๐ฉ๐ช
Holger
2026-10-02 08:32:18
(1 day ago)
Bruteforce WebAttack
Brute-Force
Web App Attack
๐ท๐ธ
pexodelic
2026-09-30 04:05:02
(3 days ago)
Automated report from web, SSH and FTP server logs: 232 requests probing for exposed secrets (.env, ...
show more
Automated report from web, SSH and FTP server logs: 232 requests probing for exposed secrets (.env, .git, config files). First reported 2026-09-29 19:05 UTC, last reported 2026-09-30 06:05 UTC; counts cover the current log rotation window.
show less
Hacking
Web App Attack
๐ช๐ธ
robotstxt
2026-09-30 03:12:50
(3 days ago)
35.240.183.15 - - [30/Sep/2026:01:18:56 +0000] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1 ...
show more
35.240.183.15 - - [30/Sep/2026:01:18:56 +0000] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 189 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "-" edge="35.240.183.15"
35.240.183.15 - - [30/Sep/2026:01:18:57 +0000] "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/1.1" 404 189 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" "-" edge="35.240.183.15"
35.240.183.15 - - [30/Sep/2026:01:18:57 +0000] "POST /cgi-bin/php-cgi?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1" 404 189 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" "-" edge="35.240.183.15"
35.240.183.15 - - [30/Sep/2026:01:18:58 +0000] "POST /cgi-bin/php?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input HTTP/1.1" 404 189 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.g
...
show less
Bad Web Bot
๐ฉ๐ช
Holger
2026-09-30 02:47:48
(3 days ago)
Bruteforce WebAttack
Brute-Force
Web App Attack
๐ช๐ธ
robotstxt
2026-09-30 01:18:49
(3 days ago)
35.240.183.15 - - [30/Sep/2026:01:18:45 +0000] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env ...
show more
35.240.183.15 - - [30/Sep/2026:01:18:45 +0000] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.240.183.15"
35.240.183.15 - - [30/Sep/2026:01:18:45 +0000] "GET /static/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.240.183.15"
35.240.183.15 - - [30/Sep/2026:01:18:45 +0000] "GET /resources/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.240.183.15"
35.240.183.15 - - [30/Sep/2026:01:18:45 +0000] "GET /resources/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.240.183.15"
35.240.183.15 - - [30/Sep/2026:01:18:46 +0000] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.240.183.15"
...
show less
Web Spam
Web App Attack
Anonymous
2026-09-29 23:36:15
(3 days ago)
35.240.183.15 - - [29/Sep/2026:23:36:10 +0000] "GET /.env?import&raw HTTP/2.0" 404 13297 "-" "Mozill ...
show more
35.240.183.15 - - [29/Sep/2026:23:36:10 +0000] "GET /.env?import&raw HTTP/2.0" 404 13297 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
35.240.183.15 - - [29/Sep/2026:23:36:10 +0000] "GET /.env?import&url&inline HTTP/2.0" 404 13304 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
35.240.183.15 - - [29/Sep/2026:23:36:10 +0000] "GET /.env?raw HTTP/2.0" 404 13281 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
35.240.183.15 - - [29/Sep/2026:23:36:11 +0000] "GET /.env HTTP/2.0" 404 13273 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
35.240.183.15 - - [29/Sep/2026:23:36:13 +0000] "GET /.env HTTP/2.0" 404 13273 "https://jinda-massage.nl/.//.env" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
...
show less
Brute-Force
Web App Attack
๐ญ๐บ
kranem
2026-09-29 21:00:25
(3 days ago)
Triggered Cloudflare WAF from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POS ...
show more
Triggered Cloudflare WAF from SG.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/2 (POST method)
Endpoint: /index.php
Query: ?-d+allow_url_include%3don+-d+auto_prepend_file%3dphp://input
Timestamp: 2026-09-29T18:59:10Z
User-Agent: Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)
show less
Bad Web Bot
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-29 20:30:25
(3 days ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 20:20:02
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.183.15 (15.183.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.183.15 (15.183.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:19:55.347276 2026] [security2:error] [pid 3280:tid 3280] [client 35.240.183.15:58314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "empoweruohio.org"] [uri "/userfiles"] [unique_id "arwda8rSL1eCauHlq4aeJgAAADA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-29 20:14:52
(3 days ago)
35.240.183.15 - - [29/Sep/2026:20:14:40 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 21345 "-" "Mo ...
show more
35.240.183.15 - - [29/Sep/2026:20:14:40 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 21345 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "35.240.183.15" edge="172.68.164.119"
35.240.183.15 - - [29/Sep/2026:20:14:40 +0000] "GET /build/manifest.json HTTP/2.0" 403 21342 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "35.240.183.15" edge="172.68.164.119"
35.240.183.15 - - [29/Sep/2026:20:14:40 +0000] "GET /z9x8c7v6b5-debug-trigger-ccoo.app HTTP/2.0" 403 21346 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" "35.240.183.15" edge="172.68.164.119"
35.240.183.15 - - [29/Sep/2026:20:14:40 +0000] "GET /dist/manifest.json HTTP/2.0" 403 21342 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36" "35.240.183.15" edge="172.68.164.119"
...
show less
Web App Attack
๐ธ๐ช
eagle
2026-09-29 20:03:29
(3 days ago)
35.240.183.15 - - [29/Sep/2026:20:03:29 +0000] "POST / HTTP/2.0" 401 37 "-" "DuckAssistBot/1.1 (http ...
show more
35.240.183.15 - - [29/Sep/2026:20:03:29 +0000] "POST / HTTP/2.0" 401 37 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
...
show less
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-29 20:00:18
(3 days ago)
37.728 requests from untrusted country (2w3d28m)
Brute-Force
Bad Web Bot
๐ฉ๐ช
FD-IX
2026-09-29 19:58:14
(3 days ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐ต๐ฑ
Niko's Stuff
2026-09-29 19:57:53
(3 days ago)
Triggered crowdsecurity/http-probing. More information at: https://app.crowdsec.net/cti/35.240.183.1 ...
show more
Triggered crowdsecurity/http-probing. More information at: https://app.crowdsec.net/cti/35.240.183.15
show less
Web App Attack
Hacking
๐ฉ๐ช
dbmwebdesign
2026-09-29 19:30:17
(3 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack