๐ฉ๐ช
klaus_ph
2026-09-23 20:24:53
(5 days ago)
2026-09-23 03:50:19,865 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 35.229.158.2
...
Bad Web Bot
๐ท๐ธ
pexodelic
2026-09-21 11:53:54
(1 week ago)
Automated report from web, SSH and FTP server logs: 218 requests probing for exposed secrets (.env, ...
show more
Automated report from web, SSH and FTP server logs: 218 requests probing for exposed secrets (.env, .git, config files); 314 distinct non-existent paths requested (wordlist scanning); 662 HTTP 4xx responses. Reported by our automated log scan at 2026-09-21 11:32 UTC; counts cover the current log rotation window.
show less
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 15:21:02
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.229.158.2 (2.158.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.158.2 (2.158.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:20:58.866547 2026] [security2:error] [pid 12176:tid 12176] [client 35.229.158.2:48416] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rooksfamily.com"] [uri "/.env.js"] [unique_id "aq_52oN-YMGyeHJtvNGIAgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-20 15:14:05
(1 week ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-20 15:06:10
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 35.229.158.2 (TW/Taiwan/2.158.229.35.bc ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.229.158.2 (TW/Taiwan/2.158.229.35.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-20 15:05:15
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.229.158.2 (2.158.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.158.2 (2.158.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:05:09.579103 2026] [security2:error] [pid 11255:tid 11265] [client 35.229.158.2:40068] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||robotics4fun.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "robotics4fun.com"] [uri "/z9x8c7v6b5-debug-trigger-robotics4fun.com"] [unique_id "aq_2Jfgzif9WxphzZ7Q_dQAAAUU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2026-09-20 14:58:42
(1 week ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-20 14:50:07
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.229.158.2 (2.158.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.158.2 (2.158.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:50:01.445256 2026] [security2:error] [pid 11352:tid 11352] [client 35.229.158.2:36988] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ritterlien.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ritterlien.com"] [uri "/z9x8c7v6b5-debug-trigger-ritterlien.com"] [unique_id "aq_ymU0IPO8yK4GQYGs9rgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-20 14:40:12
(1 week ago)
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-20 14:34:40
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 14:29:59
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.229.158.2 (2.158.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.158.2 (2.158.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:29:52.338144 2026] [security2:error] [pid 2934595:tid 2934595] [client 35.229.158.2:39818] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rewirenetworks.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rewirenetworks.com"] [uri "/z9x8c7v6b5-debug-trigger-rewirenetworks.com"] [unique_id "aq_t4BUZKj0ghf0MmX4ZyAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:13:10
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.229.158.2 (2.158.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.158.2 (2.158.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:13:05.951739 2026] [security2:error] [pid 31393:tid 31393] [client 35.229.158.2:48760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rentstrippersindio.com"] [uri "/.env.local"] [unique_id "aq_p8dVHlt0-eNQmngQwJQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-20 14:08:22
(1 week ago)
35.229.158.2 - - [20/Sep/2026:10:08:22 -0400] "GET /.aws/credentials HTTP/1.1" 404 6304 "-" "Mozilla ...
show more
35.229.158.2 - - [20/Sep/2026:10:08:22 -0400] "GET /.aws/credentials HTTP/1.1" 404 6304 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐ด
clauss
2026-09-20 14:06:04
(1 week ago)
35.229.158.2 - - [20/Sep/2026:17:06:03 +0300] "GET /config.json HTTP/2.0" 301 0 "-" "Mozilla/5.0 (co ...
show more
35.229.158.2 - - [20/Sep/2026:17:06:03 +0300] "GET /config.json HTTP/2.0" 301 0 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
35.229.158.2 - - [20/Sep/2026:17:06:03 +0300] "GET /config.json HTTP/2.0" 404 14095 "https://remusazoitei.com/config.json" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
...
show less
Web App Attack
๐ฉ๐ช
LRob
2026-09-20 14:00:39
(1 week ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: / | 2026-09-20 14:00 UTC
show less
Bad Web Bot