๐บ๐ธ
micropedro
2026-09-24 14:15:07
(13 hours ago)
4 incidents: malicious activity. First: 2026-09-22 20:19, Last: 2026-09-24 10:15 UTC. Triggers: unkn ...
show more
4 incidents: malicious activity. First: 2026-09-22 20:19, Last: 2026-09-24 10:15 UTC. Triggers: unknown.
show less
Port Scan
๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-09-23 03:57:42
(1 day ago)
Automatically blocked after 2 security events. Observed sensitive configuration-file probes. Source: ...
show more
Automatically blocked after 2 security events. Observed sensitive configuration-file probes. Source: Cloudflare security controls.
show less
Hacking
Bad Web Bot
Web App Attack
๐ธ๐ฌ
mypatricks
2026-09-23 03:45:55
(1 day ago)
35.231.142.112 | Port: 11844 | DNS: 112.142.231.35.bc.googleusercontent.com 2026-09-23T11:45:54+08:0 ...
show more
35.231.142.112 | Port: 11844 | DNS: 112.142.231.35.bc.googleusercontent.com 2026-09-23T11:45:54+08:00 America/New_York | Abuse bots or crawlers | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1) HTTP/1.1 443 GET | URL: /@fs/root/.aws/credentials/?raw?? | Ref: https://xxxxxx/@fs/root/.aws/credentials?raw?? | Country: US/United States/-08:00 IP City: North Charleston a3f68f2a6be10d70-ATL/Atlanta, GA, United States 4 hits/3 secs Robots 2
show less
Brute-Force
Web App Attack
Blog Spam
Web Spam
Exploited Host
๐ซ๐ท
masterguru
2026-09-23 03:18:26
(2 days ago)
URL file extension is restricted by policy. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".asa/ .asax/ .ascx/ .axd/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .config/ .conf/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dll/ .dos/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .ini/ .key/ .licx/ .lnk/ .log/ .mdb/ .old/ .pass/ .pdb/ .pol/ .printer/ .pwd/ .rdb/ .resources/ .resx/ .sql/ .swp/ .sys/ .vb/ .vbs/ .vbproj/ .vsdisco/ .webinfo/ .xsd/ .xsx/" at TX:extension. (920440-135)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-23 03:00:21
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.231.142.112 (112.142.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.142.112 (112.142.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 23:00:15.723605 2026] [security2:error] [pid 13142:tid 13142] [client 35.231.142.112:45550] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||californiastarsfarm.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "californiastarsfarm.com"] [uri "/z9x8c7v6b5-debug-trigger-californiastarsfarm.com"] [unique_id "arNAvwluVj61_zPv2Bg_UgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
Asimar
2026-09-23 02:14:59
(2 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted]): (CF_ENABLE)
Bad Web Bot
๐บ๐ธ
kosada.com
2026-09-23 02:07:57
(2 days ago)
Repeated exploit attempts, for example: /@fs/src/.env?raw?? /.env (HTTP/2.0 port 443, user agent: "M ...
show more
Repeated exploit attempts, for example: /@fs/src/.env?raw?? /.env (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)")
show less
Web App Attack
๐บ๐ธ
interbiznw.com
2026-09-23 01:58:45
(2 days ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 01:49:25
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.231.142.112 (112.142.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.142.112 (112.142.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 21:49:22.184153 2026] [security2:error] [pid 13666:tid 13666] [client 35.231.142.112:47638] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cameronsol.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cameronsol.com"] [uri "/z9x8c7v6b5-debug-trigger-cameronsol.com"] [unique_id "arMwIi8PC1kFj4ckc41bKwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 01:43:44
(2 days ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 01:31:08
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.231.142.112 (112.142.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.142.112 (112.142.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 21:31:01.752887 2026] [security2:error] [pid 947:tid 947] [client 35.231.142.112:47012] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||camouflagebikinis.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "camouflagebikinis.com"] [uri "/z9x8c7v6b5-debug-trigger-camouflagebikinis.com"] [unique_id "arMr1VukA6Oq9etUKHPGPAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 00:44:18
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.231.142.112 (112.142.231.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.142.112 (112.142.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 20:44:11.998681 2026] [security2:error] [pid 3557:tid 3557] [client 35.231.142.112:40824] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||canaldumidi360.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "canaldumidi360.com"] [uri "/z9x8c7v6b5-debug-trigger-canaldumidi360.com"] [unique_id "arMg21H8d44nNeDHHXs8lAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-09-23 00:37:02
(2 days ago)
(PERMBLOCK) 35.231.142.112 (US/United States/112.142.231.35.bc.googleusercontent.com) has had more t ...
show more
(PERMBLOCK) 35.231.142.112 (US/United States/112.142.231.35.bc.googleusercontent.com) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
๐ช๐ธ
robotstxt
2026-09-22 23:51:03
(2 days ago)
35.231.142.112 - - [22/Sep/2026:23:51:01 +0000] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/proc/self/environ ...
show more
35.231.142.112 - - [22/Sep/2026:23:51:01 +0000] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="35.231.142.112"
35.231.142.112 - - [22/Sep/2026:23:51:01 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="35.231.142.112"
35.231.142.112 - - [22/Sep/2026:23:51:01 +0000] "GET /appearance/../../.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.231.142.112"
35.231.142.112 - - [22/Sep/2026:23:51:02 +0000] "GET /appearance/../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="35.231.142.112"
35.231.142.112 - - [22/Sep/2026:23:51:02 +0000] "GET /static/../../../a/../../../../.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.231.142.112"
...
show less
Web Spam
Web App Attack