๐ง๐พ
lns.bz
2026-10-11 04:02:49
(9 minutes ago)
Too many 404 requests [BY]
Web App Attack
๐ง๐ท
Peregrine
2026-10-11 03:12:45
(59 minutes ago)
Fail2Ban ct101 Jail: tomcat-404 | Evidence: 35.252.188.47 104.22.72.41 - - [11/Oct/2026:00:11:30 -03 ...
show more
Fail2Ban ct101 Jail: tomcat-404 | Evidence: 35.252.188.47 104.22.72.41 - - [11/Oct/2026:00:11:30 -0300] "GET /dist/manifest.json HTTP/1.1" 404 18149
35.252.188.47 104.22.72.41 - - [11/Oct/2026:00:11:30 -0300] "GET /dist/.vite/manifest.json HTTP/1.1" 404 18149
35.252.188.47 104.22.72.41 - - [11/Oct/2026:00:11:30 -0300] "GET /bs570w0tvjmt58s51512 HTTP/1.1" 404 18149
35.252.188.47 104.22.72.41 - - [11/Oct/2026:00:11:30 -0300] "GET /.vite/manifest.json HTTP/1.1" 404 18149
35.252.188.47 104.22.72.41 - - [11/Oct/2026:00:11:30 -0300] "GET /service_account.json HTTP/1.1" 404 18149
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-11 02:53:10
(1 hour ago)
[cb-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.252.188.47 - - [11/Oct/2026:04:53:06 +0200] "GET /api/.env/public/.env HTTP/2.0" 404 1338 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-11 02:50:09
(1 hour ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-11 02:29:51
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.252.188.47 (47.188.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.188.47 (47.188.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 22:29:47.202786 2026] [security2:error] [pid 4368:tid 4368] [client 35.252.188.47:39300] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cthog.xyz"] [uri "/@fs/app/.env"] [unique_id "asr0m0lMlX2RrVlwbztF4wAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
4server
2026-10-11 02:17:16
(1 hour ago)
[SunOct1104:17:12.1761842026][security2:error][pid704144:tid704234][client35.252.188.47:0]ModSecurit ...
show more
[SunOct1104:17:12.1761842026][security2:error][pid704144:tid704234][client35.252.188.47:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Patternmatch\"\(\?:queryintrospectionquery\?\|__schema\\\\\\\\\?{\?\(\?:querytype\|types\?\)\)\?\\\\\\\\{\"atREQUEST_BODY.[file\"/etc/apache2/conf.d/modsec_rules/10_asl_rules.conf\"][line\"234\"][id\"344378\"][rev\"2\"][msg\"Atomicorp.comWAFRules:GraphQLInjectionAttackattempt\"][data\"MatchedData:__schema{types{foundwithinREQUEST_BODY:{\\\\x22query\\\\x22:\\\\x22{__schema{types{namefields{nameargs{namedefaultvalue}}}}}\\\\x22}\"][severity\"CRITICAL\"][tag\"SQLi\"][hostname\"creazione-siti-ticino.ch\"][uri\"/graphql\"][unique_id\"asrxqEnygPEdPz1ZIgsOewAAANY\"]\,referer:https://creazione-siti-ticino.ch
show less
Hacking
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-10-11 02:05:51
(2 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.252.188.47 (US/United States/47.188.252.35.b ...
show more
(mod_security) mod_security (id:949110) triggered by 35.252.188.47 (US/United States/47.188.252.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ซ๐ท
Zundapper
2026-10-11 01:19:25
(2 hours ago)
35.252.188.47 - - [11/Oct/2026:03:19:24 +0200] "GET /zt2lr315na76wzl9y5wn HTTP/2.0" 404 106 "-" "Moz ...
show more
35.252.188.47 - - [11/Oct/2026:03:19:24 +0200] "GET /zt2lr315na76wzl9y5wn HTTP/2.0" 404 106 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
35.252.188.47 - - [11/Oct/2026:03:19:24 +0200] "GET /asset-manifest.json HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
35.252.188.47 - - [11/Oct/2026:03:19:24 +0200] "GET /dist/manifest.json HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
35.252.188.47 - - [11/Oct/2026:03:19:24 +0200] "GET /3b9b16g5289h8snqfob6 HTTP/2.0" 404 106 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot"
35.252.188.47 - - [11/Oct/2026:03:19:24 +0200] "GET /assets/manifest.json HTTP/2.0" 404 167 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
...
show less
Web App Attack
Port Scan
Anonymous
2026-10-11 01:17:56
(2 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ฌ๐ง
Steve
2026-10-10 23:40:24
(4 hours ago)
SQL Injection Attempts
Brute-Force
SQL Injection
๐ณ๐ฑ
e.fierstra
2026-10-10 23:23:32
(4 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 23:19:30
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.252.188.47 (47.188.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.188.47 (47.188.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 19:19:26.919972 2026] [security2:error] [pid 1298:tid 1298] [client 35.252.188.47:37696] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||butterflygolem.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "butterflygolem.com"] [uri "/z9x8c7v6b5-debug-trigger-butterflygolem.com"] [unique_id "asrH_pphq7LUjugwgExACwAAAGc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-10 23:14:27
(4 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-10-10 23:05:14
(5 hours ago)
Too many Status 40X (11)
Scanning/Probing (26)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 23:01:09
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.252.188.47 (47.188.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.188.47 (47.188.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 19:01:06.183919 2026] [security2:error] [pid 11276:tid 11276] [client 35.252.188.47:52354] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||britanniapilates.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "britanniapilates.com"] [uri "/z9x8c7v6b5-debug-trigger-britanniapilates.com"] [unique_id "asrDsmBLCd0RE7YWjRBTKAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack