๐ง๐ช
Ivo Vynckier
2026-09-21 16:47:00
(2 days ago)
35.234.33.56 - - [20/Sep/2026:16:34:19 +0200] "GET /.aws/credentials HTTP/2.0" 404 2143 "-" "Mozilla ...
show more
35.234.33.56 - - [20/Sep/2026:16:34:19 +0200] "GET /.aws/credentials HTTP/2.0" 404 2143 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
35.234.33.56 - - [20/Sep/2026:16:34:19 +0200] "GET /.aws/config HTTP/2.0" 404 2143 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
35.234.33.56 - - [20/Sep/2026:16:34:19 +0200] "GET /z9x8c7v6b5-debug-trigger-how-ocr-works.com HTTP/2.0" 404 2143 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
35.234.33.56 - - [20/Sep/2026:16:34:19 +0200] "GET /openapi.json HTTP/2.0" 404 2143 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
show less
Web App Attack
Anonymous
2026-09-21 06:04:08
(3 days ago)
35.234.33.56 - - [20/Sep/2026:08:53:10 -0500] "GET /.env.stage HTTP/1.1" 403 199 "-" "Mozilla/5.0 Ap ...
show more
35.234.33.56 - - [20/Sep/2026:08:53:10 -0500] "GET /.env.stage HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot" 172.68.87.39
35.234.33.56 - - [20/Sep/2026:08:53:14 -0500] "GET /.env.live HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" 172.68.87.39
35.234.33.56 - - [20/Sep/2026:08:53:15 -0500] "GET /.env.production HTTP/1.1" 403 199 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" 172.68.87.39
35.234.33.56 - - [20/Sep/2026:08:53:15 -0500] "GET /.env.local HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 172.68.87.38
35.234.33.56 - - [20/Sep/2026:08:53:15 -0500] "GET /.env.backup HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" 172.68.87.39
35.234.33.56 - - [20/Sep/2026:08:53:15 -0500] "GET /.env.www HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-09-21 04:17:44
(3 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 15:22:52
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.234.33.56 (56.33.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.33.56 (56.33.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:22:47.390062 2026] [security2:error] [pid 16362:tid 16403] [client 35.234.33.56:56324] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||htpsocal.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "htpsocal.com"] [uri "/z9x8c7v6b5-debug-trigger-htpsocal.com"] [unique_id "aq_6R7-qdCk1DcOY2_06egAAAcs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 15:04:27
(3 days ago)
IP matched detection query many 3xx errors.
Brute-Force
๐ณ๐ฑ
Savvii
2026-09-20 14:58:51
(3 days ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:44:41
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.234.33.56 (56.33.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.33.56 (56.33.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:44:35.698399 2026] [security2:error] [pid 26156:tid 26156] [client 35.234.33.56:41244] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||hppagewideprinting.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hppagewideprinting.com"] [uri "/z9x8c7v6b5-debug-trigger-hppagewideprinting.com"] [unique_id "aq_xUycXp1O-06drwTLyrQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-20 14:18:09
(3 days ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-20 14:11:41
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.33.56 (56.33.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.33.56 (56.33.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:11:36.218066 2026] [security2:error] [pid 3127:tid 3127] [client 35.234.33.56:42118] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "donaldcoleman.com"] [uri "/.env.backup"] [unique_id "aq_pmCA3uxhNZ_H8reNlEAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 13:59:00
(3 days ago)
Trying to access a WP site with invalid credentials
Hacking
Anonymous
2026-09-20 13:52:27
(3 days ago)
Web application attack detected.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:51:05
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.33.56 (56.33.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.33.56 (56.33.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:50:58.185233 2026] [security2:error] [pid 5347:tid 5347] [client 35.234.33.56:57290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blackjobsnetwork.com"] [uri "/.git/HEAD"] [unique_id "aq_kwhqy1iF1n_f4VikIUAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 13:45:04
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:34:15
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.33.56 (56.33.234.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.33.56 (56.33.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:34:11.588693 2026] [security2:error] [pid 4011:tid 4011] [client 35.234.33.56:47344] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "abbeygardensllandudno.com"] [uri "/.git/config"] [unique_id "aq_g00AeTA7FqoNzDJ9pIgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-20 13:30:19
(3 days ago)
Multiple WAF Violations
Web App Attack