๐ต๐ฑ
mscode.pl
2026-09-25 21:09:01
(18 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Prot ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 396982 (Google LLC)
Protocol: HTTP/1.1 (GET method)
Zone: status.selify.io
Endpoint: /includes/phpinfo.php
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36
show less
Bad Web Bot
๐ฉ๐ช
updown.io
2026-09-25 19:14:02
(20 hours ago)
{"level":"info","ts":1790363618.973686,"logger":"http.log.access.log1","msg":"handled request","requ ...
show more
{"level":"info","ts":1790363618.973686,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.245.218.233","remote_port":"41668","client_ip":"35.245.218.233","proto":"HTTP/1.1","method":"POST","host":"status-jost-ag.frank-schmittlein.net","uri":"/","headers":{"Next-Action":["x"],"Content-Length":["636"],"User-Agent":["Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36"],"Accept-Encoding":["gzip, deflate"],"Connection":["keep-alive"],"X-Nextjs-Request-Id":["502eee1e"],"Content-Type":["multipart/form-data; boundary=--------WebKitFormBoundary1e514dd1c6cb47b8"],"Accept":["*/*"]},"tls":{"resumed":false,"version":772,"cipher_suite":4865,"proto":"http/1.1","server_name":"status-jost-ag.frank-schmittlein.net","ech":false}},"bytes_read":0,"user_id":"","duration":0.000857187,"size":0,"status":429,"resp_headers":{"Retry-After":["1"],"Server":["Caddy"],"Alt-Svc":["h3=\":443\"; ma=2592000"]}}
{"level":"info","ts":1790363
...
show less
DDoS Attack
Web App Attack
๐ช๐ธ
robotstxt
2026-09-25 06:03:54
(1 day ago)
35.245.218.233 - - [25/Sep/2026:06:02:55 +0000] "GET /.env HTTP/1.1" 403 15957 "-" "Mozilla/5.0 (X11 ...
show more
35.245.218.233 - - [25/Sep/2026:06:02:55 +0000] "GET /.env HTTP/1.1" 403 15957 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.245.218.233"
35.245.218.233 - - [25/Sep/2026:06:02:55 +0000] "GET /.env.local HTTP/1.1" 403 15957 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.245.218.233"
35.245.218.233 - - [25/Sep/2026:06:02:56 +0000] "GET /.env.production HTTP/1.1" 403 15957 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.245.218.233"
35.245.218.233 - - [25/Sep/2026:06:02:56 +0000] "GET /.env.staging HTTP/1.1" 403 15957 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36" "-" edge="35.245.218.233"
35.245.218.233 - - [25/Sep/2026:06:02:57 +0000] "GET /.env.development HTTP/1.1" 403 15957 "-" "Mozilla/5.0 (X11; Linux x86
...
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-25 01:58:14
(1 day ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-24 19:15:30
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.245.218.233 (233.218.245.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.218.233 (233.218.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 15:15:24.044686 2026] [security2:error] [pid 24217:tid 24217] [client 35.245.218.233:43590] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.grandpont-house.org"] [uri "/.git/config"] [unique_id "arV2zK68rY6538bmG9rmFQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 18:32:59
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.245.218.233 (233.218.245.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.218.233 (233.218.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 14:32:53.458940 2026] [security2:error] [pid 21181:tid 21205] [client 35.245.218.233:35628] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webdisk.gqsi.org"] [uri "/.git/config"] [unique_id "arVs1Tp6QqXWIXPNhc__dwAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-24 05:00:06
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 10:53:46
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.245.218.233 (233.218.245.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.218.233 (233.218.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 06:53:38.516388 2026] [security2:error] [pid 26167:tid 26167] [client 35.245.218.233:45730] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shine-x.com"] [uri "/.git/config"] [unique_id "arOvsoE9hH6LxJ6LodLDDQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 08:34:18
(4 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 17:20:17
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.245.218.233 (233.218.245.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.218.233 (233.218.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 13:20:12.670783 2026] [security2:error] [pid 30746:tid 30746] [client 35.245.218.233:58690] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shelyaneandmartin.com.naturopathicsource.com"] [uri "/.git/config"] [unique_id "arFnTMKY7UN-90D7SBP_mAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 15:56:25
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.245.218.233 (233.218.245.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.218.233 (233.218.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:56:19.494744 2026] [security2:error] [pid 30158:tid 30158] [client 35.245.218.233:53080] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "shellyfamily.com"] [uri "/.git/config"] [unique_id "arFTozMwRMW-UncX8N3fNQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-21 06:16:11
(5 days ago)
[topuurbd] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35 ...
show more
[topuurbd] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35.245.218.233 - - \[21/Sep/2026:08:16:08 +0200\] "GET /.git/config HTTP/1.1" 307 348 "-" "Mozilla/5.0 \(Macintosh\; Intel Mac OS X 10_15_7\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/131.0.0.0 Safari/537.36"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 15:35:31
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.245.218.233 (233.218.245.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.245.218.233 (233.218.245.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:35:25.552796 2026] [security2:error] [pid 21338:tid 21338] [client 35.245.218.233:40808] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swindon-itf.com"] [uri "/.git/config"] [unique_id "aq_9PVV4TwV0vSQsAkkHCgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack