๐จ๐ฑ
Fernando Soto
2026-10-01 03:05:26
(16 hours ago)
WAF propio vps1 (CL): sensx135 score 22 en 1h. sondeo rutas sensibles.
Web App Attack
๐ณ๐ฑ
EGP Abuse Dept
2026-09-30 05:08:18
(1 day ago)
Scanning for web/db/file exploits on www.crea-art.nl
SQL Injection
Bad Web Bot
Web App Attack
๐ฉ๐ช
creoline GmbH
2026-09-30 04:52:07
(1 day ago)
[WAF] Multiple suspicious HTTP requests has been blocked
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 04:44:08
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.233.185.222 (222.185.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.185.222 (222.185.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:44:01.442562 2026] [security2:error] [pid 17914:tid 17914] [client 35.233.185.222:48460] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "createbelieve.mroxygen.org"] [uri "/userfiles/x"] [unique_id "aryTkVIFc8ljIMjYFERZ5wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 04:02:25
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.233.185.222 (222.185.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.233.185.222 (222.185.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:02:17.421272 2026] [security2:error] [pid 25569:tid 25569] [client 35.233.185.222:38810] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||azcrittergetter.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "azcrittergetter.com"] [uri "/z9x8c7v6b5-debug-trigger-azcrittergetter.com"] [unique_id "aryJyT-I3LtHb5QQGYgk5QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-09-30 03:53:37
(1 day ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐จ๐ฑ
Fernando Soto
2026-09-30 03:05:32
(1 day ago)
WAF propio vps1 (CL): realtime_404x16,sensx153 score 22 en 1h. sondeo rutas sensibles, barrido 404.
Port Scan
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-09-30 02:44:10
(1 day ago)
35.233.185.222 - - [30/Sep/2026:03:44:10 +0100] "GET /@fs/../.env?raw?? HTTP/2.0" 401 410 "-" "Mozil ...
show more
35.233.185.222 - - [30/Sep/2026:03:44:10 +0100] "GET /@fs/../.env?raw?? HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
Anonymous
2026-09-30 02:15:08
(1 day ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 01:43:41
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.233.185.222 (222.185.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.233.185.222 (222.185.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:43:34.701491 2026] [security2:error] [pid 12528:tid 12528] [client 35.233.185.222:34328] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||crescentcitycafe.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "crescentcitycafe.com"] [uri "/z9x8c7v6b5-debug-trigger-crescentcitycafe.com"] [unique_id "arxpRssgfpDhhTDmJTozZgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-30 01:01:19
(1 day ago)
2.411 requests from abuseipdb.com blacklisted IP (1yr3mos4w)
Brute-Force
Bad Web Bot
๐ซ๐ฎ
Christopher Hughes
2026-09-30 00:32:12
(1 day ago)
35.233.185.222 - - [30/Sep/2026:01:32:11 +0100] "GET /@fs/src/.env?import&raw?? HTTP/2.0" 200 6012 " ...
show more
35.233.185.222 - - [30/Sep/2026:01:32:11 +0100] "GET /@fs/src/.env?import&raw?? HTTP/2.0" 200 6012 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-30 00:29:31
(1 day ago)
35.233.185.222 - - [30/Sep/2026:00:28:55 +0000] "GET /static/manifest.json HTTP/2.0" 403 33405 "http ...
show more
35.233.185.222 - - [30/Sep/2026:00:28:55 +0000] "GET /static/manifest.json HTTP/2.0" 403 33405 "https://ccoo.cat/static/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0" "35.233.185.222" edge="104.23.160.37"
35.233.185.222 - - [30/Sep/2026:00:28:55 +0000] "GET /manifest.json HTTP/2.0" 403 33418 "https://ccoo.cat/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0" "35.233.185.222" edge="104.23.160.37"
35.233.185.222 - - [30/Sep/2026:00:28:55 +0000] "GET /assets/manifest.json HTTP/2.0" 403 33368 "https://ccoo.cat/assets/manifest.json" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0" "35.233.185.222" edge="104.23.160.37"
35.233.185.222 - - [30/Sep/2026:00:28:56 +0000] "GET /webpack-stats.json HTTP/2.0" 403 33452 "https://ccoo.c
...
show less
Web App Attack
Anonymous
2026-09-29 22:31:09
(1 day ago)
git/env leak probe
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-29 22:04:56
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 35.233.185.222 (US/United States/222.185.233.35 ...
show more
(mod_security) mod_security (id:949110) triggered by 35.233.185.222 (US/United States/222.185.233.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack