๐ช๐น
AlienBase
2026-05-28 23:44:00
(2 weeks ago)
35.205.8.252 - - [28/May/2026:01:32:52 +0000] "\x16\x03\x01\x05\xC2\x01\x00\x05\xBE\x03\x03\x22\x07t ...
show more
35.205.8.252 - - [28/May/2026:01:32:52 +0000] "\x16\x03\x01\x05\xC2\x01\x00\x05\xBE\x03\x03\x22\x07t<\x7F1\xF6\xD9\xDD@\xD8/47\x1D\x8D\xA3\x1B\x97\xFD\x94\x82\x99\x9D0\xBB\xA3\x90+\xB6c\xA2 \xFB7\xB6\xE7\xF2{\x15G/\x07\x8F\x18\xF8\xE7M\x5CH\xA9j\x88gXD\xB1\xB1\xE5A>\xF4\xC3\x12\x8E\x00\x1A\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC0\x13\xC0" 400 150 "->
35.205.8.252 - - [28/May/2026:01:32:52 +0000] "\x16\x03\x01\x05\xC2\x01\x00\x05\xBE\x03\x03\xF6)\x91\xEB\x95\xE4\xF6\x82^\xEB!&\x91N\xCD\x98\xB0YF\xEC\x14\xBEex\xFA\xB2C\x16\xAB\x0E\x17\xB6 \x0C\x97\x10\x1A\x0C\xCE\x98J\x08\xD8\xE2\xE09\x1D9\x9D\x1E\xCB\x16\xB8\xA9\xB4=\x87\x8F\xCC\xA5\x8B\xDB\xB8S\xE9\x00\x1A\xC0+\xC0/\xC0,\xC00\xCC\xA9\xCC\xA8\xC0\x09\xC>
35.205.8.252 - - [28/May/2026:01:32:52 +0000] "GET / HTTP/1.1" 403 146 "-" "Mozilla/5.0 (compatible; Crusader/1.0)"
35.205.8.252 - - [28/May/2026:01:32:53 +0000] "GET / HTTP/1.1" 301 162 "-" "Mozilla/5.0 (compatible; Crusader/1.0)"
35.205.8.252 - - [28/May/2026:01:32:58 +0000] "GET / HTTP/1.1" 301
show less
DDoS Attack
Bad Web Bot
Web App Attack
Hacking
Anonymous
2026-05-28 10:30:09
(2 weeks ago)
Aggressive web scan
Web App Attack
๐ซ๐ท
maxxsense
2026-05-28 02:04:56
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted] 35.205.8.252 (BE/Belgium/252.8.205.35.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.205.8.252 (BE/Belgium/252.8.205.35.bc.googleusercontent.com)
show less
SQL Injection
๐ณ๐ฑ
Savvii
2026-05-27 15:19:18
(3 weeks ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 14:05:47
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.205.8.252 (252.8.205.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.8.252 (252.8.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 10:05:42.826422 2026] [security2:error] [pid 31282:tid 31282] [client 35.205.8.252:37254] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.myemail.navy"] [uri "/.env.old"] [unique_id "ahb6NrLqByoYN1f54QNEogAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-27 10:30:43
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.205.8.252 (252.8.205.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.8.252 (252.8.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 06:30:36.857242 2026] [security2:error] [pid 8528:tid 8528] [client 35.205.8.252:55280] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.tarakanov.com"] [uri "/.env.prod"] [unique_id "ahbHzPLRUDSarl5WWW1sswAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Melle
2026-05-27 03:41:44
(3 weeks ago)
Blocked by CrowdSec | Scenario: crowdsecurity/http-sensitive-files | 35.205.8.252 triggered 5 events ...
show more
Blocked by CrowdSec | Scenario: crowdsecurity/http-sensitive-files | 35.205.8.252 triggered 5 events | Detected: 2026-05-27T03:41:42.430599707Z
show less
Web App Attack
Hacking
๐ฉ๐ช
XICTRON
2026-05-27 01:10:04
(3 weeks ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-26 23:22:52
(3 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.205.8.252 (252.8.205.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.8.252 (252.8.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 26 19:22:47.401303 2026] [security2:error] [pid 27327:tid 27327] [client 35.205.8.252:39670] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.albioncapitalfund.com"] [uri "/.env"] [unique_id "ahYrR2fqIpcshR_ZAAnmQAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack