🇧🇷
Halux
2026-09-11 03:27:03
(14 minutes ago)
35.228.126.203 Web Application Firewall multiple violations
Hacking
Web App Attack
🇩🇪
Skyrider
2026-09-11 03:25:05
(16 minutes ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
🇫🇷
Baking333
2026-09-11 02:10:57
(1 hour ago)
[redacted] 35.228.126.203 - - [11/Sep/2026:03:10:55 +0100] "GET /.svn/entries HTTP/1.1" 302 1574 0/5 ...
show more
[redacted] 35.228.126.203 - - [11/Sep/2026:03:10:55 +0100] "GET /.svn/entries HTTP/1.1" 302 1574 0/57274 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://[redacted]/[redacted])" [redacted] 35.228.126.203 - - [11/Sep/2026:03:10:55 +0100] "GET / HTTP/1.1" 200 8279 0/106711 "https://[redacted]/.svn/entries" "Mozilla/5.0 (compatible; Google-Extended; +http://[redacted]/[redacted])"
show less
Bad Web Bot
Web App Attack
🇩🇪
Séfora Srl
2026-09-11 01:56:27
(1 hour ago)
crowdsecurity/http-bad-user-agent detected by CrowdSec
Bad Web Bot
Anonymous
2026-09-11 01:29:29
(2 hours ago)
35.228.126.203 - - [11/Sep/2026:03:29:20 +0200] "GET /build/manifest.json HTTP/1.1" 404 30086
35.228 ...
show more
35.228.126.203 - - [11/Sep/2026:03:29:20 +0200] "GET /build/manifest.json HTTP/1.1" 404 30086
35.228.126.203 - - [11/Sep/2026:03:29:21 +0200] "GET /dist/manifest.json HTTP/1.1" 404 30086
35.228.126.203 - - [11/Sep/2026:03:29:20 +0200] "GET /z9x8c7v6b5-debug-trigger-crypcool.com HTTP/1.1" 404 30086
35.228.126.203 - - [11/Sep/2026:03:29:21 +0200] "GET /dist/.vite/manifest.json HTTP/1.1" 404 30086
35.228.126.203 - - [11/Sep/2026:03:29:21 +0200] "GET /secrets.json HTTP/1.1" 404 30086
35.228.126.203 - - [11/Sep/2026:03:29:21 +0200] "GET /secrets.yml HTTP/1.1" 404 30086
35.228.126.203 - - [11/Sep/2026:03:29:22 +0200] "GET /service-account.json HTTP/1.1" 404 30086
35.228.126.203 - - [11/Sep/2026:03:29:22 +0200] "GET /credentials.json HTTP/1.1" 404 30086
35.228.126.203 - - [11/Sep/2026:03:29:23 +0200] "GET /key.json HTTP/1.1" 404 30086
35.228.126.203 - - [11/Sep/2026:03:29:23 +0200] "GET /serviceAccountKey.json HTTP/1.1" 404 30086
...
show less
Web Spam
Web App Attack
🇬🇧
consul.to
2026-09-11 01:23:24
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
🇳🇱
mieg
2026-09-11 01:22:42
(2 hours ago)
Web vulnerability probing
Brute-Force
Web App Attack
🇺🇸
countdownmail.com
2026-09-11 01:18:02
(2 hours ago)
Extensive web application scanning for vulnerabilities. Automated attack tool detected.
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 00:50:27
(2 hours ago)
(mod_security) mod_security (id:210580) triggered by 35.228.126.203 (203.126.228.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 35.228.126.203 (203.126.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 20:50:19.630752 2026] [security2:error] [pid 26406:tid 26406] [client 35.228.126.203:0] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".ssh/id_rsa" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||cloudex.click|F|2"] [data "Matched Data: .ssh/id_rsa found within ARGS:filename: file:/root/.ssh/id_rsa"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "cloudex.click"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqNQS93fjjWhBuCFBnWrSwAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-11 00:38:19
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
Anonymous
2026-09-11 00:28:21
(3 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇳🇱
Savvii
2026-09-11 00:23:33
(3 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
Marten Mark
2026-09-11 00:22:15
(3 hours ago)
35.228.126.203 - - [11/Sep/2026:00:22:14 +0000] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/ ...
show more
35.228.126.203 - - [11/Sep/2026:00:22:14 +0000] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/2.0" 404 23033 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
...
show less
Web App Attack
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-11 00:21:14
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.228.126.203 (203.126.228.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.228.126.203 (203.126.228.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 20:21:10.453245 2026] [security2:error] [pid 6592:tid 6592] [client 35.228.126.203:60748] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "certifiedfarmersmarkets.org"] [uri "/.git/config"] [unique_id "aqNJdo_PDMgw6JLKordV-AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
grassau.com
2026-09-11 00:20:53
(3 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.228.126.203 (FI/F ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.228.126.203 (FI/Finland/South Karelia Region/Lappeenranta/203.126.228.35.bc.googleusercontent.com)
show less
Bad Web Bot