Anonymous
2026-10-07 14:44:01
(14 minutes ago)
35.243.87.129 - - [07/Oct/2026:16:43:53 +0200] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1 ...
show more
35.243.87.129 - - [07/Oct/2026:16:43:53 +0200] "POST /cgi-bin/php-cgi.exe?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 404 19425 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
35.243.87.129 - - [07/Oct/2026:16:43:54 +0200] "POST /cgi-bin/php?%ADd+allow_url_include%3d1+%ADd+auto_prepend_file%3dphp://input HTTP/2.0" 404 19417 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
...
show less
Web App Attack
π«π·
Omar MartΓnez
2026-10-07 14:38:21
(20 minutes ago)
[Wed Oct 07 08:37:55.824907 2026] [core:error] [pid 4116331:tid 139864716899904] [remote 35.243.87.1 ...
show more
[Wed Oct 07 08:37:55.824907 2026] [core:error] [pid 4116331:tid 139864716899904] [remote 35.243.87.129:37596] AH10244: invalid URI path (/public/plugins/text/../../../../../../../../proc/self/environ)
[Wed Oct 07 08:38:19.813585 2026] [core:error] [pid 4116331:tid 139864784082496] [remote 35.243.87.129:37596] AH10244: invalid URI path (/cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh)
...
show less
Phishing
Email Spam
Blog Spam
π©πͺ
big-cloud.nl
2026-10-07 14:36:35
(22 minutes ago)
Try to access /cache/original/%2e%2e/%2e%2e/.env
Web App Attack
π³π±
mieg
2026-10-07 14:24:57
(33 minutes ago)
Web vulnerability probing
Brute-Force
Web App Attack
Anonymous
2026-10-07 14:14:18
(44 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 35.243.87.129 (JP/Japan/129.87.243.35.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.243.87.129 (JP/Japan/129.87.243.35.bc.googleusercontent.com)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-10-07 13:58:27
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.243.87.129 (129.87.243.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.243.87.129 (129.87.243.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 09:58:24.249836 2026] [security2:error] [pid 10163:tid 10163] [client 35.243.87.129:34710] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||daveweisman.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "daveweisman.com"] [uri "/z9x8c7v6b5-debug-trigger-daveweisman.com"] [unique_id "asZQAA3lP1kDYcqLDmprPgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-07 13:42:17
(1 hour ago)
Malicious activity detected
Hacking
Web App Attack
πͺπΈ
robotstxt
2026-10-07 13:41:54
(1 hour ago)
35.243.87.129 - - [07/Oct/2026:13:40:50 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 77599 "h ...
show more
35.243.87.129 - - [07/Oct/2026:13:40:50 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 77599 "https://cool-dreams.com/dist/.vite/manifest.json" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.243.87.129"
35.243.87.129 - - [07/Oct/2026:13:41:01 +0000] "GET /.env.example HTTP/2.0" 403 79017 "https://cool-dreams.com/.env.example" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "-" edge="35.243.87.129"
35.243.87.129 - - [07/Oct/2026:13:41:01 +0000] "GET /.env HTTP/2.0" 403 79018 "https://cool-dreams.com/.env" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" "-" edge="35.243.87.129"
35.243.87.129 - - [07/Oct/2026:13:41:02 +0000] "GET /.env.production HTTP/2.0" 403 78883 "https://cool-dreams.com/.env.production" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)" "-" edge="35.243.87.12
...
show less
Web App Attack
Anonymous
2026-10-07 13:40:01
(1 hour ago)
suspicious request in access.log
Web App Attack
π«π·
COMAITE
2026-10-07 13:29:46
(1 hour ago)
Common web attack from 35.243.87.129.
Web App Attack
Anonymous
2026-10-07 13:23:39
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
Anonymous
2026-10-07 13:22:16
(1 hour ago)
35.243.87.129 (JP/Japan/Tokyo/Tokyo/129.87.243.35.bc.googleusercontent.com/[redacted]), more than 10 ...
show more
35.243.87.129 (JP/Japan/Tokyo/Tokyo/129.87.243.35.bc.googleusercontent.com/[redacted]), more than 10 Apache 403 hits
show less
Hacking
π©πͺ
LRob
2026-10-07 13:07:39
(1 hour ago)
Wordlist path sweep | method: GET | path: /assets/manifest.json, /asset-manifest.json, /lib/terminal ...
show more
Wordlist path sweep | method: GET | path: /assets/manifest.json, /asset-manifest.json, /lib/terminal-xhr.php (+3 more) | ua: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36, Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)
show less
Port Scan
Web App Attack
Anonymous
2026-10-07 13:04:16
(1 hour ago)
Fail2Ban apache-noscript
Bad Web Bot
π³π±
WeCloudit-Anti-Abuse
2026-10-07 12:46:27
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/grafana-cve-2021-43798
Web App Attack
Hacking