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.emea.legal"] [uri "/.env.development"] [unique_id "ar9HH_1lepW6diHalcqYZwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 04:42:30
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.199.79.184 (184.79.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.79.184 (184.79.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 00:42:22.703979 2026] [security2:error] [pid 31310:tid 31310] [client 35.199.79.184:45852] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ideaofauniversity.website|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ideaofauniversity.website"] [uri "/rclone.conf"] [unique_id "ar82LuJwert3ldE69O0ifgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-10-02 04:40:03
(13 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-10-02 04:10:07
(13 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ณ๐ฑ
Alt255
2026-10-02 04:08:24
(13 hours ago)
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35. ...
show more
[ti-14al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35.199.79.184 - - \[02/Oct/2026:06:08:16 +0200\] "GET /cache/original/%2e%2e/.env HTTP/1.1" 403 521 "-" "Mozilla/5.0 \(compatible\; Baiduspider/2.0\; +http://www.baidu.com/search/spider.html\)"
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-02 04:08:18
(13 hours ago)
Web attack/malicious scanning detected
Web App Attack