๐ฑ๐น
damorfati
2026-10-05 05:17:36
(4 hours ago)
ANNA automated report (scanning) | hacking - agent:Mozilla/5.0 (compatible; GrokBot/1.0; +https://x. ...
show more
ANNA automated report (scanning) | hacking - agent:Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/), body: null, method: GET, url: /i61s6p6k3mwlflrxwxs4
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-05 03:17:15
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.79.222 (222.79.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.79.222 (222.79.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 23:17:08.519041 2026] [security2:error] [pid 13202:tid 13202] [client 35.234.79.222:49006] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.sheldondesigns.info"] [uri "/.env.js"] [unique_id "asMWtHnYo_XhQgUtYAZwlgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
phoenix1jl96
2026-10-05 02:59:36
(6 hours ago)
2026/10/05 04:59:35 [error] 13476#13476: *22033 open() "/home/user-data/www/default/cgi-bin/php-cgi. ...
show more
2026/10/05 04:59:35 [error] 13476#13476: *22033 open() "/home/user-data/www/default/cgi-bin/php-cgi.exe" failed (2: No such file or directory), client: 35.234.79.222, server: autodiscover.dsatec.info, request: "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0", host: "autodiscover.dsatec.info"
2026/10/05 04:59:35 [error] 13476#13476: *22033 open() "/home/user-data/www/default/cgi-bin/php" failed (2: No such file or directory), client: 35.234.79.222, server: autodiscover.dsatec.info, request: "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0", host: "autodiscover.dsatec.info"
...
show less
DNS Compromise
DNS Poisoning
DDoS Attack
Ping of Death
Web Spam
Email Spam
Blog Spam
Port Scan
Hacking
Brute-Force
Bad Web Bot
SSH
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 02:54:32
(6 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.79.222 (222.79.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.79.222 (222.79.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 22:54:24.768008 2026] [security2:error] [pid 2870:tid 2870] [client 35.234.79.222:53886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.belgiophar.info"] [uri "/public../.env"] [unique_id "asMRYEA6pMeop6jfmzhnfwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-05 02:05:37
(7 hours ago)
2026/10/05 03:05:35 [error] 3069275#3069275: *120107 access forbidden by rule, client: 35.234.79.222 ...
show more
2026/10/05 03:05:35 [error] 3069275#3069275: *120107 access forbidden by rule, client: 35.234.79.222, server: [redacted], request: "GET /images../.env HTTP/2.0", host: "artesia.betatechnologies.info"
2026/10/05 03:05:35 [error] 3069275#3069275: *120107 access forbidden by rule, client: 35.234.79.222, server: [redacted], request: "GET /uploads../.env HTTP/2.0", host: "artesia.betatechnologies.info"
2026/10/05 03:05:35 [error] 3069275#3069275: *120107 access forbidden by rule, client: 35.234.79.222, server: [redacted], request: "GET /dist../.env HTTP/2.0", host: "artesia.betatechnologies.info"
show less
Brute-Force
Web App Attack
๐ซ๐ท
dwmp
2026-10-05 00:36:09
(8 hours ago)
Url probing: /pc5so4zzsy9fht8of5fz
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-04 23:07:07
(10 hours ago)
2026/10/05 00:07:05 [error] 3069275#3069275: *100032 access forbidden by rule, client: 35.234.79.222 ...
show more
2026/10/05 00:07:05 [error] 3069275#3069275: *100032 access forbidden by rule, client: 35.234.79.222, server: api.betatechnologies.info, request: "GET /public../.env HTTP/2.0", host: "api.betatechnologies.info"
2026/10/05 00:07:05 [error] 3069275#3069275: *100032 access forbidden by rule, client: 35.234.79.222, server: api.betatechnologies.info, request: "GET /js../.env HTTP/2.0", host: "api.betatechnologies.info"
2026/10/05 00:07:05 [error] 3069275#3069275: *100032 access forbidden by rule, client: 35.234.79.222, server: api.betatechnologies.info, request: "GET /build../.env HTTP/2.0", host: "api.betatechnologies.info"
show less
Brute-Force
Web App Attack
๐ง๐ท
radardatelecom
2026-10-04 22:26:02
(11 hours ago)
Blocked by Radar da Telecom firewall โ abuseipdb
Bad Web Bot
Web App Attack
๐ฉ๐ช
updown.io
2026-10-04 22:14:03
(11 hours ago)
{"level":"info","ts":1791152041.7500327,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1791152041.7500327,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.234.79.222","remote_port":"49732","client_ip":"35.234.79.222","proto":"HTTP/2.0","method":"POST","host":"aceforbiz.pro-epic.info","uri":"/v1/graphql","headers":{"Referer":["https://aceforbiz.pro-epic.info"],"Accept":["*/*"],"Accept-Language":["en-US,en;q=0.9"],"Sec-Ch-Ua":["\"Chromium\";v=\"153\", \"Google Chrome\";v=\"153\", \"Not_A Brand\";v=\"8\""],"Accept-Encoding":["gzip, deflate, br, zstd"],"Cookie":["REDACTED"],"Sec-Fetch-Site":["same-origin"],"Sec-Ch-Ua-Platform":["\"Android\""],"Sec-Ch-Ua-Mobile":["?1"],"Sec-Fetch-Dest":["empty"],"Content-Type":["application/json"],"Content-Length":["86"],"Sec-Fetch-Mode":["cors"],"Origin":["https://aceforbiz.pro-epic.info"],"Priority":["u=1, i"],"User-Agent":["Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"]},"tls":{"resumed":false,"version":772,"cipher_suit
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 21:25:20
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.79.222 (222.79.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.79.222 (222.79.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 17:25:13.553414 2026] [security2:error] [pid 3646:tid 3646] [client 35.234.79.222:41874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tavo.info"] [uri "/.env.example"] [unique_id "asLEOY_FJTVfwPM9VMRWxgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-04 21:23:33
(12 hours ago)
$f2bV_matches
Brute-Force
๐ณ๐ฑ
Savvii
2026-10-04 21:21:30
(12 hours ago)
20 attempts against mh-misbehave-ban on pf221116
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 21:04:59
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.79.222 (222.79.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.79.222 (222.79.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 17:04:53.949834 2026] [security2:error] [pid 8944:tid 8944] [client 35.234.79.222:32930] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "onlineteacher.info"] [uri "/.htpasswd"] [unique_id "asK_dVx96z3Ppzhis39i5AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
n2nguyenn2nguyen
2026-10-04 21:00:36
(12 hours ago)
Blocked by YFC Security on https://1904.brixzly.com โ type: rapid_scan_attempts
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-04 20:51:24
(12 hours ago)
Excessive multi-domain requests
Brute-Force