๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-30 15:27:18
(25 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-30 15:23:41
(29 minutes ago)
(mod_security) mod_security (id:210492) triggered by 35.233.239.185 (185.239.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.239.185 (185.239.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:23:35.827819 2026] [security2:error] [pid 2384:tid 2391] [client 35.233.239.185:54744] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.nothingwithoutwater.com"] [uri "/.env.js"] [unique_id "ar0pd34ySs98-d2MmCGl0QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:49:46
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.233.239.185 (185.239.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.233.239.185 (185.239.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:49:40.620397 2026] [security2:error] [pid 9630:tid 9656] [client 35.233.239.185:58378] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.theyogicat.com"] [uri "/api/.env/public/.env"] [unique_id "ar0hhNKzO979YClGXiGvaAAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-30 14:49:17
(1 hour ago)
35.233.239.185 - - [30/Sep/2026:10:49:16 -0400] "GET /dist../.env HTTP/1.1" 403 5818 "-" "Mozilla/5. ...
show more
35.233.239.185 - - [30/Sep/2026:10:49:16 -0400] "GET /dist../.env HTTP/1.1" 403 5818 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
35.233.239.185 - - [30/Sep/2026:10:49:16 -0400] "GET /static../.env HTTP/1.1" 403 5818 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
35.233.239.185 - - [30/Sep/2026:10:49:16 -0400] "GET /media../.env HTTP/1.1" 403 5023 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:22:09
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.233.239.185 (185.239.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.233.239.185 (185.239.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:22:03.511013 2026] [security2:error] [pid 27805:tid 27805] [client 35.233.239.185:52088] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.thefrontporchoffering.com|F|2"] [data ".thefrontporchoffering.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.thefrontporchoffering.com"] [uri "/z9x8c7v6b5-debug-trigger-www.thefrontporchoffering.com"] [unique_id "ar0bC0Bz_LT8-PMxwp8ERQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 14:06:39
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.233.239.185 (185.239.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.233.239.185 (185.239.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:06:35.911784 2026] [security2:error] [pid 13028:tid 13028] [client 35.233.239.185:42874] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.desertrosedoves.com|F|2"] [data ".desertrosedoves.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.desertrosedoves.com"] [uri "/z9x8c7v6b5-debug-trigger-www.desertrosedoves.com"] [unique_id "ar0Xa5zWG77uUNMDMDxpSAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-30 14:00:23
(1 hour ago)
Excessive 404/403 errors
Brute-Force
๐ณ๐ฑ
Alt255
2026-09-30 13:39:05
(2 hours ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.233.239.185 - - [30/Sep/2026:15:39:01 +0200] "GET /static../.env HTTP/2.0" 403 346 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:27:28
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.233.239.185 (185.239.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.233.239.185 (185.239.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:27:20.672848 2026] [security2:error] [pid 19262:tid 19262] [client 35.233.239.185:50892] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.tgcindustrial.com|F|2"] [data ".tgcindustrial.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.tgcindustrial.com"] [uri "/z9x8c7v6b5-debug-trigger-www.tgcindustrial.com"] [unique_id "ar0OOOr5CKBZ1wVBFE0sNgAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-30 12:44:59
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
dot.mg
2026-09-30 11:22:05
(4 hours ago)
Scan of vulnerable files
Web App Attack
๐ฎ๐น
VHosting
2026-09-30 10:40:03
(5 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 10:39:26
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.233.239.185 (185.239.233.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.233.239.185 (185.239.233.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 06:39:18.599038 2026] [security2:error] [pid 27570:tid 27570] [client 35.233.239.185:53726] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||athome360.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "athome360.com"] [uri "/z9x8c7v6b5-debug-trigger-athome360.com"] [unique_id "arzm1pD1rzEuJle954VKZQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-30 10:27:39
(5 hours ago)
Multiple WAF Violations
Web App Attack