Anonymous
2026-07-24 20:21:13
(6 hours ago)
(PERMBLOCK) 35.85.63.140 (US/United States/ec2-35-85-63-140.us-west-2.compute.amazonaws.com) has had ...
show more
(PERMBLOCK) 35.85.63.140 (US/United States/ec2-35-85-63-140.us-west-2.compute.amazonaws.com) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
Anonymous
2026-07-24 19:05:06
(7 hours ago)
(caddyscan) Scanner path probe from 35.85.63.140 (US/United States/ec2-35-85-63-140.us-west-2.comput ...
show more
(caddyscan) Scanner path probe from 35.85.63.140 (US/United States/ec2-35-85-63-140.us-west-2.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 35.85.63.140 - - [24/Jul/2026:19:05:03 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 35.85.63.140 - - [24/Jul/2026:19:05:03 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 35.85.63.140 - - [24/Jul/2026:19:05:03 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 35.85.63.140 - - [24/Jul/2026:19:05:04 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 35.85.63.140 - - [24/Jul/2026:19:05:04 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
Anonymous
2026-07-24 17:22:56
(9 hours ago)
(caddyscan) Scanner path probe from 35.85.63.140 (US/United States/ec2-35-85-63-140.us-west-2.comput ...
show more
(caddyscan) Scanner path probe from 35.85.63.140 (US/United States/ec2-35-85-63-140.us-west-2.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 35.85.63.140 - - [24/Jul/2026:17:22:51 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 35.85.63.140 - - [24/Jul/2026:17:22:51 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 35.85.63.140 - - [24/Jul/2026:17:22:51 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 35.85.63.140 - - [24/Jul/2026:17:22:51 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 35.85.63.140 - - [24/Jul/2026:17:22:51 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
Anonymous
2026-07-24 15:48:08
(11 hours ago)
(caddyscan) Scanner path probe from 35.85.63.140 (US/United States/ec2-35-85-63-140.us-west-2.comput ...
show more
(caddyscan) Scanner path probe from 35.85.63.140 (US/United States/ec2-35-85-63-140.us-west-2.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 35.85.63.140 - - [24/Jul/2026:15:48:07 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 35.85.63.140 - - [24/Jul/2026:15:48:07 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 35.85.63.140 - - [24/Jul/2026:15:48:07 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 35.85.63.140 - - [24/Jul/2026:15:48:07 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 35.85.63.140 - - [24/Jul/2026:15:48:07 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
Anonymous
2026-07-24 14:45:13
(12 hours ago)
(caddyscan) Scanner path probe from 35.85.63.140 (US/United States/ec2-35-85-63-140.us-west-2.comput ...
show more
(caddyscan) Scanner path probe from 35.85.63.140 (US/United States/ec2-35-85-63-140.us-west-2.compute.amazonaws.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 35.85.63.140 - - [24/Jul/2026:14:45:08 +0000] "GET /.git/config HTTP/1.1"
[REDACTED] 200 2627 35.85.63.140 - - [24/Jul/2026:14:45:08 +0000] "GET /.env HTTP/1.1"
[REDACTED] 200 2627 35.85.63.140 - - [24/Jul/2026:14:45:08 +0000] "GET /.env.local HTTP/1.1"
[REDACTED] 200 2627 35.85.63.140 - - [24/Jul/2026:14:45:08 +0000] "GET /.env.production HTTP/1.1"
[REDACTED] 200 2627 35.85.63.140 - - [24/Jul/2026:14:45:08 +0000] "GET /.env.staging HTTP/1.1"
show less
Port Scan
Anonymous
2026-07-24 14:00:06
(12 hours ago)
| Suspicious URL access.
Web App Attack
Hacking
SQL Injection
π§πͺ
taivas.nl
2026-07-24 08:32:15
(18 hours ago)
Bad_requests
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-07-24 08:21:29
(18 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.85.63.140 (ec2-35-85-63-140.us-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 35.85.63.140 (ec2-35-85-63-140.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 04:21:21.632689 2026] [security2:error] [pid 7171:tid 7171] [client 35.85.63.140:60096] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gardner.farm.brazilianbottom.com"] [uri "/.git/config"] [unique_id "amMggWxvgwcpAveK3tRLIgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 04:55:48
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.85.63.140 (ec2-35-85-63-140.us-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 35.85.63.140 (ec2-35-85-63-140.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 24 00:55:44.844221 2026] [security2:error] [pid 154005:tid 154013] [client 35.85.63.140:41622] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gardenclub.ramona.town"] [uri "/.git/config"] [unique_id "amLwUCEOqeckuhrUtfGE7wAAAQI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-24 03:01:11
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.85.63.140 (ec2-35-85-63-140.us-west-2.comput ...
show more
(mod_security) mod_security (id:210492) triggered by 35.85.63.140 (ec2-35-85-63-140.us-west-2.compute.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 23 23:01:07.100445 2026] [security2:error] [pid 25032:tid 25032] [client 35.85.63.140:37398] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "garanzuayrec.com"] [uri "/.git/config"] [unique_id "amLVc7IqDY-tYxSeKHns7QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack