๐ซ๐ท
Batz
2026-10-05 14:58:22
(4 hours ago)
Automated Web Bot hunting for hidden .env / AI API Credentials
Port Scan
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-10-05 12:59:34
(6 hours ago)
csagent: score 24.0: 404 noise floor x20, php 404 x2, secrets grab x1; 2 domain(s) in 32s
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-05 12:56:45
(6 hours ago)
[ti-01al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-01al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.254.132.222 - - [05/Oct/2026:14:56:31 +0200] "GET /.htpasswd HTTP/1.1" 403 2113 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-05 10:47:48
(8 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-10-05 10:25:20
(8 hours ago)
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-05 10:03:56
(9 hours ago)
20 attempts against mh-misbehave-ban on burne
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-10-05 09:46:40
(9 hours ago)
165 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐ฌ๐ง
consul.to
2026-10-05 08:33:31
(10 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ซ๐ท
IRISIO
2026-10-05 08:32:55
(10 hours ago)
scans/SQL injection/spam posts : 1019 queries
Web App Attack
SQL Injection
Anonymous
2026-10-05 07:56:34
(11 hours ago)
35.254.132.222 - - [05/Oct/2026:15:56:34 +0800] "GET /dist/manifest.json HTTP/1.1" 404 196 "-" "Mozi ...
show more
35.254.132.222 - - [05/Oct/2026:15:56:34 +0800] "GET /dist/manifest.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.254.132.222 - - [05/Oct/2026:15:56:34 +0800] "GET /webpack-stats.json HTTP/1.1" 404 196 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.254.132.222 - - [05/Oct/2026:15:56:34 +0800] "GET /jayeziuy6vovy2br14qf HTTP/1.1" 404 196 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
35.254.132.222 - - [05/Oct/2026:15:56:34 +0800] "GET /44hsp6mfy5ahijvv2qid HTTP/1.1" 404 196 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)"
35.254.132.222 - - [05/Oct/2026:15:56:34 +0800] "GET /z9x8c7v6b5-debug-trigger-nowbaogumovies.com HTTP/1.1" 404 196 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
35.254.132.222 - - [05/Oct/2026:15:56:34 +0800] "GET /manifest.json HTTP/1.1" 4
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 07:28:42
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.254.132.222 (222.132.254.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.254.132.222 (222.132.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 03:28:37.348357 2026] [security2:error] [pid 2359:tid 2359] [client 35.254.132.222:53836] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||natesupport.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "natesupport.com"] [uri "/z9x8c7v6b5-debug-trigger-natesupport.com"] [unique_id "asNRpQOcSui91fj9nVc8JgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
MatCat
2026-10-05 07:05:06
(12 hours ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
๐บ๐ธ
helios.live
2026-10-05 04:32:02
(14 hours ago)
2026/10/05 04:32:01 [error] 3705168#3705168: *5708254 access forbidden by rule, client: 35.254.132.2 ...
show more
2026/10/05 04:32:01 [error] 3705168#3705168: *5708254 access forbidden by rule, client: 35.254.132.222, server: kocerroxy.com, request: "GET /dist/.vite/manifest.json HTTP/1.1", host: "kocerroxy.com"
2026/10/05 04:32:01 [error] 3705168#3705168: *5708273 access forbidden by rule, client: 35.254.132.222, server: kocerroxy.com, request: "GET /.vite/manifest.json HTTP/1.1", host: "kocerroxy.com"
2026/10/05 04:32:01 [error] 3705168#3705168: *5708273 FastCGI sent in stderr: "Primary script unknown" while reading response header from upstream, client: 35.254.132.222, server: kocerroxy.com, request: "POST /lib/terminal-xhr.php HTTP/1.1", upstream: "fastcgi://unix:/var/run/php/php8.4-fpm-betakocerroxycom.sock:", host: "kocerroxy.com"
35.254.132.222 - - [05/Oct/2026:04:32:01 +0000] "POST /lib/terminal-xhr.php HTTP/1.1" 404 47 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
2026/10/05 04:32:02 [error] 3705168#3705168: *5708707 access forbidden by rule, client: 35.254.132.222, server:
...
show less
Web App Attack
๐บ๐ธ
pachec
2026-10-05 04:29:37
(14 hours ago)
Automated vulnerability scanning blocked by fail2ban
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-05 04:07:58
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.254.132.222 (222.132.254.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.254.132.222 (222.132.254.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 00:07:51.271877 2026] [security2:error] [pid 18311:tid 18311] [client 35.254.132.222:51220] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kairoslogammakmur.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kairoslogammakmur.com"] [uri "/z9x8c7v6b5-debug-trigger-kairoslogammakmur.com"] [unique_id "asMil_LhBUZKNAP8KXSq5wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack