๐ท๐ธ
pexodelic
2026-09-22 03:35:02
(5 days ago)
Automated report from web, SSH and FTP server logs: 980 requests probing for exposed secrets (.env, ...
show more
Automated report from web, SSH and FTP server logs: 980 requests probing for exposed secrets (.env, .git, config files); 432 distinct non-existent paths requested (wordlist scanning); 2894 HTTP 4xx responses. First reported 2026-09-21 15:05 UTC, last reported 2026-09-22 05:35 UTC; counts cover the current log rotation window.
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 02:02:09
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.224.34.226 (226.34.224.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.34.226 (226.34.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 22:02:01.343638 2026] [security2:error] [pid 18870:tid 18870] [client 35.224.34.226:44658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.willoughbywolf.com"] [uri "/.git/config"] [unique_id "arHhmbyZY9V3gbdyNUCZ5QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-22 01:56:47
(5 days ago)
35.224.34.226 - - [22/Sep/2026:01:56:43 +0000] "GET /.git/config HTTP/2.0" 403 16019 "https://graphq ...
show more
35.224.34.226 - - [22/Sep/2026:01:56:43 +0000] "GET /.git/config HTTP/2.0" 403 16019 "https://graphql.temporada-alta.com/.git/config" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
35.224.34.226 - - [22/Sep/2026:01:56:43 +0000] "GET /.gitlab-ci.yml HTTP/2.0" 403 16023 "https://graphql.temporada-alta.com/.gitlab-ci.yml" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
35.224.34.226 - - [22/Sep/2026:01:56:43 +0000] "GET /src/.env HTTP/2.0" 403 16019 "https://graphql.temporada-alta.com/src/.env" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
35.224.34.226 - - [22/Sep/2026:01:56:43 +0000] "GET /.git/HEAD HTTP/2.0" 403 16021 "https://graphql.temporada-alta.com/.git/HEAD" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
35.224.34.226 - - [22/Sep/2026:01:56:44 +0000] "GET /.aws/credentials HTTP/2.0" 403 16021 "https://graphql.temporada-alta.com/.aws/credentials" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 01:35:24
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.224.34.226 (226.34.224.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.224.34.226 (226.34.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:35:18.342259 2026] [security2:error] [pid 20302:tid 20302] [client 35.224.34.226:58668] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.z-mgmt.com|F|2"] [data ".z-mgmt.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.z-mgmt.com"] [uri "/z9x8c7v6b5-debug-trigger-www.z-mgmt.com"] [unique_id "arHbVkRqlW-x7K6whAi9CgAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 00:50:44
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.224.34.226 (226.34.224.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.34.226 (226.34.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:50:37.582498 2026] [security2:error] [pid 8908:tid 8908] [client 35.224.34.226:46420] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.30daysout.com"] [uri "/.git/config"] [unique_id "arHQ3UJs61YF6XhIPUpMwwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-22 00:14:38
(5 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 23:17:37
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.224.34.226 (226.34.224.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.224.34.226 (226.34.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:17:30.034804 2026] [security2:error] [pid 10965:tid 10965] [client 35.224.34.226:42706] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.tortoisehosting.com|F|2"] [data ".tortoisehosting.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.tortoisehosting.com"] [uri "/z9x8c7v6b5-debug-trigger-www.tortoisehosting.com"] [unique_id "arG7CicWDL0_2KNwOPgj2QAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-21 22:28:00
(5 days ago)
๐ฅ VERY AGGRESSIVE SCANNER probed over 400 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 22:08:58
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.224.34.226 (226.34.224.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.34.226 (226.34.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 18:08:53.360145 2026] [security2:error] [pid 5118:tid 5118] [client 35.224.34.226:60724] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "slimlaw.com"] [uri "/ml/.env"] [unique_id "arGq9SChuNKPwAhfUIkYQgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-21 21:44:41
(5 days ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - ๐ก Port Scan (Non Decay-Based)
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:37:30
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.224.34.226 (226.34.224.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.224.34.226 (226.34.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:37:23.685845 2026] [security2:error] [pid 29557:tid 29557] [client 35.224.34.226:42252] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.starcrestsales.com|F|2"] [data ".starcrestsales.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.starcrestsales.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.starcrestsales.com"] [unique_id "arGjk3omAwUC_ZWued4FmwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:21:12
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.224.34.226 (226.34.224.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.224.34.226 (226.34.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:21:07.935239 2026] [security2:error] [pid 32036:tid 32036] [client 35.224.34.226:57334] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.tradersworldmarket.com|F|2"] [data ".tradersworldmarket.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.tradersworldmarket.com"] [uri "/z9x8c7v6b5-debug-trigger-www.tradersworldmarket.com"] [unique_id "arGfwxjg9-bNGukvsHyW5QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:51:20
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 35.224.34.226 (226.34.224.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.224.34.226 (226.34.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:51:15.665767 2026] [security2:error] [pid 25913:tid 25913] [client 35.224.34.226:33658] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.zoesaadeh.com"] [uri "/@fs/app/.env"] [unique_id "arGYw6Gdeg48od5Ex4xuhQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-21 20:40:12
(5 days ago)
35.224.34.226 - - [21/Sep/2026:20:39:43 +0000] "GET /.git/config HTTP/2.0" 403 16019 "https://owa.te ...
show more
35.224.34.226 - - [21/Sep/2026:20:39:43 +0000] "GET /.git/config HTTP/2.0" 403 16019 "https://owa.temporada-alta.com/.git/config" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
35.224.34.226 - - [21/Sep/2026:20:39:43 +0000] "GET /.aws/config HTTP/2.0" 403 16019 "https://owa.temporada-alta.com/.aws/config" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
35.224.34.226 - - [21/Sep/2026:20:39:43 +0000] "GET /.env.local HTTP/2.0" 403 16020 "https://owa.temporada-alta.com/.env.local" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
35.224.34.226 - - [21/Sep/2026:20:39:43 +0000] "GET /var/.env HTTP/2.0" 403 16017 "https://owa.temporada-alta.com/var/.env" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
35.224.34.226 - - [21/Sep/2026:20:39:44 +0000] "GET /.env.backup HTTP/2.0" 403 16020 "https://owa.temporada-alta.com/.env.backu
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:01:06
(5 days ago)
(mod_security) mod_security (id:949110) triggered by 35.224.34.226 (226.34.224.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 35.224.34.226 (226.34.224.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:00:59.002042 2026] [security2:error] [pid 27120:tid 27120] [client 35.224.34.226:55618] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "taxijunkremoval.com"] [uri "/z9x8c7v6b5-debug-trigger-taxijunkremoval.com"] [unique_id "arGM-4J___6hN-0UgpGMXwAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack