๐บ๐ธ
TPI-Abuse
2026-10-09 04:05:05
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.152.200 (200.152.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.152.200 (200.152.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 00:04:56.432992 2026] [security2:error] [pid 30256:tid 30256] [client 35.229.152.200:46816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.volkerjahn.link"] [uri "/api/.env/public/.env"] [unique_id "ashn6ENDO50E_PkGqnFo9QAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
simpeg-adm.bandung.go.id
2026-10-09 03:36:32
(1 day ago)
09/Oct/2026:03:36:31 +0000;35.229.152.200;"/z9x8c7v6b5-debug-trigger-app.timrecht.au"
09/Oct/2026:03 ...
show more
09/Oct/2026:03:36:31 +0000;35.229.152.200;"/z9x8c7v6b5-debug-trigger-app.timrecht.au"
09/Oct/2026:03:36:31 +0000;35.229.152.200;"/0m0lyyk0x3wu76a0a0x5"
09/Oct/2026:03:36:31 +0000;35.229.152.200;"/.vite/manifest.json"
09/Oct/2026:03:36:31 +0000;35.229.152.200;"/lib/terminal-xhr.php"
09/Oct/2026:03:36:31 +0000;35.229.152.200;"/7yhwd52va02pudg6xhts"
09/Oct/2026:03:36:31 +0000;35.229.152.200;"/dist/.vite/manifest.json"
09/Oct/2026:03:36:31 +0000;35.229.152.200;"/dist/manifest.json"
...
show less
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
snappic
2026-10-09 03:35:37
(1 day ago)
Scanning for .env files [GET /api/fs/read?allowOutsideWorkspace=true&path=/app/.env] [Mozilla/5.0 (c ...
show more
Scanning for .env files [GET /api/fs/read?allowOutsideWorkspace=true&path=/app/.env] [Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)]
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 02:38:32
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.152.200 (200.152.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.152.200 (200.152.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 22:38:28.621586 2026] [security2:error] [pid 12389:tid 12389] [client 35.229.152.200:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ac.cloudex.link"] [uri "/.htpasswd"] [unique_id "ashTpMxpAP6oYpNU6q5UMQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
Scrapline
2026-10-09 02:32:35
(1 day ago)
[Fail2Ban] nginx-scraper: banned after 5 failures
Web App Attack
Anonymous
2026-10-09 02:19:15
(1 day ago)
Automated report (2026-10-09T10:19:15+08:00). Scraper detected. AI scanner notorious for flooding an ...
show more
Automated report (2026-10-09T10:19:15+08:00). Scraper detected. AI scanner notorious for flooding and DDoS attacks detected.
show less
Bad Web Bot
DDoS Attack
๐ฉ๐ช
ger-stg-sifi1
2026-10-09 00:17:03
(1 day ago)
(wordpress) Failed wordpress login using wp-login.php or xmlrpc.php
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 22:17:35
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.152.200 (200.152.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.152.200 (200.152.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 18:17:31.445458 2026] [security2:error] [pid 10910:tid 10910] [client 35.229.152.200:52650] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "newlife.org.au"] [uri "/.htpasswd"] [unique_id "asgWe6CWhuP-hn08_IV8hwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
A.i.D.A.N.N
2026-10-08 22:11:31
(1 day ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web vulnerability scanning detected
Web App Attack
๐ฆ๐บ
foff
2026-10-08 21:19:28
(1 day ago)
Source IP: 35.229.152.200 (TW/Google LLC). Web application attack detected by OWASP CRS (local file ...
show more
Source IP: 35.229.152.200 (TW/Google LLC). Web application attack detected by OWASP CRS (local file inclusion). Attack observed 2026-10-09T08:19:28+11:00.
show less
Web App Attack
๐ฆ๐บ
paulshipley.com.au
2026-10-08 21:07:19
(1 day ago)
[Fri Oct 09 08:07:19.075393 2026] [security2:error] [pid 572209] [client 35.229.152.200:56588] [clie ...
show more
[Fri Oct 09 08:07:19.075393 2026] [security2:error] [pid 572209] [client 35.229.152.200:56588] [client 35.229.152.200] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "levellapromotions.com.au"] [uri "/.ssh/id_rsa"] [unique_id "asgGB2LDn5VxMImWSZgE1wAAAAQ"]
...
show less
Web App Attack
๐ฆ๐บ
Klaverstyn
2026-10-08 20:28:45
(1 day ago)
Excessive HTTP request rate
Web App Attack
๐ฆ๐บ
screwlooseit.com.au
2026-10-08 19:56:37
(1 day ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
200.152.229.35.bc.googleusercontent.com
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 19:47:49
(1 day ago)
(mod_security) mod_security (id:210580) triggered by 35.229.152.200 (200.152.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 35.229.152.200 (200.152.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 15:47:43.746964 2026] [security2:error] [pid 14689:tid 14689] [client 35.229.152.200:46996] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||joyflightsunshinecoast.com.au|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "joyflightsunshinecoast.com.au"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "asfzX0_TYgo6y0Ethfj1CAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-10-08 19:44:43
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking