๐จ๐ญ
๐จ๐ญ Hosting
2026-10-01 05:10:20
(21 hours ago)
Automated WAF report: 200-300 blocked requests from this IP detected by our WAF.
Bad Web Bot
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-30 18:48:24
(1 day ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-09-30 18:10:35
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after high AbuseIPDB reputation + local blo ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after high AbuseIPDB reputation + local block policy. Evidence: High Abuse + Suspicion (47, Abuse: 95)
show less
Hacking
Exploited Host
Web App Attack
๐ซ๐ฎ
sibahota
2026-09-30 17:52:52
(1 day ago)
35.234.67.231 - - [30/Sep/2026:17:52:51 +0000] www.uniquestorerxl.com "GET /app/settings.py HTTP/1.1 ...
show more
35.234.67.231 - - [30/Sep/2026:17:52:51 +0000] www.uniquestorerxl.com "GET /app/settings.py HTTP/1.1" 403 37 0.000 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" - - - "http://www.uniquestorerxl.com"
35.234.67.231 - - [30/Sep/2026:17:52:52 +0000] www.uniquestorerxl.com "GET /data/.env HTTP/1.1" 403 37 0.000 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot" - - - "http://www.uniquestorerxl.com"
...
show less
Bad Web Bot
๐ฉ๐ช
IVski.com
2026-09-30 17:01:10
(1 day ago)
IVski WAF | Next.js Server Action probe
Hacking
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-09-30 15:46:44
(1 day ago)
854 requests with url.path *.env
Brute-Force
Bad Web Bot
๐ซ๐ท
IRISIO
2026-09-30 14:56:13
(1 day ago)
scans/SQL injection/spam posts : 2424 queries
Web App Attack
SQL Injection
Anonymous
2026-09-30 14:51:49
(1 day ago)
35.234.67.231 - - [30/Sep/2026:11:51:48 -0300] "GET /admin%2F.env HTTP/2.0" 403 1110 "-" "Mozilla/5. ...
show more
35.234.67.231 - - [30/Sep/2026:11:51:48 -0300] "GET /admin%2F.env HTTP/2.0" 403 1110 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
35.234.67.231 - - [30/Sep/2026:11:51:48 -0300] "GET /dashboard%2F.env HTTP/2.0" 403 1110 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
...
show less
Port Scan
Anonymous
2026-09-30 14:36:47
(1 day ago)
35.234.67.231 - - [30/Sep/2026:09:36:47 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (co ...
show more
35.234.67.231 - - [30/Sep/2026:09:36:47 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" 35.234.67.231
35.234.67.231 - - [30/Sep/2026:09:36:47 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36" 35.234.67.231
35.234.67.231 - - [30/Sep/2026:09:36:47 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" 35.234.67.231
35.234.67.231 - - [30/Sep/2026:09:36:47 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)" 35.234.67.231
35.234.67.231 - - [30/Sep/2026:09:36:47 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" 35.234.67.231
35.234.67.231 - - [30/Sep/2026:09:36:47 -0500] "GET /.env.production?import&raw HTTP/1.1" 403 199
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
paissangroup
2026-09-30 14:21:00
(1 day ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:59:20
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.234.67.231 (231.67.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.67.231 (231.67.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:59:12.580294 2026] [security2:error] [pid 32612:tid 32612] [client 35.234.67.231:55120] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "undergroundh2o.com"] [uri "/.htpasswd"] [unique_id "ar0VsEujCFl5xXsUc3GDVQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:08:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.234.67.231 (231.67.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.67.231 (231.67.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:08:02.662838 2026] [security2:error] [pid 14616:tid 14616] [client 35.234.67.231:43576] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.manzilly.com"] [uri "/core/.env"] [unique_id "ar0JsilbQzYnFMP9TkqQ0QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-30 12:40:03
(1 day ago)
[ti-14al] Web exploit scanning: 4 suspicious requests detected by fail2ban jail <name>. Example: 35. ...
show more
[ti-14al] Web exploit scanning: 4 suspicious requests detected by fail2ban jail <name>. Example: 35.234.67.231 - - \[30/Sep/2026:14:39:54 +0200\] "GET /.ssh/id_ed25519 HTTP/1.1" 403 521 "-" "Mozilla/5.0 \(compatible\; Amazonbot/0.1\; +https://developer.amazon.com/support/amazonbot\)"
35.234.67.231 - - \[30/Sep/2026:14:39:54 +0200\] "GET /.ssh/config HTTP/1.1" 404 518 "-" "Mozilla/5.0 \(compatible\; Meta-ExternalAgent/1.0\; +https://developers.facebook.com/docs/sharing/webmasters/crawler\)"
35.234.67.231 - - \[30/Sep/2026:14:39:54 +0200\] "GET /.htpasswd HTTP/1.1" 403 521 "-" "Mozilla/5.0 \(compatible\; Bravebot/1.0\; +https://brave.com/search/\)"
35.234.67.231 - - \[30/Sep/2026:14:39:54 +0200\] "GET /.ssh/id_rsa HTTP/1.1" 404 518 "-" "Mozilla/5.0 AppleWebKit/537.36 \(KHTML, like Gecko\; compatible\; ClaudeBot/1.0\
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:21:09
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.234.67.231 (231.67.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.67.231 (231.67.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:21:03.251790 2026] [security2:error] [pid 4095:tid 4095] [client 35.234.67.231:52398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.ussthresher.com"] [uri "/.env.prod"] [unique_id "arz-r0Uz2p3OOw4_8gvrcwAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
vanderhost
2026-09-30 12:02:25
(1 day ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/gcp-credentials. ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/gcp-credentials.json via rule: /config
show less
Web App Attack
Bad Web Bot