๐จ๐ฟ
SystemAdmin
2026-09-22 12:20:38
(37 minutes ago)
Doing bad things...
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-22 11:35:44
(1 hour ago)
Excessive multi-domain requests
Brute-Force
๐ฌ๐ง
consul.to
2026-09-22 11:29:27
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
robotstxt
2026-09-22 11:00:03
(1 hour ago)
35.229.254.218 - - [22/Sep/2026:10:59:14 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 36262 " ...
show more
35.229.254.218 - - [22/Sep/2026:10:59:14 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 36262 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "35.229.254.218" edge="162.159.106.123"
35.229.254.218 - - [22/Sep/2026:10:59:15 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/2.0" 403 36262 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" "35.229.254.218" edge="172.71.215.113"
35.229.254.218 - - [22/Sep/2026:10:59:16 +0000] "GET /@fs/root/.aws/credentials?raw?? HTTP/2.0" 403 36260 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" "35.229.254.218" edge="172.71.215.113"
35.229.254.218 - - [22/Sep/2026:10:59:16 +0000] "GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/2.0" 403 36260 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" "35.229.254.218" edge="172.71.215.113"
35.229.254.218 - - [22/Sep/2026:10:59:16 +0000] "GET /@fs/home/ec2-u
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 10:52:22
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.229.254.218 (218.254.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.254.218 (218.254.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:52:15.272937 2026] [security2:error] [pid 4818:tid 4818] [client 35.229.254.218:37222] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||caribbeancoders.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "caribbeancoders.com"] [uri "/z9x8c7v6b5-debug-trigger-caribbeancoders.com"] [unique_id "arJd3wl7QB3V1fG6NtG_5AAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 10:06:24
(2 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.229.254.218 (218.254.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 35.229.254.218 (218.254.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:06:17.339286 2026] [security2:error] [pid 15688:tid 15688] [client 35.229.254.218:56952] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "crazycontrols.com"] [uri "/z9x8c7v6b5-debug-trigger-crazycontrols.com"] [unique_id "arJTGZ62ubnTy0SnIEzPFQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
oralunal
2026-09-22 09:51:42
(3 hours ago)
IP banned by Fail2Ban in jail ente-suss ente.com-ssl_log mvfnds
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 09:31:08
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.229.254.218 (218.254.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.254.218 (218.254.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 05:31:02.066908 2026] [security2:error] [pid 24158:tid 24158] [client 35.229.254.218:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hvacs-aircon.com"] [uri "/.env.bak"] [unique_id "arJK1n2DxFp860XQN_omPAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-22 09:29:06
(3 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-22 09:20:09
(3 hours ago)
| [Dangerous/Taiwan] Aggressive IP 35.229.254.218 (~30 hits). Type: DoS Defender- Web server 400 err ...
show more
| [Dangerous/Taiwan] Aggressive IP 35.229.254.218 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
pachec
2026-09-22 09:15:48
(3 hours ago)
Automated vulnerability scanning blocked by fail2ban
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 09:14:14
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.229.254.218 (218.254.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.254.218 (218.254.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 05:14:10.972551 2026] [security2:error] [pid 24004:tid 24004] [client 35.229.254.218:51982] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kreweofhyatt.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kreweofhyatt.com"] [uri "/z9x8c7v6b5-debug-trigger-kreweofhyatt.com"] [unique_id "arJG4rn3RGifT4-TFZ5qJAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-22 09:10:03
(3 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:48:11
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.229.254.218 (218.254.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.254.218 (218.254.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:48:04.427104 2026] [security2:error] [pid 27826:tid 27920] [client 35.229.254.218:60160] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mylordsday.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mylordsday.com"] [uri "/z9x8c7v6b5-debug-trigger-mylordsday.com"] [unique_id "arJAxClrs2rSxYTIlYFEXgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 08:30:45
(4 hours ago)
35.229.254.218 - - [22/Sep/2026:08:30:44 +0000] "GET /web/.env HTTP/2.0" 404 14103 "-" "Mozilla/5.0 ...
show more
35.229.254.218 - - [22/Sep/2026:08:30:44 +0000] "GET /web/.env HTTP/2.0" 404 14103 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
...
show less
Bad Web Bot
Web App Attack