๐บ๐ธ
TPI-Abuse
2026-09-10 03:42:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.234.54.222 (222.54.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.54.222 (222.54.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 23:42:08.407062 2026] [security2:error] [pid 17305:tid 17305] [client 35.234.54.222:1848] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.26"] [uri "/static../.env"] [unique_id "aqInEMh8A_OjI9D9gCUfVgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jormaster3k
2026-09-10 02:12:29
(1 day ago)
Attack against Apache (too many 404s)
Web App Attack
Anonymous
2026-09-10 02:00:05
(1 day ago)
| Common web attack.
Web App Attack
Hacking
SQL Injection
๐ณ๐ฑ
Savvii
2026-09-09 19:47:41
(1 day ago)
20 attempts against mh-misbehave-ban on joost-dev
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
KevinNeale
2026-09-09 16:49:55
(1 day ago)
Fail2Ban recidive block for repeated malicious authentication attempts.
Brute-Force
Web App Attack
๐จ๐ฆ
Mediashaker
2026-09-09 16:15:03
(1 day ago)
(CT) IP 35.234.54.222 (TW/Taiwan/222.54.234.35.bc.googleusercontent.com) found to have 713 connectio ...
show more
(CT) IP 35.234.54.222 (TW/Taiwan/222.54.234.35.bc.googleusercontent.com) found to have 713 connections
show less
DDoS Attack
๐ณ๐ด
Abuse Buster
2026-09-09 10:24:05
(2 days ago)
35.234.54.222 - - [09/Sep/2026:12:24:02 +0200] "GET /__aws_leak_probe_85db6bf4__ HTTP/1.1" 404 22 "- ...
show more
35.234.54.222 - - [09/Sep/2026:12:24:02 +0200] "GET /__aws_leak_probe_85db6bf4__ HTTP/1.1" 404 22 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user)"
35.234.54.222 - - [09/Sep/2026:12:24:03 +0200] "GET /static../.env HTTP/1.1" 404 22 "-" "Mozilla/5.0 (compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
35.234.54.222 - - [09/Sep/2026:12:24:03 +0200] "GET /media../.env HTTP/1.1" 404 22 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 18_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot) Version/19.4 Mobile/15E148 Safari/604.1"
...
show less
Web App Attack
๐น๐ท
pashait
2026-09-09 10:22:53
(2 days ago)
Auto-blocked by Seczar SecureOps โ IPS Web Attack Signature (38 events in 5min) at 2026-09-09 10:22
Web App Attack
Bad Web Bot
๐ช๐ธ
librebit
2026-09-09 09:21:52
(2 days ago)
Bad guys doing bad things, bad crawling
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-09 08:16:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.234.54.222 (222.54.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.54.222 (222.54.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 04:16:13.825613 2026] [security2:error] [pid 5277:tid 5277] [client 35.234.54.222:44098] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "192.64.150.234"] [uri "/static../.env"] [unique_id "aqEVzUo011MTty7BWJL_IgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-09 06:55:12
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ง๐พ
lns.bz
2026-09-09 05:19:29
(2 days ago)
.env scanning [BY]
Web App Attack
๐ฉ๐ช
dom4k
2026-09-09 02:54:46
(2 days ago)
2026-09-09T02:54:44.312218+00:00 dom4k.pro kernel: [2968774.269335] [UFW BLOCK] IN=ens3 OUT= MAC=52: ...
show more
2026-09-09T02:54:44.312218+00:00 dom4k.pro kernel: [2968774.269335] [UFW BLOCK] IN=ens3 OUT= MAC=52:54:00:ca:13:e8:02:00:00:00:00:01:08:00 SRC=35.234.54.222 DST=84.21.173.199 LEN=60 TOS=0x00 PREC=0x60 TTL=59 ID=64687 DF PROTO=TCP SPT=61186 DPT=9443 WINDOW=42600 RES=0x00 SYN URGP=0
2026-09-09T02:54:44.331833+00:00 dom4k.pro kernel: [2968774.288965] [UFW BLOCK] IN=ens3 OUT= MAC=52:54:00:ca:13:e8:02:00:00:00:00:01:08:00 SRC=35.234.54.222 DST=84.21.173.199 LEN=60 TOS=0x00 PREC=0x60 TTL=59 ID=60338 DF PROTO=TCP SPT=32268 DPT=8000 WINDOW=42600 RES=0x00 SYN URGP=0
2026-09-09T02:54:44.334866+00:00 dom4k.pro kernel: [2968774.289599] [UFW BLOCK] IN=ens3 OUT= MAC=52:54:00:ca:13:e8:02:00:00:00:00:01:08:00 SRC=35.234.54.222 DST=84.21.173.199 LEN=60 TOS=0x00 PREC=0x60 TTL=59 ID=55909 DF PROTO=TCP SPT=12098 DPT=9090 WINDOW=42600 RES=0x00 SYN URGP=0
2026-09-09T02:54:44.334980+00:00 dom4k.pro kernel: [2968774.289713] [UFW BLOCK] IN=ens3 OUT= MAC=52:54:00:ca:13:e8:02:00:00:00:00:01:08:00 SRC=35.234.5
...
show less
Port Scan
๐บ๐ธ
MPL
2026-09-09 01:57:00
(2 days ago)
tcp port scan (8 or more attempts)
Port Scan
Anonymous
2026-09-09 01:33:15
(2 days ago)
suricata IPS/IDS detection, ruleset ET WEB_SPECIFIC_APPS Vite Arbitrary File Read Via raw parameter ...
show more
suricata IPS/IDS detection, ruleset ET WEB_SPECIFIC_APPS Vite Arbitrary File Read Via raw parameter (CVE-2025-30208), ET WEB_SERVER Likely Malicious Request for /proc/self/environ, ET WEB_SPECIFIC_APPS Wordpress LiteSpeed Cache Plugin debug.log Access Attempt (CVE-2024-44000), ET WEB_SERVER WEB-PHP phpinfo access
show less
Port Scan