Anonymous
2026-09-22 00:10:14
(1 day ago)
{"reqId":"zZ37XJpLaCKlbgBVysxb","level":1,"time":"2026-09-22T02:10:12+02:00","remoteAddr":"35.221.17 ...
show more
{"reqId":"zZ37XJpLaCKlbgBVysxb","level":1,"time":"2026-09-22T02:10:12+02:00","remoteAddr":"35.221.170.48","user":"--","app":"core","method":"GET","url":"/","scriptName":"/index.php","message":"Trusted domain error. \"35.221.170.48\" tried to access using \"shield.khomri.com\" as host.","userAgent":"Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36","version":"35.0.0.10","data":{"app":"core"}}
{"reqId":"H7Ea20jqD6pj44fTlGWY","level":1,"time":"2026-09-22T02:10:12+02:00","remoteAddr":"35.221.170.48","user":"--","app":"core","method":"GET","url":"/z9x8c7v6b5-debug-trigger-shield.khomri.com","scriptName":"/index.php","message":"Trusted domain error. \"35.221.170.48\" tried to access using \"shield.khomri.com\" as host.","userAgent":"Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)","version":"35.0.0.10","data":{"app":"core"}}
{"reqId":"s3ctybMi02lpMd1oRrF9","level":1,"time":"2026-09-22T02:10:13+02:00","remote
...
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-21 21:49:38
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 35.221.170.48 (TW/Taiwan/48.170.221 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 35.221.170.48 (TW/Taiwan/48.170.221.35.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
kosada.com
2026-09-21 21:47:19
(1 day ago)
Repeated exploit attempts, for example: /graphql {x22queryx22:x22{ __schema { types { name fields { ...
show more
Repeated exploit attempts, for example: /graphql {x22queryx22:x22{ __schema { types { name fields { name args { name defaultValue } } } } }x22} (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36")
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-21 20:51:28
(1 day ago)
35.221.170.48 - - [21/Sep/2026:20:50:52 +0000] "GET /static/.env HTTP/2.0" 403 26793 "-" "Mozilla/5. ...
show more
35.221.170.48 - - [21/Sep/2026:20:50:52 +0000] "GET /static/.env HTTP/2.0" 403 26793 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "-" edge="35.221.170.48"
35.221.170.48 - - [21/Sep/2026:20:50:52 +0000] "GET /.git/config HTTP/2.0" 403 26758 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" "-" edge="35.221.170.48"
35.221.170.48 - - [21/Sep/2026:20:50:52 +0000] "GET /.aws/config HTTP/2.0" 403 26793 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "-" edge="35.221.170.48"
35.221.170.48 - - [21/Sep/2026:20:50:52 +0000] "GET /.git/HEAD HTTP/2.0" 403 26791 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)" "-" edge="35.221.170.48"
35.221.170.48 - - [21/Sep/2026:20:50:53 +0000] "GET /.git-credentials HTTP/2.0" 403 26793 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compat
...
show less
Web App Attack
Anonymous
2026-09-21 19:30:02
(1 day ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 18:58:23
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.221.170.48 (48.170.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.170.48 (48.170.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 14:58:15.564236 2026] [security2:error] [pid 581262:tid 581262] [client 35.221.170.48:55492] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "catholicshopper.com"] [uri "/.env.local"] [unique_id "arF-R4bvH2YxsoRCeYpqlgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hbrks
2026-09-21 15:43:33
(1 day ago)
98 attack(s) detected, such as these: {"event":"web_block","ip":"35.221.170.48","host":"www.marche-b ...
show more
98 attack(s) detected, such as these: {"event":"web_block","ip":"35.221.170.48","host":"www.marche-be.com","request":"POST /api/designer/v1/file-content HTTP/2.0","user_agent":"","reason":"Status-404","timestamp":"2026-09-21T15:43:33 00:00","logentry":"www.marche-be.com 35.221.170.48 - - [21/Sep/2026:15:43:33 0000] \"POST /api/designer/v1/file-content HTTP/2.0\" 404 153 \"-\" \"Mozilla/5.0 (compatible; cohere-ai; https://cohere.com/crawler)\" \"172.25.79.45:80\""} * Report Details *: https://p4u.xyz/6KRDJ32Q2SH/1* IP Details *: https://p4u.xyz/6KRDJ32Q2SH/2
show less
Web Spam
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 15:29:58
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.221.170.48 (48.170.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.170.48 (48.170.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:29:52.120545 2026] [security2:error] [pid 21089:tid 21089] [client 35.221.170.48:54772] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.jamesallenwalker.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "arFNcDjbZeEjcw46r0EyhwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
hbrks
2026-09-21 14:47:02
(1 day ago)
84 attack(s) detected, such as these: {"event":"web_block","ip":"35.221.170.48","host":"api.marche-b ...
show more
84 attack(s) detected, such as these: {"event":"web_block","ip":"35.221.170.48","host":"api.marche-be.com","request":"POST /api/templates/preview HTTP/2.0","user_agent":"","reason":"Status-404","timestamp":"2026-09-21T14:47:02 00:00","logentry":"api.marche-be.com 35.221.170.48 - - [21/Sep/2026:14:47:02 0000] \"POST /api/templates/preview HTTP/2.0\" 404 0 \"-\" \"Mozilla/5.0 (compatible; GrokBot/1.0; https://x.ai/)\" \"172.25.79.30:5000\""} * Report Details *: https://p4u.xyz/PKRTJACJFV6/1* IP Details *: https://p4u.xyz/PKRTJACJFV6/2
show less
Web Spam
Hacking
Bad Web Bot
Anonymous
2026-09-21 14:30:06
(1 day ago)
CrowdSec decision: crowdsecurity/http-bad-user-agent (origin: crowdsec)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-21 14:19:02
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.221.170.48 (48.170.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.170.48 (48.170.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:18:56.250401 2026] [security2:error] [pid 30877:tid 30877] [client 35.221.170.48:40074] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||voltbox.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "voltbox.com"] [uri "/z9x8c7v6b5-debug-trigger-voltbox.com"] [unique_id "arE80Kvw0cVncIXm_5cBBwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 14:12:30
(1 day ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐ณ๐ฑ
svr
2026-09-21 14:11:38
(1 day ago)
Abusive Automated Web Scanner
Web App Attack
๐ฌ๐ง
noise.agency
2026-09-21 14:08:54
(1 day ago)
35.221.170.48 (TW/Taiwan/48.170.221.35.bc.googleusercontent.com), more than 10 Apache 403 hits
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 13:58:25
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.221.170.48 (48.170.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.170.48 (48.170.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 09:58:22.132788 2026] [security2:error] [pid 12302:tid 12302] [client 35.221.170.48:49524] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.vvs-inc.com|F|2"] [data ".vvs-inc.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.vvs-inc.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.vvs-inc.com"] [unique_id "arE3_pybtvAZ8q_7pgpvLAAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack