🇺🇸
dot.mg
2026-09-20 15:32:15
(20 hours ago)
Scan of vulnerable files
Web App Attack
🇺🇸
kosada.com
2026-09-20 15:18:39
(21 hours ago)
Repeated exploit attempts, for example: /.git/config /.git/config (HTTP/2.0 port 443, user agent: "M ...
show more
Repeated exploit attempts, for example: /.git/config /.git/config (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)")
show less
Web App Attack
🇪🇸
masterguru
2026-09-20 15:16:17
(21 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:user-agent. (1100000- ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
🇩🇪
ghostwarriors
2026-09-20 14:50:07
(21 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇩🇪
yitzhaq
2026-09-20 14:27:35
(21 hours ago)
35.229.228.211 - - [20/Sep/2026:16:27:33 +0200] "GET /env.json HTTP/2.0" 403 295 "-" "Mozilla/5.0 (M ...
show more
35.229.228.211 - - [20/Sep/2026:16:27:33 +0200] "GET /env.json HTTP/2.0" 403 295 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
35.229.228.211 - - [20/Sep/2026:16:27:33 +0200] "GET /debug/pprof HTTP/2.0" 403 295 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
35.229.228.211 - - [20/Sep/2026:16:27:33 +0200] "GET /actuator HTTP/2.0" 404 292 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
35.229.228.211 - - [20/Sep/2026:16:27:33 +0200] "GET /api/v1/models HTTP/2.0" 404 292 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
35.229.228.211 - - [20/Sep/2026:16:27:33 +0200] "GET /.well-known/jwks.json HTTP/2.0" 403 295 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
35
show less
Web App Attack
Hacking
🇺🇸
TPI-Abuse
2026-09-20 14:26:54
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.229.228.211 (211.228.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.228.211 (211.228.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:26:47.754435 2026] [security2:error] [pid 2933797:tid 2933797] [client 35.229.228.211:50856] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||anenchantingevening.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "anenchantingevening.com"] [uri "/z9x8c7v6b5-debug-trigger-anenchantingevening.com"] [unique_id "aq_tJ8URLjHmkB1VuPP8wwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 13:59:51
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.229.228.211 (211.228.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.228.211 (211.228.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:59:48.292371 2026] [security2:error] [pid 18778:tid 18778] [client 35.229.228.211:50768] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||andrewmcgrath.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "andrewmcgrath.com"] [uri "/z9x8c7v6b5-debug-trigger-andrewmcgrath.com"] [unique_id "aq_m1I4mJ3_YIxjr3P2QdAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 13:43:26
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.228.211 (211.228.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.228.211 (211.228.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:43:19.086030 2026] [security2:error] [pid 20310:tid 20310] [client 35.229.228.211:46460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "andrejblatnik.com"] [uri "/.env.production"] [unique_id "aq_i98euAD9Bew80ClrIxwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-20 13:31:20
(22 hours ago)
Restricted File Access Attempt. Matched phrase ".gitconfig" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
Anonymous
2026-09-20 13:27:38
(22 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇮🇹
ciccio diddo
2026-09-20 13:27:03
(22 hours ago)
High Burst multiple 40X port:Tcp/80,443
Brute-Force
Web App Attack
🇮🇹
VHosting
2026-09-20 13:25:04
(22 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-20 13:21:16
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.228.211 (211.228.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.228.211 (211.228.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:21:09.746206 2026] [security2:error] [pid 21239:tid 21239] [client 35.229.228.211:34438] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "andiamocomputers.com"] [uri "/backend/.env"] [unique_id "aq_dxQk1zOYOtp4oa6jZmAAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-20 13:08:12
(23 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-20 12:52:51
(23 hours ago)
Restricted File Access Attempt. Matched phrase ".aws/" at REQUEST_FILENAME. (930130-193)
Hacking
Web App Attack