Anonymous
2026-09-16 13:45:02
(1 week ago)
Observed scanned 6 known-sensitive endpoint(s), e.g.: /.env, //.env, /@fs/../.env, /@fs/src/.env, /l ...
show more
Observed scanned 6 known-sensitive endpoint(s), e.g.: /.env, //.env, /@fs/../.env, /@fs/src/.env, /lib/terminal-xhr.php, /read-document
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-16 06:31:28
(1 week ago)
[ti-06al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail ngin ...
show more
[ti-06al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail nginx-404. Example: 35.229.91.79 - - [16/Sep/2026:08:31:26 +0200] "GET /user/login HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
35.229.91.79 - - [16/Sep/2026:08:31:26 +0200] "GET /signup HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
35.229.91.79 - - [16/Sep/2026:08:31:26 +0200] "GET /z9x8c7v6b5-debug-trigger-wpmailsmtp.nl HTTP/2.0" 404 1338 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
35.229.91.79 - - [16/Sep/2026:08:31:26 +0200] "GET /secure HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
palzer.IT
2026-09-16 06:07:03
(1 week ago)
Fail2ban automatic report for plesk-apache-badbot: 35.229.91.79 - - [16/Sep/2026:08:06:44 +0200] GET ...
show more
Fail2ban automatic report for plesk-apache-badbot: 35.229.91.79 - - [16/Sep/2026:08:06:44 +0200] GET /key.pem [DOMAIN_REMOVED] 303 5719 - Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +[DOMAIN_REMOVED]
show less
Bad Web Bot
๐ฆ๐บ
paulshipley.com.au
2026-09-16 06:00:59
(1 week ago)
[Wed Sep 16 16:00:57.543994 2026] [security2:error] [pid 347970] [client 35.229.91.79:33086] [client ...
show more
[Wed Sep 16 16:00:57.543994 2026] [security2:error] [pid 347970] [client 35.229.91.79:33086] [client 35.229.91.79] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "winesbydesign.com.au"] [uri "/.git/HEAD"] [unique_id "aqowmX6J731-dEOT0rgQuAAAAAU"]
...
show less
Web App Attack
๐ง๐พ
lns.bz
2026-09-16 04:45:20
(1 week ago)
Too many 404 requests [BY]
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-16 04:05:04
(1 week ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-16 03:43:19
(1 week ago)
[ti-01al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-01al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 35.229.91.79 - - [16/Sep/2026:05:43:06 +0200] "GET /.git/config HTTP/1.1" 404 2110 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
35.229.91.79 - - [16/Sep/2026:05:43:06 +0200] "GET /.aws/credentials HTTP/1.1" 404 2110 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
35.229.91.79 - - [16/Sep/2026:05:43:06 +0200] "GET /z9x8c7v6b5-debug-trigger-websels.com HTTP/1.1" 404 2110 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
35.229.91.79 - - [16/Sep/2026:05:43:06 +0200] "GET /.ssh/id_ed25519 HTTP/1.1" 404 2110 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
35.229.91.79 - - [16/Sep/2026
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 03:42:51
(1 week ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ฉ๐ช
netclix.gr
2026-09-16 03:21:19
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 35.229.91.79 (US/United States/79.91.22 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.229.91.79 (US/United States/79.91.229.35.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-16 02:52:15
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.229.91.79 (79.91.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.91.79 (79.91.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 22:52:07.652680 2026] [security2:error] [pid 2994:tid 2994] [client 35.229.91.79:36816] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wastetrack.io"] [uri "/appearance/../../.env"] [unique_id "aqoEV9vSngIy3eH7mmGTCgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 02:48:45
(1 week ago)
Blocked by ModSec and CSF
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-16 02:06:41
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.229.91.79 (79.91.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.91.79 (79.91.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 22:06:33.758967 2026] [security2:error] [pid 4137:tid 4137] [client 35.229.91.79:56242] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vrevgaming.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vrevgaming.net"] [uri "/rclone.conf"] [unique_id "aqn5qfNZebbVLAEvt8cuxwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2026-09-16 01:56:23
(1 week ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-16 01:22:24
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.229.91.79 (79.91.229.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.91.79 (79.91.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:22:20.557129 2026] [security2:error] [pid 12280:tid 12280] [client 35.229.91.79:60792] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vitess.com"] [uri "/.env.bak"] [unique_id "aqnvTGBHXjjUwtZUDLH0XwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Lentini
2026-09-16 01:16:41
(1 week ago)
visuitslagen.nl: malicious request:/.aws/credentials
Web App Attack