๐จ๐ฆ
Mediashaker
2026-10-01 16:35:22
(1 hour ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.247.129.124 (SG/S ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.247.129.124 (SG/Singapore/124.129.247.35.bc.googleusercontent.com)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 16:03:45
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.247.129.124 (124.129.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.247.129.124 (124.129.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:03:42.338156 2026] [security2:error] [pid 3355:tid 3355] [client 35.247.129.124:51846] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.xirination.com|F|2"] [data ".xirination.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.xirination.com"] [uri "/z9x8c7v6b5-debug-trigger-www.xirination.com"] [unique_id "ar6EXmJLU66KHEnG_5tEsAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Christopher Hughes
2026-10-01 15:54:29
(2 hours ago)
35.247.129.124 - - [01/Oct/2026:16:54:29 +0100] "GET /.env.test HTTP/2.0" 401 410 "-" "Mozilla/5.0 ( ...
show more
35.247.129.124 - - [01/Oct/2026:16:54:29 +0100] "GET /.env.test HTTP/2.0" 401 410 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 15:29:13
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.247.129.124 (124.129.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.247.129.124 (124.129.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:29:08.226588 2026] [security2:error] [pid 8636:tid 8636] [client 35.247.129.124:56254] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ww-bbs.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ww-bbs.com"] [uri "/z9x8c7v6b5-debug-trigger-ww-bbs.com"] [unique_id "ar58RCpf9eTBPtIxf0NyIwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 15:23:03
(2 hours ago)
[Thu Oct 01 17:23:02.036094 2026] [authz_core:error] [pid 26698] [client 35.247.129.124:45674] AH016 ...
show more
[Thu Oct 01 17:23:02.036094 2026] [authz_core:error] [pid 26698] [client 35.247.129.124:45674] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Oct 01 17:23:02.244832 2026] [authz_core:error] [pid 26698] [client 35.247.129.124:45674] AH01630: client denied by server configuration: /etc/httpd/htdocs
[Thu Oct 01 17:23:02.468397 2026] [authz_core:error] [pid 26698] [client 35.247.129.124:45674] AH01630: client denied by server configuration: /etc/httpd/htdocs
...
show less
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-10-01 15:05:07
(3 hours ago)
Try to access /.//.env
Web App Attack
๐ฌ๐ง
NotCool
2026-10-01 14:12:20
(4 hours ago)
(CRAWLDELAY) Generic Bot Crawl-delay Violation 35.247.129.124 (SG/Singapore/124.129.247.35.bc.google ...
show more
(CRAWLDELAY) Generic Bot Crawl-delay Violation 35.247.129.124 (SG/Singapore/124.129.247.35.bc.googleusercontent.com): 50 in the last 3600 secs
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 13:49:19
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.129.124 (124.129.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.129.124 (124.129.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:49:15.774571 2026] [security2:error] [pid 11179:tid 11179] [client 35.247.129.124:52152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wisk.org"] [uri "/dist../.env"] [unique_id "ar5k27tDiwJsiwJBrIJCsQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 12:23:46
(5 hours ago)
Portscan: TCP/8080 (6x), TCP/8443 (6x), TCP/443, TCP/80
Port Scan
๐บ๐ธ
mnsf
2026-10-01 12:05:19
(6 hours ago)
Too many Status 40X (15)
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-01 11:39:38
(6 hours ago)
[ti-26al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-26al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.247.129.124 - - [01/Oct/2026:13:39:22 +0200] "GET /static../.env HTTP/1.1" 404 2065 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
wHosts
2026-10-01 11:23:26
(6 hours ago)
Blocked by Fail2Ban
Web App Attack
๐ณ๐ฑ
Alboweb B.V.
2026-10-01 11:11:06
(7 hours ago)
Bad web bot activity detected by Fail2Ban in plesk-apache-badbot jail
Bad Web Bot
๐ซ๐ท
guillaume illien
2026-10-01 10:19:26
(7 hours ago)
35.247.129.124 - - [01/Oct/2026:10:19:15 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.% ...
show more
35.247.129.124 - - [01/Oct/2026:10:19:15 +0000] "POST /cgi-bin/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/bin/sh HTTP/1.1" 400 166 "-" "-"
35.247.129.124 - - [01/Oct/2026:10:19:25 +0000] "GET /..%2f.env HTTP/1.1" 400 166 "-" "-"
35.247.129.124 - - [01/Oct/2026:10:19:26 +0000] "GET /%2e%2e/.env HTTP/1.1" 400 166 "-" "-"
35.247.129.124 - - [01/Oct/2026:10:19:26 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 166 "-" "-"
35.247.129.124 - - [01/Oct/2026:10:19:26 +0000] "GET /icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ HTTP/1.1" 400 166 "-" "-"
35.247.129.124 - - [01/Oct/2026:10:19:26 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 166 "-" "-"
35.247.129.124 - - [01/Oct/2026:10:19:26 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 166 "-" "-"
...
show less
Hacking
Brute-Force
Web App Attack
SSH
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-10-01 10:09:27
(8 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking