๐ฎ๐ณ
evicky2002
2026-08-09 06:00:00
(2 weeks ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
homeshowdomain.nl
2026-08-08 22:00:09
(2 weeks ago)
Auto-ban: >3000 req/min op 2026-08-08
Web App Attack
SSH
Hacking
๐ฉ๐ช
klaus_ph
2026-08-08 11:37:46
(2 weeks ago)
...
Bad Web Bot
๐ซ๐ท
IRISIO
2026-08-08 11:02:50
(2 weeks ago)
scans/SQL injection/spam posts : 122 queries
Web App Attack
SQL Injection
๐ณ๐ฑ
debestelapp
2026-08-08 06:45:06
(2 weeks ago)
Web App Attack
๐บ๐ธ
interbiznw.com
2026-08-08 06:36:49
(2 weeks ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 05:55:18
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 35.187.213.76 (76.213.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.187.213.76 (76.213.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 01:55:10.335879 2026] [security2:error] [pid 1883519:tid 1883519] [client 35.187.213.76:54078] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||greatchristianadventure.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "greatchristianadventure.com"] [uri "/rclone.conf"] [unique_id "anbEvsGp21HI2yFuFXdWLwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-08-08 05:21:51
(2 weeks ago)
35.187.213.76 - - [08/Aug/2026:10:51:51 +0530] "GET /.aws/config HTTP/2.0" 404 8280 "-" "Mozilla/5.0 ...
show more
35.187.213.76 - - [08/Aug/2026:10:51:51 +0530] "GET /.aws/config HTTP/2.0" 404 8280 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 04:37:24
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.187.213.76 (76.213.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.213.76 (76.213.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 00:37:19.463405 2026] [security2:error] [pid 3474644:tid 3474644] [client 35.187.213.76:50904] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "gordonmerrill.com"] [uri "/laravel/.env"] [unique_id "anayfwn0IjhvPBvOytuvqQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-08-08 04:13:23
(2 weeks ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.187.213 ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.187.213.76 (JP/Japan/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 35.187.213.76 (JP/Japan/76.213.187.35.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-08-08 04:12:02
(2 weeks ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ฉ๐ช
maxpower
2026-08-08 03:28:39
(2 weeks ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.187.213.76 (JP/Japan/76.213.187.35.bc ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.187.213.76 (JP/Japan/76.213.187.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.187.213.76 - - [08/Aug/2026:05:28:34 +0200] "GET /.aws/credentials HTTP/2.0" 429 41 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexity-user" "-" host=grafica-x.com
show less
Port Scan
๐จ๐ญ
lufi
2026-08-08 03:21:46
(2 weeks ago)
2026-08-08T05:21:46+02:00 lufischer04 ids442 2026-08-08 05:21:46 35.187.213.76: blacklisted Pattern: ...
show more
2026-08-08T05:21:46+02:00 lufischer04 ids442 2026-08-08 05:21:46 35.187.213.76: blacklisted Pattern: /wp-json
...
show less
Web Spam
Brute-Force
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 03:21:38
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 35.187.213.76 (76.213.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.187.213.76 (76.213.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 07 23:21:32.495898 2026] [security2:error] [pid 3042351:tid 3042351] [client 35.187.213.76:40768] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||grasslakepizzatime.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "grasslakepizzatime.com"] [uri "/z9x8c7v6b5-debug-trigger-grasslakepizzatime.com"] [unique_id "anagvCtLWNUBh6ycnlB8WAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
mnazibo
2026-08-08 03:00:05
(2 weeks ago)
Date: 08/Aug/2026 05:45:01 | Reported IP: 35.187.213.76 mod_security | id: 930130 930140 | JP/group. ...
show more
Date: 08/Aug/2026 05:45:01 | Reported IP: 35.187.213.76 mod_security | id: 930130 930140 | JP/group.my_domain/- | Connections: 69 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /admin/.env; /api/.env; /app-config.json; /auth.json; /.aws/config; /.aws/credentials; /backend/.env; /.bash_profile; /.bashrc; /.boto; /.claude/settings.json; /.codex/config.toml; /.config/anthropic/credentials/default.json; /config/.env.php; /config.json; /config.php.bak; /.continue/config.json; /core/.env; /credentials.json; /.cursor/mcp.json; /docker-compose.yaml; /.docker/config.json; /Dockerfile; /.env.backup; /.env.bak; /.env.dev; /.env.example; /.env.local; /.env.old; /.env.php.bak; /.env.production; /.env.swp; /firebase-config.json; /.git/config; /.gitconfig; /.git-credentials; /.git/HEAD; /.github/.env; /.gitlab-ci.yml; /.hermes/auth.json; /.hermes/config.yaml; /.hermes/.env; /.htpasswd; /laravel/.env; /.npmrc; /.openclaw/.env; /.openclaw/openclaw.json
show less
SQL Injection
Brute-Force
Bad Web Bot