๐ง๐ท
radardatelecom
2026-10-05 22:27:04
(11 hours ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐บ๐ธ
leasj
2026-10-05 21:41:39
(11 hours ago)
Observed Scanned 46 known-sensitive endpoint(s), e.g.: /files../.env, /media../.env, /build../.env, ...
show more
Observed Scanned 46 known-sensitive endpoint(s), e.g.: /files../.env, /media../.env, /build../.env, /static../.env, /settings/.env.
show less
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-10-05 19:19:22
(14 hours ago)
35.203.7.124 - - [05/Oct/2026:14:19:21 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (com ...
show more
35.203.7.124 - - [05/Oct/2026:14:19:21 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" 35.203.7.124
35.203.7.124 - - [05/Oct/2026:14:19:21 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" 35.203.7.124
35.203.7.124 - - [05/Oct/2026:14:19:21 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 35.203.7.124
35.203.7.124 - - [05/Oct/2026:14:19:21 -0500] "GET /.env.production?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" 35.203.7.124
35.203.7.124 - - [05/Oct/2026:14:19:21 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" 35.203.7.124
35.203.7.124 - - [05/Oct/2026:14:19:21 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199 "
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-10-05 18:28:45
(15 hours ago)
crowdsecurity/http-probing
Web App Attack
๐บ๐ธ
deskpass.com
2026-10-05 18:16:21
(15 hours ago)
POST /index.php
Web App Attack
๐บ๐ธ
MakoWish
2026-10-05 17:35:29
(15 hours ago)
Fuzzing for misconfigured web servers.
Hacking
Web App Attack
๐ซ๐ท
regishoussin
2026-10-05 14:00:26
(19 hours ago)
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of ...
show more
Automated web scanning detected by Wazuh (rule 100241): repeated 400/404 errors from mass probing of admin/backdoor paths (e.g. wp-login.php, known CMS shell filenames) on an Apache web server, on 2026-10-05 14:00 UTC.
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-05 12:30:04
(21 hours ago)
CrowdSec decision: crowdsecurity/http-path-traversal-probing (origin: crowdsec)
Port Scan
Anonymous
2026-10-05 11:30:02
(22 hours ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
๐ฌ๐ง
Apache
2026-10-05 10:46:01
(22 hours ago)
(mod_security) mod_security (id:930130) triggered by 35.203.7.124 (CA/Canada/124.7.203.35.bc.googleu ...
show more
(mod_security) mod_security (id:930130) triggered by 35.203.7.124 (CA/Canada/124.7.203.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
SSH
Web App Attack
๐ช๐ธ
robotstxt
2026-10-05 09:35:28
(23 hours ago)
35.203.7.124 - - [05/Oct/2026:09:34:29 +0000] "GET /.env.local?import&raw HTTP/1.1" 403 0 "https://s ...
show more
35.203.7.124 - - [05/Oct/2026:09:34:29 +0000] "GET /.env.local?import&raw HTTP/1.1" 403 0 "https://segurosaegon.com/.env.local?import&raw" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "35.203.7.124"
35.203.7.124 - - [05/Oct/2026:09:34:31 +0000] "GET /.env.development?raw HTTP/1.1" 403 0 "https://segurosaegon.com/.env.development?raw" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" "35.203.7.124"
35.203.7.124 - - [05/Oct/2026:09:34:31 +0000] "GET /.env.production?raw HTTP/1.1" 403 0 "https://segurosaegon.com/.env.production?raw" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" "35.203.7.124"
35.203.7.124 - - [05/Oct/2026:09:34:25 +0000] "GET /.vite/manifest.json HTTP/1.1" 403 31 "https://segurosaegon.com/.vite/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36" "35.203.7.12
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 09:33:19
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.203.7.124 (124.7.203.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.203.7.124 (124.7.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 05:33:14.337280 2026] [security2:error] [pid 22300:tid 22326] [client 35.203.7.124:47128] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sea2er.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sea2er.com"] [uri "/z9x8c7v6b5-debug-trigger-sea2er.com"] [unique_id "asNu2gQn15MFDYTuXGKEaAAAAZI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
IRISIO
2026-10-05 08:32:45
(1 day ago)
scans/SQL injection/spam posts : 204 queries
Web App Attack
SQL Injection
Anonymous
2026-10-05 08:28:41
(1 day ago)
35.203.7.124 - - [05/Oct/2026:16:28:39 +0800] "GET /assets/manifest.json HTTP/1.1" 404 196 "-" "Mozi ...
show more
35.203.7.124 - - [05/Oct/2026:16:28:39 +0800] "GET /assets/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.203.7.124 - - [05/Oct/2026:16:28:40 +0800] "GET /asset-manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.203.7.124 - - [05/Oct/2026:16:28:40 +0800] "GET /static/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.203.7.124 - - [05/Oct/2026:16:28:40 +0800] "GET /dv46b39yeows52svdlgs HTTP/1.1" 404 196 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
35.203.7.124 - - [05/Oct/2026:16:28:40 +0800] "GET /webpack-stats.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 07:58:06
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.203.7.124 (124.7.203.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.203.7.124 (124.7.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 03:57:59.000082 2026] [security2:error] [pid 802:tid 802] [client 35.203.7.124:48076] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mainescentsecrets.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mainescentsecrets.com"] [uri "/z9x8c7v6b5-debug-trigger-mainescentsecrets.com"] [unique_id "asNYhmV25katcH6l6zXmyAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack