๐ฉ๐ช
macrob
2026-10-08 17:56:00
(52 minutes ago)
2026/10/08 17:55:58 [error] 1030192#1030192: *30915958 access forbidden by rule, client: 35.204.126. ...
show more
2026/10/08 17:55:58 [error] 1030192#1030192: *30915958 access forbidden by rule, client: 35.204.126.29, server: fn.binixo.es, request: "GET /static//app/.env HTTP/2.0", host: "backend.pinpartners.net"
2026/10/08 17:55:58 [error] 1030189#1030189: *30915967 access forbidden by rule, client: 35.204.126.29, server: fn.binixo.es, request: "GET /files../.env HTTP/2.0", host: "backend.pinpartners.net"
2026/10/08 17:55:58 [error] 1030189#1030189: *30915967 access forbidden by rule, client: 35.204.126.29, server: fn.binixo.es, request: "GET /assets../.env HTTP/2.0", host: "backend.pinpartners.net"
...
show less
Web App Attack
๐ซ๐ท
guillaume illien
2026-10-08 17:36:29
(1 hour ago)
35.204.126.29 - - [08/Oct/2026:17:36:24 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2 ...
show more
35.204.126.29 - - [08/Oct/2026:17:36:24 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 166 "-" "-"
35.204.126.29 - - [08/Oct/2026:17:36:24 +0000] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 166 "-" "-"
35.204.126.29 - - [08/Oct/2026:17:36:24 +0000] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 166 "-" "-"
35.204.126.29 - - [08/Oct/2026:17:36:24 +0000] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 166 "-" "-"
35.204.126.29 - - [08/Oct/2026:17:36:24 +0000] "GET /resources/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 166 "-" "-"
35.204.126.29 - - [08/Oct/2026:17:36:28 +0000] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/proc/self/environ HTTP/1.1" 400 166 "-" "-"
35.204.126.29 - - [08/Oct/2026:17:36:28 +0000] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env HTTP/1.1" 400 166 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
๐ฉ๐ช
Bedios GmbH
2026-10-08 17:11:46
(1 hour ago)
Login credentials theft attempt
Hacking
Anonymous
2026-10-08 17:07:16
(1 hour ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-10-08 17:07:01
(1 hour ago)
2026-10-08 19:05:06 AH10244: invalid URI path (/public/plugins/text/../../../../../../../../proc/sel ...
show more
2026-10-08 19:05:06 AH10244: invalid URI path (/public/plugins/text/../../../../../../../../proc/self/environ) && 2026-10-08 19:05:08 AH10244: invalid URI path (/%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env) && 2026-10-08 19:05:08 AH10244: invalid URI path (/%2e%2e/%2e%2e/%2e%2e/%2e%2e/proc/self/environ) && 162 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-10-08 17:02:20
(1 hour ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-mnz6-1)
show less
Bad Web Bot
๐ฉ๐ช
itsolon
2026-10-08 17:01:26
(1 hour ago)
[08/Oct/2026:19:01:23 +0200] 179147888388.310808 35.204.126.29 0 217.154.7.177 443
[08/Oct/2026:19:0 ...
show more
[08/Oct/2026:19:01:23 +0200] 179147888388.310808 35.204.126.29 0 217.154.7.177 443
[08/Oct/2026:19:01:25 +0200] 179147888571.229831 35.204.126.29 0 217.154.7.177 443
[08/Oct/2026:19:01:26 +0200] 179147888653.373884 35.204.126.29 0 217.154.7.177 443
[08/Oct/2026:19:01:26 +0200] 17914788863.931320 35.204.126.29 0 217.154.7.177 443
[08/Oct/2026:19:01:26 +0200] 179147888639.676965 35.204.126.29 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 16:55:37
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.204.126.29 (29.126.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.126.29 (29.126.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 12:55:31.023258 2026] [security2:error] [pid 28189:tid 28189] [client 35.204.126.29:56860] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "poltorak.net"] [uri "/.htpasswd"] [unique_id "asfLAypRSYp3EcMCkRI4MwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-08 16:38:00
(2 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 16:30:51
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.204.126.29 (29.126.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.126.29 (29.126.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 12:30:45.070134 2026] [security2:error] [pid 29879:tid 29938] [client 35.204.126.29:39354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pinnaclemgmt.net"] [uri "/.htpasswd"] [unique_id "asfFNaNPK-5u11AV1c9W9gAAARY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-10-08 16:05:03
(2 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
Charlesiv
2026-10-08 16:00:20
(2 hours ago)
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from NL.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /images../.env
Timestamp: 2026-10-08T15:41:28Z
Ray ID: a4763ffaddce497f
UA: Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)
show less
Bad Web Bot
๐ซ๐ฎ
oh.mg
2026-10-08 16:00:16
(2 hours ago)
[Thu Oct 08 18:00:12.605793 2026] [security2:error] [pid 871109:tid 871116] [client 35.204.126.29:0] ...
show more
[Thu Oct 08 18:00:12.605793 2026] [security2:error] [pid 871109:tid 871116] [client 35.204.126.29:0] [client 35.204.126.29] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "eu.mmn.ca"] [uri "/"] [unique_id "ase-DDzX8bb04U82fft9igAAAIU"]
[Thu Oct 08 18:00:15.289980 2026] [security2:error] [pid 871109:tid 871118] [client 35.204.126.29:0] [client 35.204.126.29] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation
...
show less
Web App Attack
Bad Web Bot
Anonymous
2026-10-08 15:56:32
(2 hours ago)
404 burst scanner detected by fail2ban
...
Web App Attack
๐บ๐ธ
valornode
2026-10-08 15:53:10
(2 hours ago)
Detected by CrowdSec on www.iambrayden.net-47d88224: CrowdSec: crowdsecurity/http-bad-user-agent | A ...
show more
Detected by CrowdSec on www.iambrayden.net-47d88224: CrowdSec: crowdsecurity/http-bad-user-agent | ASN: 396982 (GOOGLE-CLOUD-PLATFORM) | Country: NL | Range: 35.204.0.0/15
show less
Brute-Force
SSH