๐ฉ๐ช
itsolon
2026-10-08 20:40:07
(3 minutes ago)
[08/Oct/2026:22:40:05 +0200] 179149200510.178300 35.221.224.108 0 217.154.7.177 443
[08/Oct/2026:22: ...
show more
[08/Oct/2026:22:40:05 +0200] 179149200510.178300 35.221.224.108 0 217.154.7.177 443
[08/Oct/2026:22:40:05 +0200] 179149200576.716689 35.221.224.108 0 217.154.7.177 443
[08/Oct/2026:22:40:06 +0200] 179149200644.815470 35.221.224.108 0 217.154.7.177 443
[08/Oct/2026:22:40:06 +0200] 179149200619.061311 35.221.224.108 0 217.154.7.177 443
[08/Oct/2026:22:40:07 +0200] 179149200764.862684 35.221.224.108 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
palzer.IT
2026-10-08 20:30:46
(13 minutes ago)
Fail2ban automatic report for plesk-apache-badbot: 35.221.224.108 - - [08/Oct/2026:22:30:13 +0200] G ...
show more
Fail2ban automatic report for plesk-apache-badbot: 35.221.224.108 - - [08/Oct/2026:22:30:13 +0200] GET /3y1o5gei2h3a19oyprdm [DOMAIN_REMOVED] 404 6527 [DOMAIN_REMOVED] Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +[DOMAIN_REMOVED]
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-08 20:18:49
(25 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.221.224.108 (108.224.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.224.108 (108.224.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 16:18:42.089072 2026] [security2:error] [pid 18280:tid 18280] [client 35.221.224.108:48682] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shafie.net"] [uri "/.htpasswd"] [unique_id "asf6oqYm8I1WMM21Q2gVkgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 19:51:18
(52 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.221.224.108 (108.224.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.224.108 (108.224.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 15:51:12.781121 2026] [security2:error] [pid 10904:tid 10904] [client 35.221.224.108:52046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "schmitzcomm.net"] [uri "/css../.env"] [unique_id "asf0MOGoC8Y4wd5p3QmyngAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hagen Schoebel
2026-10-08 19:51:11
(52 minutes ago)
Blocked by CrowdSec - Enabling body inspection (TW)
Port Scan
Brute-Force
Web App Attack
SSH
๐ฉ๐ช
Viveronese
2026-10-08 19:35:21
(1 hour ago)
HTTP vulnerability scanning
Web App Attack
Anonymous
2026-10-08 19:30:04
(1 hour ago)
| [Dangerous/Taiwan] Aggressive IP 35.221.224.108 (~30 hits). Type: DoS Defender- Web server 400 err ...
show more
| [Dangerous/Taiwan] Aggressive IP 35.221.224.108 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-08 19:18:35
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.221.224.108 (108.224.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.224.108 (108.224.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 15:18:30.428873 2026] [security2:error] [pid 21633:tid 21633] [client 35.221.224.108:39354] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "royalchess.net"] [uri "/.htpasswd"] [unique_id "asfshg5dFgwi2NSCtbWANAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-10-08 19:16:43
(1 hour ago)
35.221.224.108 - - [08/Oct/2026:15:16:42 -0400] "GET /.ssh/id_rsa HTTP/1.1" 404 5521 "-" "Mozilla/5. ...
show more
35.221.224.108 - - [08/Oct/2026:15:16:42 -0400] "GET /.ssh/id_rsa HTTP/1.1" 404 5521 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
35.221.224.108 - - [08/Oct/2026:15:16:43 -0400] "GET /static../.env HTTP/1.1" 403 5508 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
35.221.224.108 - - [08/Oct/2026:15:16:43 -0400] "GET /media../.env HTTP/1.1" 403 5508 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
...
show less
Web App Attack
๐ฌ๐ง
consul.to
2026-10-08 19:10:01
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 18:54:56
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.221.224.108 (108.224.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.224.108 (108.224.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 14:54:54.063320 2026] [security2:error] [pid 7514:tid 7514] [client 35.221.224.108:58260] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "riccibuilders.net"] [uri "/.htpasswd"] [unique_id "asfm_rHJycUfvFaVWhvFhwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-10-08 18:50:13
(1 hour ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-10-08 18:31:58
(2 hours ago)
35.221.224.108 - - [08/Oct/2026:20:31:54 +0200] "GET /.bashrc HTTP/2.0" 404 295 "-" "Mozilla/5.0 App ...
show more
35.221.224.108 - - [08/Oct/2026:20:31:54 +0200] "GET /.bashrc HTTP/2.0" 404 295 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
35.221.224.108 - - [08/Oct/2026:20:31:54 +0200] "GET /api/.env/public/.env HTTP/2.0" 404 295 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
35.221.224.108 - - [08/Oct/2026:20:31:54 +0200] "GET /.zshrc HTTP/2.0" 403 298 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
35.221.224.108 - - [08/Oct/2026:20:31:54 +0200] "GET /%2eenv HTTP/2.0" 403 298 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
35.221.224.108 - - [08/Oct/2026:20:31:54 +0200] "GET /@fs/app/.env?raw?? HTTP/2.0" 403 298 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
35.221.224.108 - - [08/Oct/2026:20:31:54 +0200] "GET /..%2f.env HTTP/2.0" 404 295 "-" "Mo
show less
Web App Attack
Hacking
๐ฌ๐ง
spamverify.com
2026-10-08 18:31:57
(2 hours ago)
Honeypot Hit: WordPress Json
Web Spam
Blog Spam
Bad Web Bot
Web App Attack
๐ฌ๐ง
oja
2026-10-08 18:12:55
(2 hours ago)
Aggressive web scanner
Web App Attack