๐บ๐ธ
TPI-Abuse
2026-06-13 17:29:55
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.8.24 (24.8.199.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.8.24 (24.8.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 13:29:51.248977 2026] [security2:error] [pid 25661:tid 25661] [client 35.199.8.24:60398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/config.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "manaplas.com"] [uri "/config/config.yml"] [unique_id "ai2Tj89XWCeZREX5YOYYuAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Savvii
2026-06-13 15:58:32
(5 hours ago)
20 attempts against mh-misbehave-ban on bush
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-13 15:17:39
(5 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ณ๐ฑ
Roderic
2026-06-13 14:54:40
(6 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-06-13 13:17:58
(7 hours ago)
20 attempts against mh-misbehave-ban on ficus
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-13 12:14:23
(9 hours ago)
35.199.8.24 - - [13/Jun/2026:09:14:23 -0300] "GET /actuator/env HTTP/1.1" 404 870 "-" "Mozilla/5.0 ( ...
show more
35.199.8.24 - - [13/Jun/2026:09:14:23 -0300] "GET /actuator/env HTTP/1.1" 404 870 "-" "Mozilla/5.0 (Linux; Android 9; ONEPLUS A6010) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/76.0.3809.111 Mobile Safari/537.36"
35.199.8.24 - - [13/Jun/2026:09:14:23 -0300] "GET /actuator/sessions HTTP/1.1" 404 870 "-" "Mozilla/5.0 (Windows NT 6.1; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/66.0.3359.170 Safari/537.36"
35.199.8.24 - - [13/Jun/2026:09:14:23 -0300] "GET /api/actuator/heapdump HTTP/1.1" 404 870 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 12_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148 MicroMessenger/7.0.5(0x17000523) NetType/4G Language/zh_CN"
35.199.8.24 - - [13/Jun/2026:09:14:23 -0300] "GET /actuator/threaddump HTTP/1.1" 404 870 "-" "Roku/DVP-4.1 (024.01E01250A)"
35.199.8.24 - - [13/Jun/2026:09:14:23 -0300] "GET /api/actuator/env HTTP/1.1" 404 870 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.0; Trident/4.0)"
...
show less
Port Scan
๐บ๐ธ
Power Ca
2026-06-13 11:27:04
(9 hours ago)
35.199.8.24 - - [13/Jun/2026:11:27:02 +0000] "GET /heapdump HTTP/2.0" 404 123 "-" "Mozilla/5.0 (iPad ...
show more
35.199.8.24 - - [13/Jun/2026:11:27:02 +0000] "GET /heapdump HTTP/2.0" 404 123 "-" "Mozilla/5.0 (iPad; CPU OS 12_4 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Mobile/15E148 Flipboard/4.2.48"
35.199.8.24 - - [13/Jun/2026:11:27:02 +0000] "GET /configprops HTTP/2.0" 404 185 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_11_6) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/54.0.2840.98 Safari/537.36"
35.199.8.24 - - [13/Jun/2026:11:27:02 +0000] "GET /logfile HTTP/2.0" 404 123 "-" "Mozilla/5.0 (X11; CentOS; Linux x86_64; rv:36.0) Gecko/20100101 Firefox/36.0"
35.199.8.24 - - [13/Jun/2026:11:27:02 +0000] "GET /threaddump HTTP/2.0" 404 185 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) snap Chromium/76.0.3809.87 Chrome/76.0.3809.87 Safari/537.36"
35.199.8.24 - - [13/Jun/2026:11:27:02 +0000] "GET /env HTTP/2.0" 404 123 "-" "Mozilla/5.0 (iPad; CPU OS 5_1 like Mac OS X) AppleWebKit/534.46 (KHTML, like Gecko ) Version/5.1 Mobile/9B176 Safari/7534.48.3"
35.199
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-06-13 11:06:44
(10 hours ago)
Scanning/Probing (61)
Request Overload (383)
Brute-Force
Web App Attack
๐ฌ๐ง
cg-design.co.uk
2026-06-13 10:48:26
(10 hours ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 35.199.8.24 (US/United S ...
show more
(apache-scanners) Failed apache-scanners trigger with match [redacted] from 35.199.8.24 (US/United States/24.8.199.35.bc.googleusercontent.com)
show less
Port Scan
๐ง๐ช
cmbplf
2026-06-13 10:24:18
(10 hours ago)
232 requests with url.path *credentials.json
191 requests with url.path *config.json
134 requests ...
show more
232 requests with url.path *credentials.json
191 requests with url.path *config.json
134 requests with url.path *config.yml
132 requests with url.path *compose.yml
125 requests with url.path *config.php
120 requests with url.path *secrets.json
show less
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-06-13 10:17:05
(11 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-13 09:27:31
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.199.8.24 (24.8.199.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.8.24 (24.8.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 05:27:25.051884 2026] [security2:error] [pid 1939:tid 1948] [client 35.199.8.24:50102] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||anointedtour.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "anointedtour.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ai0ifdbsuKw3yTEg0bD0uAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-06-13 09:27:27
(11 hours ago)
Aggressive web search of vulnerable pages: /secrets/aws.json /secrets/gcp.json /secrets/azure.json / ...
show more
Aggressive web search of vulnerable pages: /secrets/aws.json /secrets/gcp.json /secrets/azure.json /secrets/credentials.json /docker-compose.ym ...
show less
Web App Attack
๐จ๐ฆ
zXero
2026-06-13 08:50:17
(12 hours ago)
Fail2Ban automatic report - jail: web-exploit
Brute-Force
SSH
DDoS Attack
๐ฌ๐ง
consul.to
2026-06-13 07:54:56
(13 hours ago)
Web attack/malicious scanning detected
Web App Attack