🇨🇭
dalslab ltd
2026-09-14 10:07:11
(1 day ago)
[14/Sep/2026:12:07:11 +0200] - 404 404 - GET https auth.dalslab.com "/z9x8c7v6b5-debug-trigger-auth. ...
show more
[14/Sep/2026:12:07:11 +0200] - 404 404 - GET https auth.dalslab.com "/z9x8c7v6b5-debug-trigger-auth.dalslab.com" [Client 35.234.33.19] [Length 1599] [Gzip -] [Sent-to 10.1.1.240] "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" "-"
[14/Sep/2026:12:07:11 +0200] - 404 404 - GET https auth.dalslab.com "/dist/.vite/manifest.json" [Client 35.234.33.19] [Length 1600] [Gzip -] [Sent-to 10.1.1.240] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-"
[14/Sep/2026:12:07:11 +0200] - 404 404 - GET https auth.dalslab.com "/dist/.vite/manifest.json" [Client 35.234.33.19] [Length 1600] [Gzip -] [Sent-to 10.1.1.240] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "-"
[14/Sep/2026:12:07:11 +0200] - 404 404 - GET https auth.dalslab.com "/api/settings" [Client 35.234.33.19] [Length 1601] [Gzip -] [Sent-to 10.1.1.240] "Mozil
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
🇮🇳
evicky2002
2026-09-14 06:00:01
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇲🇽
octageeks.com
2026-09-14 04:08:41
(1 day ago)
Wordpress malicious attack:[octablocked]
Web App Attack
🇦🇺
screwlooseit.com.au
2026-09-14 02:10:47
(1 day ago)
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/19.33.234.35.bc.googleusercontent ...
show more
Blocked by CSF 13 firewall - Rule: config-dotfile
US/United States/19.33.234.35.bc.googleusercontent.com
show less
Web App Attack
Anonymous
2026-09-13 18:25:46
(1 day ago)
malicious scanning tool activity
Web App Attack
🇩🇪
Holger
2026-09-13 18:12:58
(1 day ago)
Bruteforce WebAttack
Brute-Force
Web App Attack
🇧🇪
voormedia
2026-09-13 16:35:45
(1 day ago)
Accessed trap at '/.aws/config'
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-13 15:49:21
(2 days ago)
Bad bot ignoring robot.txt
Bad Web Bot
Anonymous
2026-09-13 15:22:22
(2 days ago)
[Sun Sep 13 17:22:21.069008 2026] [authz_core:error] [pid 21948] [client 35.234.33.19:34058] AH01630 ...
show more
[Sun Sep 13 17:22:21.069008 2026] [authz_core:error] [pid 21948] [client 35.234.33.19:34058] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun Sep 13 17:22:21.438661 2026] [authz_core:error] [pid 21948] [client 35.234.33.19:34058] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Sun Sep 13 17:22:21.715676 2026] [authz_core:error] [pid 21948] [client 35.234.33.19:34058] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 14:43:49
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.234.33.19 (19.33.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.33.19 (19.33.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 10:43:41.340662 2026] [security2:error] [pid 21578:tid 21578] [client 35.234.33.19:56188] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wizind.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wizind.com"] [uri "/z9x8c7v6b5-debug-trigger-wizind.com"] [unique_id "aqa2nf9Qpb7tD3njtxOGUgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
WizardsToolkit
2026-09-13 14:42:05
(2 days ago)
tried to access server backup files
Web App Attack
Anonymous
2026-09-13 14:26:52
(2 days ago)
35.234.33.19 - - [13/Sep/2026:22:26:52 +0800] "GET /dist/manifest.json HTTP/1.1" 404 196 "-" "Mozill ...
show more
35.234.33.19 - - [13/Sep/2026:22:26:52 +0800] "GET /dist/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
35.234.33.19 - - [13/Sep/2026:22:26:52 +0800] "GET /static/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
35.234.33.19 - - [13/Sep/2026:22:26:52 +0800] "GET /rclone.conf HTTP/1.1" 404 196 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
35.234.33.19 - - [13/Sep/2026:22:26:52 +0800] "GET /api/w/starter/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1" 404 196 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
35.234.33.19 - - [13/Sep/2026:22:26:52 +0800] "GET /api/w/default/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1" 404 196 "-" "Mozilla/5
...
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 14:12:14
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.234.33.19 (19.33.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.33.19 (19.33.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 10:12:07.378168 2026] [security2:error] [pid 28212:tid 28212] [client 35.234.33.19:48806] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||wisdomwfm.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wisdomwfm.com"] [uri "/z9x8c7v6b5-debug-trigger-wisdomwfm.com"] [unique_id "aqavNzSOcepXba8nkFUR7AAAADQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
palzer.IT
2026-09-13 14:05:09
(2 days ago)
Fail2ban automatic report for plesk-apache-badbot: 35.234.33.19 - - [13/Sep/2026:16:04:49 +0200] GET ...
show more
Fail2ban automatic report for plesk-apache-badbot: 35.234.33.19 - - [13/Sep/2026:16:04:49 +0200] GET /[DOMAIN_REMOVED] [DOMAIN_REMOVED] 303 5719 - Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; +claudebot@[DOMAIN_REMOVED])
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-13 13:49:19
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.234.33.19 (19.33.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.33.19 (19.33.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 09:49:09.269203 2026] [security2:error] [pid 18205:tid 18205] [client 35.234.33.19:37078] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wintercypher.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wintercypher.com"] [uri "/rclone.conf"] [unique_id "aqap1Tfm--JbDWxnyeyPNgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack