๐ณ๐ฟ
Antinson
2026-06-08 16:25:55
(5 days ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-08 15:42:23
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.236.206.194 (194.206.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.206.194 (194.206.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 11:42:16.136106 2026] [security2:error] [pid 23436:tid 23436] [client 35.236.206.194:36160] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.music.grhall.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.music.grhall.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aibi2A-6jYVnpDWBV70EAQAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Campus France
2026-06-08 14:44:11
(5 days ago)
[Mon Jun 08 16:44:10.468114 2026] [php:error] [pid 1851424] [client 35.236.206.194:60322] script '/v ...
show more
[Mon Jun 08 16:44:10.468114 2026] [php:error] [pid 1851424] [client 35.236.206.194:60322] script '/var/www/html/brume.org/phpinfo.php' not found or unable to stat
[Mon Jun 08 16:44:10.470583 2026] [php:error] [pid 1851200] [client 35.236.206.194:60326] script '/var/www/html/brume.org/info.php' not found or unable to stat
[Mon Jun 08 16:44:10.496352 2026] [php:error] [pid 1848289] [client 35.236.206.194:60328] script '/var/www/html/brume.org/php.php' not found or unable to stat
[Mon Jun 08 16:44:10.497279 2026] [php:error] [pid 1850212] [client 35.236.206.194:60330] script '/var/www/html/brume.org/test.php' not found or unable to stat
[Mon Jun 08 16:44:10.513665 2026] [php:error] [pid 1850781] [client 35.236.206.194:60334] script '/var/www/html/brume.org/debug.php' not found or unable to stat
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-08 11:26:44
(5 days ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-06-08 10:49:45
(5 days ago)
(caddyscan) Scanner path probe from 35.236.206.194 (US/United States/194.206.236.35.bc.googleusercon ...
show more
(caddyscan) Scanner path probe from 35.236.206.194 (US/United States/194.206.236.35.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 35.236.206.194 - - [08/Jun/2026:10:49:43 +0000] "GET /actuator/env HTTP/1.1"
[REDACTED] 200 2627 35.236.206.194 - - [08/Jun/2026:10:49:43 +0000] "GET /actuator/dump HTTP/1.1"
[REDACTED] 200 2627 35.236.206.194 - - [08/Jun/2026:10:49:43 +0000] "GET /actuator/httptrace HTTP/1.1"
[REDACTED] 200 2627 35.236.206.194 - - [08/Jun/2026:10:49:43 +0000] "GET /api/actuator/heapdump HTTP/1.1"
[REDACTED] 200 2627 35.236.206.194 - - [08/Jun/2026:10:49:43 +0000] "GET /api/actuator/env HTTP/1.1"
show less
Port Scan
๐ฉ๐ช
raph
2026-06-08 10:01:12
(5 days ago)
[PROTECTED PATHS] crawler credentials.ini, aws.ini, aws.yml, etc.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
wlt-blocker
2026-06-08 08:17:29
(5 days ago)
Unauthorized access to webpage admin
Web App Attack
๐ซ๐ท
dynamix
2026-06-08 07:16:01
(6 days ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
grassau.com
2026-06-08 05:56:29
(6 days ago)
*Port Scan* detected from 35.236.206.194 (US/United States/District of Columbia/Washington/194.206.2 ...
show more
*Port Scan* detected from 35.236.206.194 (US/United States/District of Columbia/Washington/194.206.236.35.bc.googleusercontent.com).
show less
Port Scan
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-06-08 05:30:02
(6 days ago)
SPAM - Bruteforce Attack - DDOS 5
Email Spam
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-08 05:27:35
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.236.206.194 (194.206.236.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.206.194 (194.206.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 01:27:28.706436 2026] [security2:error] [pid 1830:tid 1855] [client 35.236.206.194:49154] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||seasonsgreeters.net|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "seasonsgreeters.net"] [uri "/.config/gcloud/credentials.db"] [unique_id "aiZSwM-WlxznrXTWIq7WLgAAARc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Progetto1
2026-06-08 04:55:02
(6 days ago)
Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack
๐ฎ๐น
VHosting
2026-06-08 02:45:03
(6 days ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
0xffffffff
2026-06-08 02:39:06
(6 days ago)
[2026-06-08 05:39:00.688759] [authz_core:error] [pid 4192674:tid 133409301579456] [client 35.236.206 ...
show more
[2026-06-08 05:39:00.688759] [authz_core:error] [pid 4192674:tid 133409301579456] [client 35.236.206.194:0] AH01630: client denied by server configuration: /var/www/*/.aws , error_notes:config-files , URI:'/.aws/config'
[2026-06-08 05:39:00.693637] [authz_core:error] [pid 4192674:tid 133409276401344] [client 35.236.206.194:0] AH01630: client denied by server configuration: /var/www/*/.aws , error_notes:config-files , URI:'/.aws/credentials'
[2026-06-08 05:39:00.726822] [authz_core:error] [pid 11628:tid 133409301579456] [client 35.236.206.194:0] AH01630: client denied by server configuration: /var/www/*/.azure , error_notes:dot-files , URI:'/.azure/credentials'
[2026-06-08 05:39:00.811254] [authz_core:error] [pid 4192673:tid 133409268008640] [client 35.236.206.194:0] AH01630: client denied by server configuration: /var/www/*/config , error_notes:config-files , URI:'/config/.aws/credentials'
[2026-06-08 05:39:00.812239] [authz_core:error] [pid 11628:tid 133409293186752] [client 35.236.206.194:0] AH01630: client
show less
Web App Attack
Bad Web Bot
Anonymous
2026-06-08 02:10:13
(6 days ago)
Multiple web server 400 error codes from same source ip
Web App Attack