๐ฏ๐ต
amyriad
2026-10-02 15:00:30
(6 hours ago)
35.236.242.56 - - [02/Oct/2026:15:00:29 +0000] "GET /.env.dev HTTP/1.1" 404 459 "-" "Mozilla/5.0 (co ...
show more
35.236.242.56 - - [02/Oct/2026:15:00:29 +0000] "GET /.env.dev HTTP/1.1" 404 459 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
35.236.242.56 - - [02/Oct/2026:15:00:30 +0000] "GET /wp/.env HTTP/1.1" 404 459 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
35.236.242.56 - - [02/Oct/2026:15:00:30 +0000] "GET /storage/.env HTTP/1.1" 404 459 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
...
show less
DDoS Attack
Hacking
Brute-Force
๐ฉ๐ช
updown.io
2026-10-02 12:17:49
(9 hours ago)
{"level":"info","ts":1790943466.822084,"logger":"http.log.access.log1","msg":"handled request","requ ...
show more
{"level":"info","ts":1790943466.822084,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.236.242.56","remote_port":"49868","client_ip":"35.236.242.56","proto":"HTTP/2.0","method":"GET","host":"md.status.dtcc.taipei","uri":"/config.json","headers":{"Cookie":["REDACTED"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"X-Nextjs-Data":["1"],"User-Agent":["Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"],"Accept-Encoding":["gzip"],"Accept":["*/*"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"h2","server_name":"md.status.dtcc.taipei","ech":false}},"bytes_read":0,"user_id":"","duration":0.000155616,"size":0,"status":429,"resp_headers":{"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"],"Retry-After":["1"]}}
{"level":"info","ts":1790943466.826252,"logger":"http.log.access.log1","msg":"ha
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 11:29:57
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.242.56 (56.242.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.242.56 (56.242.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:29:53.164426 2026] [security2:error] [pid 16464:tid 16464] [client 35.236.242.56:54022] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.winders.name"] [uri "/build/.env"] [unique_id "ar-VsU7cP696_YDKxwjNGAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
svr
2026-10-02 11:12:17
(10 hours ago)
Abusive Automated Web Scanner
Web App Attack
๐ฆ๐น
mindrider
2026-10-02 10:46:08
(10 hours ago)
35.236.242.56 - - [02/Oct/2026:12:46:06 +0200] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 2968 "-" "Mozi ...
show more
35.236.242.56 - - [02/Oct/2026:12:46:06 +0200] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 2968 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" "-"
35.236.242.56 - - [02/Oct/2026:12:46:06 +0200] "GET /@fs/src/.env?raw?? HTTP/1.1" 404 2968 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "-"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
onlyops.app
2026-10-02 09:00:09
(12 hours ago)
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-mods ...
show more
Web application firewall (ModSecurity) detected malicious traffic | detected by Fail2Ban (plesk-modsecurity jail) | onlyops.app
show less
Exploited Host
Anonymous
2026-10-02 08:20:06
(13 hours ago)
35.236.242.56 - - [02/Oct/2026:08:20:05 +0000] "GET /secrets.env HTTP/2.0" 404 663 "-" "DuckAssistBo ...
show more
35.236.242.56 - - [02/Oct/2026:08:20:05 +0000] "GET /secrets.env HTTP/2.0" 404 663 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 07:07:11
(14 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.242.56 (56.242.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.242.56 (56.242.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 03:07:05.906750 2026] [security2:error] [pid 31455:tid 31455] [client 35.236.242.56:39760] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stufflebeam.name"] [uri "/public../.env"] [unique_id "ar9YGfpG-BNStIsEI3CnAAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-02 06:27:02
(15 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 05:45:59
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.242.56 (56.242.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.242.56 (56.242.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 01:45:55.174595 2026] [security2:error] [pid 15856:tid 15856] [client 35.236.242.56:42046] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.graham.starkey.name"] [uri "/build/.env"] [unique_id "ar9FE9GL5IosP9iQFp0RdwAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-10-02 05:35:03
(16 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 05:24:34
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.242.56 (56.242.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.242.56 (56.242.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 01:24:27.991968 2026] [security2:error] [pid 6466:tid 6466] [client 35.236.242.56:54618] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.mark.rawlings.name"] [uri "/@fs/.env"] [unique_id "ar9AC1ZyItS2AkhiYGvWWwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
oja
2026-10-02 05:13:05
(16 hours ago)
Aggressive web scanner
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 04:58:41
(16 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.236.242.56 (56.242.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.242.56 (56.242.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 00:58:34.120523 2026] [security2:error] [pid 1347:tid 1452] [client 35.236.242.56:56198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.mailme.name"] [uri "/.env.development"] [unique_id "ar85-oX5hH89zUg3RJeZwQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
svr
2026-10-02 04:35:39
(17 hours ago)
HC-Flood Web Scanner
Web App Attack