Anonymous
2026-09-18 03:46:23
(2 days ago)
Bad Web Bot
Anonymous
2026-09-17 03:46:15
(3 days ago)
Bad Web Bot
Anonymous
2026-09-15 03:46:07
(5 days ago)
Bad Web Bot
๐ฉ๐ช
creoline GmbH
2026-09-14 07:31:50
(5 days ago)
[WAF] Multiple suspicious HTTP requests has been blocked
Bad Web Bot
Web App Attack
Anonymous
2026-09-14 00:05:07
(6 days ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
Anonymous
2026-09-13 20:59:26
(6 days ago)
Detected by CrowdSec: crowdsecurity/http-sensitive-files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 20:28:07
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.236.137.187 (187.137.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.137.187 (187.137.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 16:27:59.741259 2026] [security2:error] [pid 25810:tid 25810] [client 35.236.137.187:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nyemdr.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nyemdr.com"] [uri "/host.key"] [unique_id "aqcHTxdUWwZXl6hVLNCTfgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 19:55:43
(6 days ago)
(mod_security) mod_security (id:949110) triggered by 35.236.137.187 (187.137.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 35.236.137.187 (187.137.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 15:55:36.665593 2026] [security2:error] [pid 17818:tid 17818] [client 35.236.137.187:48898] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "hamiltonbookings.com"] [uri "/z9x8c7v6b5-debug-trigger-hamiltonbookings.com"] [unique_id "aqb_uL8lxIWKI9w6E5oDfQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
demomodule
2026-09-13 19:35:57
(6 days ago)
PrestaShop Security Module: suspicious probe path detected (/.git)
Web App Attack
๐บ๐ธ
robotstxt
2026-09-13 19:21:46
(6 days ago)
35.236.137.187 - - [13/Sep/2026:19:21:18 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 36189 "-" "M ...
show more
35.236.137.187 - - [13/Sep/2026:19:21:18 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 36189 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "35.236.137.187" edge="162.159.106.183"
35.236.137.187 - - [13/Sep/2026:19:21:18 +0000] "GET /.dockerenv HTTP/2.0" 403 2 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "35.236.137.187" edge="162.158.178.29"
35.236.137.187 - - [13/Sep/2026:19:21:19 +0000] "GET /.env.production?raw HTTP/2.0" 403 36190 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )" "35.236.137.187" edge="162.158.178.29"
35.236.137.187 - - [13/Sep/2026:19:21:19 +0000] "GET /.env.local?raw HTTP/2.0" 403 36190 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)" "35.236.137.187" edge="162.158.178.29"
35.236.137.187 - - [13/Sep/2026:19:21:19 +0000] "GET /.env.local?import&raw HTTP/2.0" 403 36233 "-" "Mozilla/5.0 (com
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-13 19:15:38
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.236.137.187 (187.137.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.137.187 (187.137.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 15:15:30.006921 2026] [security2:error] [pid 6738:tid 6738] [client 35.236.137.187:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bbproductionsonline.com"] [uri "/.git/config"] [unique_id "aqb2Ui0VCANJ9XNyq4zfrQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-09-13 18:55:15
(6 days ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TAY
2026-09-13 18:34:27
(6 days ago)
35.236.137.187 - - [14/Sep/2026:02:34:23 +0800] "GET /public/plugins/grafana-clock-panel/../../../.. ...
show more
35.236.137.187 - - [14/Sep/2026:02:34:23 +0800] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1" 400 2057 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
35.236.137.187 - - [14/Sep/2026:02:34:24 +0800] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 2057 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
35.236.137.187 - - [14/Sep/2026:02:34:24 +0800] "GET /api/w/admins/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1" 404 42794 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
35.236.137.187 - - [14/Sep/2026:02:34:25 +0800] "GET /api/w/default/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1" 404 48539 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
35.236.137.187 - - [14/Sep/2026:02:34:25 +0800] "GET /api/w/starter/jobs_u/get_lo
...
show less
Brute-Force
๐ซ๐ท
masterguru
2026-09-13 17:09:42
(6 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000-195)
show less
Bad Web Bot
๐ฉ๐ช
LRob
2026-09-13 17:05:37
(6 days ago)
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: ...
show more
Probing for secret files (.git, .env, credentials, database dumps, wp-config) | method: GET | path: /rclone.conf | 2026-09-13 17:05 UTC
show less
Hacking
Web App Attack