🇩🇪
Trueforce Threat Report
2026-09-06 21:06:02
(4 days ago)
Automated report, trolling for resource vulnerabilities
Bad Web Bot
Web App Attack
🇩🇪
TheDjRider
2026-09-06 20:52:15
(4 days ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-06T20:52:11.779916137Z. Context: http_status=404
show less
Web App Attack
🇳🇴
Abuse Buster
2026-09-06 18:29:59
(4 days ago)
35.236.147.29 - [06/Sep/2026:20:29:56 +0200] "GET /api/.env/public/.env HTTP/2.0" 403 146 "-" "Mozil ...
show more
35.236.147.29 - [06/Sep/2026:20:29:56 +0200] "GET /api/.env/public/.env HTTP/2.0" 403 146 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
35.236.147.29 - [06/Sep/2026:20:29:56 +0200] "GET /.//.env HTTP/2.0" 403 146 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
35.236.147.29 - [06/Sep/2026:20:29:56 +0200] "GET /wp-json HTTP/2.0" 404 1862 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
...
show less
Web App Attack
🇺🇸
mnsf
2026-09-06 18:05:17
(4 days ago)
Too many Status 40X (16)
Brute-Force
Web App Attack
🇺🇸
ArturShelby
2026-09-06 17:32:50
(4 days ago)
Critical file access: /.gitlab-ci.yml
Web App Attack
🇩🇪
bluematrix
2026-09-06 15:46:23
(4 days ago)
crowdsecurity/http-sensitive-files - Ip 35.236.147.29 performed 'crowdsecurity/http-sensitive-files' ...
show more
crowdsecurity/http-sensitive-files - Ip 35.236.147.29 performed 'crowdsecurity/http-sensitive-files' (5 events over 500.935226ms) at 2026-09-06 15:46:23.991387111 +0000 UTC
show less
Port Scan
Hacking
Brute-Force
Web App Attack
🇩🇪
TheDjRider
2026-09-06 14:12:34
(4 days ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-06T14:12:32.707527241Z. Context: http_status=404
show less
Web App Attack
🇺🇸
kbeezie
2026-09-06 13:48:11
(4 days ago)
35.236.147.29 - - [06/Sep/2026:09:48:07 -0400] "GET /service_account.json HTTP/1.1" 429 162 "-" "Moz ...
show more
35.236.147.29 - - [06/Sep/2026:09:48:07 -0400] "GET /service_account.json HTTP/1.1" 429 162 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
35.236.147.29 - - [06/Sep/2026:09:48:08 -0400] "GET /Dockerfile HTTP/1.1" 429 162 "https://www.karlblessing.com/Dockerfile" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
35.236.147.29 - - [06/Sep/2026:09:48:08 -0400] "GET /firebase-service-account.json HTTP/1.1" 429 162 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
35.236.147.29 - - [06/Sep/2026:09:48:08 -0400] "GET /firebase-adminsdk.json HTTP/1.1" 429 162 "https://www.karlblessing.com/firebase-adminsdk.json" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
35.236.147.29 - - [06/Sep/2026:09:48:11 -0400] "GET /id_ed25519 HTTP/1.1" 429 162 "https://www.karlblessing.com/id_ed25519" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 13:30:57
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 35.236.147.29 (29.147.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.147.29 (29.147.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 09:30:49.315647 2026] [security2:error] [pid 1230:tid 1230] [client 35.236.147.29:36770] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.steamboatrowena.com|F|2"] [data ".steamboatrowena.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.steamboatrowena.com"] [uri "/z9x8c7v6b5-debug-trigger-www.steamboatrowena.com"] [unique_id "ap1rCTY27TjaiLpBQsmYkgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 12:54:03
(4 days ago)
(mod_security) mod_security (id:210580) triggered by 35.236.147.29 (29.147.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 35.236.147.29 (29.147.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 08:53:57.066990 2026] [security2:error] [pid 15565:tid 15565] [client 35.236.147.29:53722] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||rustyog.net|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "rustyog.net"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "ap1iZXE04TIq9iDNyniGgwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 12:43:07
(4 days ago)
35.236.147.29 - - [06/Sep/2026:14:42:57 +0200] "GET /dist/.vite/manifest.json HTTP/1.1" 404 30085
35 ...
show more
35.236.147.29 - - [06/Sep/2026:14:42:57 +0200] "GET /dist/.vite/manifest.json HTTP/1.1" 404 30085
35.236.147.29 - - [06/Sep/2026:14:42:57 +0200] "GET /dist/manifest.json HTTP/1.1" 404 30085
35.236.147.29 - - [06/Sep/2026:14:42:57 +0200] "GET /z9x8c7v6b5-debug-trigger-crypcool.com HTTP/1.1" 404 30085
35.236.147.29 - - [06/Sep/2026:14:42:57 +0200] "GET /build/manifest.json HTTP/1.1" 404 30085
35.236.147.29 - - [06/Sep/2026:14:42:57 +0200] "GET /private-key HTTP/1.1" 404 30085
35.236.147.29 - - [06/Sep/2026:14:42:58 +0200] "GET /ssl/server.key HTTP/1.1" 404 28545
35.236.147.29 - - [06/Sep/2026:14:42:58 +0200] "GET /ssl/localhost.key HTTP/1.1" 404 28545
35.236.147.29 - - [06/Sep/2026:14:42:59 +0200] "POST /graphql HTTP/1.1" 404 27908
35.236.147.29 - - [06/Sep/2026:14:43:00 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/1.1" 404 29448
35.236.147.29 - - [06/Sep/2026:14:43:02 +0200] "POST /api/graphql HTTP/1.1" 404 27908
...
show less
Web Spam
Web App Attack
🇳🇴
Abuse Buster
2026-09-06 12:40:04
(4 days ago)
35.236.147.29 - - [06/Sep/2026:14:40:01 +0200] "GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/2.0 ...
show more
35.236.147.29 - - [06/Sep/2026:14:40:01 +0200] "GET /@fs/home/ubuntu/.aws/credentials?raw?? HTTP/2.0" 404 22 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
35.236.147.29 - - [06/Sep/2026:14:40:01 +0200] "GET /@fs/var/task/.env?raw?? HTTP/2.0" 404 22 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; GPTBot/1.3; +https://openai.com/gptbot)"
35.236.147.29 - - [06/Sep/2026:14:40:01 +0200] "GET /rclone.conf HTTP/2.0" 404 22 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot)"
...
show less
Web App Attack
Anonymous
2026-09-06 12:14:25
(4 days ago)
35.236.147.29 - - [06/Sep/2026:14:14:14 +0200] "GET /build/manifest.json HTTP/1.1" 404 30085
35.236. ...
show more
35.236.147.29 - - [06/Sep/2026:14:14:14 +0200] "GET /build/manifest.json HTTP/1.1" 404 30085
35.236.147.29 - - [06/Sep/2026:14:14:14 +0200] "GET /z9x8c7v6b5-debug-trigger-www.crypcool.com HTTP/1.1" 404 30085
35.236.147.29 - - [06/Sep/2026:14:14:14 +0200] "GET /dist/.vite/manifest.json HTTP/1.1" 404 30085
35.236.147.29 - - [06/Sep/2026:14:14:14 +0200] "GET /dist/manifest.json HTTP/1.1" 404 30085
35.236.147.29 - - [06/Sep/2026:14:14:16 +0200] "GET /api/fs/read?path=/app/.env&allowOutsideWorkspace=true HTTP/1.1" 404 29448
35.236.147.29 - - [06/Sep/2026:14:14:18 +0200] "GET /proc/self/cmdline HTTP/1.1" 404 30085
35.236.147.29 - - [06/Sep/2026:14:14:19 +0200] "GET /proc/self/cgroup HTTP/1.1" 404 30085
35.236.147.29 - - [06/Sep/2026:14:14:18 +0200] "GET /graphql HTTP/1.1" 404 30085
35.236.147.29 - - [06/Sep/2026:14:14:19 +0200] "GET /pages/index.astro.mjs.map HTTP/1.1" 404 30085
35.236.147.29 - - [06/Sep/2026:14:14:19 +0200] "GET /_astro/pages/index.astro.mjs.map HTTP/1.1" 404 30085
...
show less
Web Spam
Web App Attack
🇩🇪
Jarda_H
2026-09-06 11:54:43
(4 days ago)
http-probing
Web App Attack
🇩🇪
ValtonTahiri
2026-09-06 11:37:04
(4 days ago)
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly as ...
show more
UFW blocked a suspicious connection attempt to a closed or denied port. This activity is commonly associated with port scanning, service discovery, or automated internet probing. Technical: source_ip=35.236.147.29; proto=TCP; source_port=40574; target_port=8080; flags=SYN
show less
Port Scan