πΈπ¬
Cloudkul Cloudkul
2026-08-17 00:54:27
(4 minutes ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
π²πΎ
Rizzy
2026-08-17 00:28:03
(30 minutes ago)
Multiple WAF Violations
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 23:56:57
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.233.208.61 (61.208.233.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.208.61 (61.208.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 19:56:53.556203 2026] [security2:error] [pid 17446:tid 17446] [client 35.233.208.61:48638] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pswebsite.com"] [uri "/.git/HEAD"] [unique_id "aoJORb6euQ-eAYS5DLM4sAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Mangelot Hosting
2026-08-16 23:01:34
(1 hour ago)
(wp_config_access) srv104 WordPress wp-config Scan 35.233.208.61 (US/United States/61.208.233.35.bc. ...
show more
(wp_config_access) srv104 WordPress wp-config Scan 35.233.208.61 (US/United States/61.208.233.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
πΊπΈ
mnsf
2026-08-16 21:05:13
(3 hours ago)
Scanning/Probing (12)
Brute-Force
Web App Attack
π©πͺ
DEV-DNS
2026-08-16 20:52:37
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
Anonymous
2026-08-16 20:14:15
(4 hours ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
π¨π
zynex
2026-08-16 20:01:53
(4 hours ago)
URL Probing: /.openclaw/.env
Web App Attack
π¬π§
Mendip_Defender
2026-08-16 20:01:34
(4 hours ago)
35.233.208.61 - - [16/Aug/2026:21:01:39 +0100] "GET /admin HTTP/1.1" 404 6355 "-" "Mozilla/5.0 (Wind ...
show more
35.233.208.61 - - [16/Aug/2026:21:01:39 +0100] "GET /admin HTTP/1.1" 404 6355 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
35.233.208.61 - - [16/Aug/2026:21:01:40 +0100] "GET /firebase-config.json HTTP/1.1" 404 6355 "-" "Mozilla/5.0 (compatible; Amzn-SearchBot/1.0; +https://developer.amazon.com/support/amazonbot)"
35.233.208.61 - - [16/Aug/2026:21:01:40 +0100] "GET /user/login HTTP/1.1" 404 6355 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
π©πͺ
maxpower
2026-08-16 19:10:32
(5 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.233.208.61 (US/United States/61.208.2 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.233.208.61 (US/United States/61.208.233.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.233.208.61 - - [16/Aug/2026:21:10:27 +0200] "GET /.aws/credentials HTTP/2.0" 500 724 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Claude-User/1.0; +mailto:[email protected] " "-" host=shoppingcenters.accademiam.com
show less
Port Scan
Anonymous
2026-08-16 18:56:46
(6 hours ago)
35.233.208.61 - - [17/Aug/2026:02:56:45 +0800] "GET /.env.example HTTP/1.1" 404 30479 "-" "Mozilla/5 ...
show more
35.233.208.61 - - [17/Aug/2026:02:56:45 +0800] "GET /.env.example HTTP/1.1" 404 30479 "-" "Mozilla/5.0 (compatible; GoogleOther; +http://www.google.com/bot.html)"
...
show less
Bad Web Bot
Web App Attack
π¬π§
noise.agency
2026-08-16 18:47:56
(6 hours ago)
35.233.208.61 (US/United States/61.208.233.35.bc.googleusercontent.com), more than 30 Apache 404 hit ...
show more
35.233.208.61 (US/United States/61.208.233.35.bc.googleusercontent.com), more than 30 Apache 404 hits
show less
Hacking
πΊπΈ
TPI-Abuse
2026-08-16 17:23:55
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.233.208.61 (61.208.233.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.233.208.61 (61.208.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 13:23:50.284190 2026] [security2:error] [pid 18620:tid 18620] [client 35.233.208.61:50698] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||shipthunder.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "shipthunder.com"] [uri "/z9x8c7v6b5-debug-trigger-shipthunder.com"] [unique_id "aoHyJq-fulGbGhk9lhm3QwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-08-16 15:59:06
(8 hours ago)
Web attack/malicious scanning detected
Web App Attack
π·π΄
clauss
2026-08-16 15:42:06
(9 hours ago)
35.233.208.61 - - [16/Aug/2026:18:42:05 +0300] "GET /.vscode/launch.json HTTP/2.0" 403 207 "-" "meta ...
show more
35.233.208.61 - - [16/Aug/2026:18:42:05 +0300] "GET /.vscode/launch.json HTTP/2.0" 403 207 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
35.233.208.61 - - [16/Aug/2026:18:42:06 +0300] "GET /config.json HTTP/2.0" 403 207 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Web App Attack