Anonymous
2026-09-23 11:49:09
(1 day ago)
35.221.249.181 - - [22/Sep/2026:21:26:34 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 Ap ...
show more
35.221.249.181 - - [22/Sep/2026:21:26:34 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" 162.158.243.104
35.221.249.181 - - [22/Sep/2026:21:26:34 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )" 162.158.243.105
35.221.249.181 - - [22/Sep/2026:21:26:34 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" 162.158.243.105
35.221.249.181 - - [22/Sep/2026:21:26:35 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" 162.158.243.104
35.221.249.181 - - [22/Sep/2026:21:26:35 -0500] "GET /.env.production?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-23 03:26:16
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.221.249.181 (181.249.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.249.181 (181.249.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 23:26:09.352495 2026] [security2:error] [pid 13637:tid 13637] [client 35.221.249.181:59616] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.thainotarycalifornia.com|F|2"] [data ".thainotarycalifornia.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.thainotarycalifornia.com"] [uri "/z9x8c7v6b5-debug-trigger-www.thainotarycalifornia.com"] [unique_id "arNG0fdkJbynWPoE5irxVQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-23 02:34:05
(1 day ago)
20 attempts against mh-misbehave-ban on mensa
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ญ
thaizone.com
2026-09-23 01:29:22
(1 day ago)
Hacking attempts against websites (D1) #2
Web App Attack
Hacking
๐บ๐ธ
Penny Packer
2026-09-23 00:58:27
(1 day ago)
Fail2Ban apache-tripwires
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-23 00:30:45
(1 day ago)
cloudlinux2 fail2ban: 2026-09-23 02:09:34,399 fail2ban.actions [1598]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-23 02:09:34,399 fail2ban.actions [1598]: NOTICE [plesk-modsecurity] Unban 35.228.62.28cloudlinux2 fail2ban: 2026-09-23 02:11:31,242 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 35.221.249.181 - 2026-09-23 02:11:31cloudlinux2 fail2ban: 2026-09-23 02:11:31,218 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 35.221.249.181 - 2026-09-23 02:11:31cloudlinux2 fail2ban: 2026-09-23 02:11:31,721 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 35.221.249.181 - 2026-09-23 02:11:31cloudlinux2 fail2ban: 2026-09-23 02:11:31,527 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 35.221.249.181 - 2026-09-23 02:11:31cloudlinux2 fail2ban: 2026-09-23 02:11:31,769 fail2ban.filter [1598]: INFO [recidive] Found 35.221.249.181 - 2026-09-23 02:11:31cloudlinux2 fail2ban: 2026-09-23 02:11:31,505 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 35.221.249.181 - 2026-09-23 02:11:31cloudlinux2 fail2ban:
show less
Brute-Force
๐ฉ๐ช
itsolon
2026-09-22 23:15:57
(1 day ago)
[23/Sep/2026:01:15:54 +0200] 179011895494.928038 35.221.249.181 36366 217.154.7.177 443
[23/Sep/2026 ...
show more
[23/Sep/2026:01:15:54 +0200] 179011895494.928038 35.221.249.181 36366 217.154.7.177 443
[23/Sep/2026:01:15:54 +0200] 179011895458.772234 35.221.249.181 36366 217.154.7.177 443
[23/Sep/2026:01:15:56 +0200] 179011895613.556916 35.221.249.181 36366 217.154.7.177 443
[23/Sep/2026:01:15:56 +0200] 179011895645.710361 35.221.249.181 36366 217.154.7.177 443
[23/Sep/2026:01:15:56 +0200] 17901189560.066730 35.221.249.181 36366 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-22 23:00:07
(1 day ago)
Fail2Ban - [WAF]ModSecurity rule violation on modsecurity ... [wa01]
Hacking
SQL Injection
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-09-22 22:57:01
(1 day ago)
Fail2Ban - [WAF]ModSecurity rule violation on modsecurity ... [wa01,wa02]
Hacking
SQL Injection
Web App Attack
๐ฉ๐ช
crypto i trust, hold i must
2026-09-22 22:10:34
(1 day ago)
Web scanner path: /.aws/credentials
Web App Attack
๐ซ๐ท
tecnicorioja
2026-09-22 22:00:56
(1 day ago)
wp-login attack [22/Sep/2026:15:31:53
Brute-Force
Web App Attack
Anonymous
2026-09-22 21:16:54
(1 day ago)
malicious scanning tool activity
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-22 21:08:14
(1 day ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
Anonymous
2026-09-22 20:30:04
(1 day ago)
CrowdSec decision: crowdsecurity/http-sensitive-files (origin: crowdsec)
Web App Attack