Anonymous
2026-10-03 15:09:14
(2 days ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: BE, Attack patterns: Back ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: BE, Attack patterns: Backup file probing, Cloud secrets probing, Directory traversal
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-03 08:14:21
(2 days ago)
207.175.213.230 - - [03/Oct/2026:03:14:17 -0500] "GET /.env.development HTTP/1.1" 403 199 "-" "Mozil ...
show more
207.175.213.230 - - [03/Oct/2026:03:14:17 -0500] "GET /.env.development HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)" 207.175.213.230
207.175.213.230 - - [03/Oct/2026:03:14:17 -0500] "GET /.env.staging HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" 207.175.213.230
207.175.213.230 - - [03/Oct/2026:03:14:17 -0500] "GET /.env.test HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" 207.175.213.230
207.175.213.230 - - [03/Oct/2026:03:14:18 -0500] "GET /.env.docker HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" 207.175.213.230
207.175.213.230 - - [03/Oct/2026:03:14:18 -0500] "GET /.env.production.bak HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" 207.175.213.230
207.175.213.230 - - [03/Oct/2026:03:14:18 -0500] "GET /.env.prod.bak HTTP/1.1" 403 199 "-"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 07:36:20
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 207.175.213.230 (230.213.175.207.bc.googleuserc ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.213.230 (230.213.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 03:36:14.853864 2026] [security2:error] [pid 8580:tid 8580] [client 207.175.213.230:59970] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.new-bethel-baptist-church.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "asCwbtexijvzLA50q9m7TQAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-03 06:55:12
(2 days ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-193)
show less
Hacking
๐ซ๐ท
masterguru
2026-10-03 05:50:37
(2 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:User-Agent. (1100000- ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "claudebot" at REQUEST_HEADERS:User-Agent. (1100000-135)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-03 05:45:49
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 207.175.213.230 (230.213.175.207.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 207.175.213.230 (230.213.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 01:45:42.667518 2026] [security2:error] [pid 24981:tid 24991] [client 207.175.213.230:41212] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brucejoell.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brucejoell.com"] [uri "/z9x8c7v6b5-debug-trigger-brucejoell.com"] [unique_id "asCWhnst0z_wRLXHC7YEMQAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
simpeg-adm.bandung.go.id
2026-10-03 05:39:11
(2 days ago)
03/Oct/2026:05:39:11 +0000;207.175.213.230;"/ilrnfc2uhteqpclk8y0v"
03/Oct/2026:05:39:11 +0000;207.17 ...
show more
03/Oct/2026:05:39:11 +0000;207.175.213.230;"/ilrnfc2uhteqpclk8y0v"
03/Oct/2026:05:39:11 +0000;207.175.213.230;"/lib/terminal-xhr.php"
03/Oct/2026:05:39:11 +0000;207.175.213.230;"/model/info"
03/Oct/2026:05:39:11 +0000;207.175.213.230;"/dist/.vite/manifest.json"
03/Oct/2026:05:39:11 +0000;207.175.213.230;"/.vite/manifest.json"
03/Oct/2026:05:39:11 +0000;207.175.213.230;"/z9x8c7v6b5-debug-trigger-vendors.heatherephotography.com"
03/Oct/2026:05:39:11 +0000;207.175.213.230;"/dist/manifest.json"
...
show less
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 05:19:44
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 207.175.213.230 (230.213.175.207.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 207.175.213.230 (230.213.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 01:19:38.877884 2026] [security2:error] [pid 13968:tid 13968] [client 207.175.213.230:33406] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||neonmotel.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "neonmotel.com"] [uri "/z9x8c7v6b5-debug-trigger-neonmotel.com"] [unique_id "asCQai1LYCACleGQ9z0aTwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-03 04:33:06
(2 days ago)
20 attempts against mh-misbehave-ban on eris
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
sibahota
2026-10-03 02:17:48
(2 days ago)
207.175.213.230 - - [03/Oct/2026:02:17:48 +0000] demo.nidandiagnostic.com "GET /static../.env HTTP/2 ...
show more
207.175.213.230 - - [03/Oct/2026:02:17:48 +0000] demo.nidandiagnostic.com "GET /static../.env HTTP/2.0" 403 26 0.000 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" - - - "http://demo.nidandiagnostic.com"
...
show less
Web App Attack
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-03 01:27:55
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 207.175.213.230 (230.213.175.207.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 207.175.213.230 (230.213.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 21:27:49.425683 2026] [security2:error] [pid 1079:tid 1079] [client 207.175.213.230:34252] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.newlistings.iainrealtor.com|F|2"] [data ".newlistings.iainrealtor.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.newlistings.iainrealtor.com"] [uri "/z9x8c7v6b5-debug-trigger-www.newlistings.iainrealtor.com"] [unique_id "asBaFQkZ_Z24gJWduH6hDAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-03 00:43:25
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ง๐ช
cmbplf
2026-10-02 23:03:09
(2 days ago)
4.165 requests from abuseipdb.com blacklisted IP (1yr10mos3w)
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-10-02 22:17:51
(2 days ago)
[ti-26al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-26al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 207.175.213.230 - - [03/Oct/2026:00:17:40 +0200] "GET /.htpasswd HTTP/1.1" 301 687 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
207.175.213.230 - - [03/Oct/2026:00:17:40 +0200] "GET /.ssh/id_ed25519 HTTP/1.1" 301 699 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
antlac1
2026-10-02 21:36:11
(3 days ago)
crowdsecurity/http-bad-user-agent
Brute-Force
Web App Attack