๐ณ๐ฑ
Site.eu
2026-09-23 02:54:04
(2 hours ago)
Excessive multi-domain requests
Brute-Force
๐ธ๐ช
vaia.cloud
2026-09-23 02:35:05
(2 hours ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 02:12:51
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.241.168.125 (125.168.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.241.168.125 (125.168.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 22:12:45.858886 2026] [security2:error] [pid 26024:tid 26024] [client 35.241.168.125:56578] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.stormwlf.com|F|2"] [data ".stormwlf.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.stormwlf.com"] [uri "/z9x8c7v6b5-debug-trigger-www.stormwlf.com"] [unique_id "arM1nX9giIjx209llcFPLgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
CDO
2026-09-23 01:15:39
(3 hours ago)
URL Injection attempt detected. Automated web attack.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
kbeezie
2026-09-23 00:21:49
(4 hours ago)
2026/09/22 20:18:24 [error] 356958#356958: *117643 access forbidden by rule, client: 35.241.168.125, ...
show more
2026/09/22 20:18:24 [error] 356958#356958: *117643 access forbidden by rule, client: 35.241.168.125, server: stevenblessing.com, request: "GET /dist/.vite/manifest.json HTTP/1.1", host: "www.stevenblessing.com"
2026/09/22 20:20:13 [error] 356958#356958: *117780 access forbidden by rule, client: 35.241.168.125, server: stevenblessing.com, request: "GET /.vite/manifest.json HTTP/1.1", host: "www.stevenblessing.com"
2026/09/22 20:21:49 [error] 356958#356958: *117987 access forbidden by rule, client: 35.241.168.125, server: stevenblessing.com, request: "GET /dist/.vite/manifest.json HTTP/1.1", host: "www.stevenblessing.com"
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
Nightreaver
2026-09-23 00:18:11
(4 hours ago)
35.241.168.125 - - [23/Sep/2026:02:18:11 0200] "GET /login HTTP/1.1" 404 5768 "-" "Mozilla/5.0 (Win ...
show more
35.241.168.125 - - [23/Sep/2026:02:18:11 0200] "GET /login HTTP/1.1" 404 5768 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.241.168.125 - - [23/Sep/2026:02:18:11 0200] "GET /signin HTTP/1.1" 404 467 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.241.168.125 - - [23/Sep/2026:02:18:11 0200] "GET /z9x8c7v6b5-debug-trigger-www.[snip] HTTP/1.1" 404 467 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; http://www.baidu.com/search/spider.html)"
35.241.168.125 - - [23/Sep/2026:02:18:11 0200] "GET /users/login HTTP/1.1" 404 5768 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.241.168.125 - - [23/Sep/2026:02:18:11 0200] "GET /auth HTTP/1.1" 404 5768 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"[...]
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 00:01:09
(5 hours ago)
35.241.168.125 - - [23/Sep/2026:02:01:03 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows ...
show more
35.241.168.125 - - [23/Sep/2026:02:01:03 +0200] "GET / HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
35.241.168.125 - - [23/Sep/2026:02:01:04 +0200] "GET /sign-in HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
35.241.168.125 - - [23/Sep/2026:02:01:04 +0200] "GET /auth/login HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36 Edg/152.0.0.0"
35.241.168.125 - - [23/Sep/2026:02:01:04 +0200] "GET /z9x8c7v6b5-debug-trigger-www.stepsinlight.com HTTP/1.1" 403 153 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
35.241.168.125 - - [23/Sep/2026:02:01:04 +0200] "GET /auth HTTP/1.1" 403 12583 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHT
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ฎ
as211431.net
2026-09-22 22:46:58
(6 hours ago)
Triggered Cloudflare WAF (firewallManaged) from BE.
Action taken: BLOCK
Protocol: HTTP/2 (GET method ...
show more
Triggered Cloudflare WAF (firewallManaged) from BE.
Action taken: BLOCK
Protocol: HTTP/2 (GET method)
Endpoint: /wp-config.php.bak
UA: Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)
This report was generated by:
https://github.com/sefinek/Cloudflare-WAF-To-AbuseIPDB
show less
Bad Web Bot
๐จ๐ฆ
Mediashaker
2026-09-22 22:45:23
(6 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.241.168.125 (BE/B ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.241.168.125 (BE/Belgium/125.168.241.35.bc.googleusercontent.com)
show less
Bad Web Bot
Anonymous
2026-09-22 22:43:19
(6 hours ago)
Multiple, malicious web requests detected
Port Scan
Hacking
๐ณ๐ฑ
homeshowdomain.nl
2026-09-22 21:59:59
(7 hours ago)
Auto-ban: >3000 req/min op 2026-09-22
Web App Attack
SSH
Hacking
๐ช๐ธ
robotstxt
2026-09-22 21:37:24
(7 hours ago)
35.241.168.125 - - [22/Sep/2026:21:37:19 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 25557 "https ...
show more
35.241.168.125 - - [22/Sep/2026:21:37:19 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 25557 "https://www.domeofthefive.com/.vite/manifest.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.241.168.125"
35.241.168.125 - - [22/Sep/2026:21:37:21 +0000] "GET /@fs/app/.env?raw?? HTTP/2.0" 403 26787 "https://www.domeofthefive.com/@fs/app/.env?raw??" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "-" edge="35.241.168.125"
35.241.168.125 - - [22/Sep/2026:21:37:21 +0000] "GET /.env HTTP/2.0" 403 26829 "https://www.domeofthefive.com/_nuxt/../.env" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" "-" edge="35.241.168.125"
35.241.168.125 - - [22/Sep/2026:21:37:21 +0000] "GET /@fs/..%252f..%252f..%252f..%252f..%252froot/.env?raw?? HTTP/2.0" 403 26829 "https://www.domeofthefive.com/@fs/..%252f..%252f..%252f..%252f..%252f
...
show less
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-22 21:11:09
(7 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
magnetosphere-tarpit
2026-09-22 20:11:14
(8 hours ago)
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not ...
show more
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not exist on this host. Tarpitted, then banned: 10 requests within 24h0m0s
show less
Port Scan
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-22 19:54:27
(9 hours ago)
35.241.168.125 - - [22/Sep/2026:19:54:13 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 25457 "-" "M ...
show more
35.241.168.125 - - [22/Sep/2026:19:54:13 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 25457 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.241.168.125"
35.241.168.125 - - [22/Sep/2026:19:54:19 +0000] "GET /.env.save HTTP/2.0" 403 26829 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "-" edge="35.241.168.125"
35.241.168.125 - - [22/Sep/2026:19:54:19 +0000] "GET /.env.prod HTTP/2.0" 403 26787 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" "-" edge="35.241.168.125"
35.241.168.125 - - [22/Sep/2026:19:54:20 +0000] "GET /api/.env HTTP/2.0" 403 26829 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "-" edge="35.241.168.125"
35.241.168.125 - - [22/Sep/2026:19:54:20 +0000] "GET /admin/.env HTTP/2.0" 403 26829 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)" "-" ed
...
show less
Web App Attack