π«π·
masterguru
2026-10-01 17:23:57
(22 hours ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-201)
show less
Bad Web Bot
πΊπΈ
jormaster3k
2026-10-01 15:55:23
(1 day ago)
Attack against Apache (too many 404s)
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 15:41:07
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 207.175.246.68 (68.246.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 207.175.246.68 (68.246.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:41:00.987241 2026] [security2:error] [pid 20009:tid 20009] [client 207.175.246.68:60094] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||zodiacwin.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "zodiacwin.com"] [uri "/z9x8c7v6b5-debug-trigger-zodiacwin.com"] [unique_id "ar5_DCQFsXOU4KxSpuruvQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 15:06:52
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 207.175.246.68 (68.246.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 207.175.246.68 (68.246.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:06:48.180548 2026] [security2:error] [pid 10185:tid 10185] [client 207.175.246.68:47392] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||awl-v.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "awl-v.com"] [uri "/z9x8c7v6b5-debug-trigger-awl-v.com"] [unique_id "ar53CPkxleHix8_uABDZawAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§π·
Halux
2026-10-01 15:02:53
(1 day ago)
207.175.246.68 Probing protected path or service
Web App Attack
π©πͺ
Hazzard
2026-10-01 14:56:55
(1 day ago)
(PERMBLOCK) 207.175.246.68 (BE/Belgium/Brussels Capital/Brussels/68.246.175.207.bc.googleusercontent ...
show more
(PERMBLOCK) 207.175.246.68 (BE/Belgium/Brussels Capital/Brussels/68.246.175.207.bc.googleusercontent.com/[redacted]) has had more than 4 temp blocks
show less
Hacking
πΊπΈ
TPI-Abuse
2026-10-01 14:17:53
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 207.175.246.68 (68.246.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 207.175.246.68 (68.246.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:17:50.435067 2026] [security2:error] [pid 3222:tid 3222] [client 207.175.246.68:50372] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||z-industrial.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "z-industrial.com"] [uri "/z9x8c7v6b5-debug-trigger-z-industrial.com"] [unique_id "ar5rjl5ZUuEV4dkOuyi6igAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
IloGus
2026-10-01 14:17:15
(1 day ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
π³π±
e.fierstra
2026-10-01 14:01:55
(1 day ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-01 13:41:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 207.175.246.68 (68.246.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.246.68 (68.246.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:41:20.736599 2026] [security2:error] [pid 1702:tid 1702] [client 207.175.246.68:34756] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.automationworkflow.com"] [uri "/uploads../.env"] [unique_id "ar5jACidT_dUvr8xz1bZfgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-10-01 12:46:17
(1 day ago)
20 attempts against mh-misbehave-ban on onion
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-10-01 12:27:26
(1 day ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-10-01 12:21:17
(1 day ago)
Portscan: TCP/8443 (8x), TCP/8080 (8x)
Port Scan
πΊπΈ
TPI-Abuse
2026-10-01 12:07:03
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 207.175.246.68 (68.246.175.207.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 207.175.246.68 (68.246.175.207.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:06:56.784024 2026] [security2:error] [pid 10545:tid 10545] [client 207.175.246.68:56026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ypsisda.net"] [uri "/static../.env"] [unique_id "ar5M4IYALp64tvrCjk2h4QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
Octopuce
2026-10-01 11:55:53
(1 day ago)
Aggressive web search of vulnerable pages: /swagger.json /openapi.json /api/v1/config/ /api/openapi. ...
show more
Aggressive web search of vulnerable pages: /swagger.json /openapi.json /api/v1/config/ /api/openapi.json /__debug__/ /api/console/api_server?se ...
show less
Web App Attack