๐บ๐ธ
mnsf
2026-09-22 13:06:37
(54 minutes ago)
Abuse Detected (2)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:05:08
(55 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.185.144.4 (4.144.185.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.185.144.4 (4.144.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:04:55.023894 2026] [security2:error] [pid 25524:tid 25524] [client 35.185.144.4:59760] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||haworthconsultinggroup.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "haworthconsultinggroup.com"] [uri "/z9x8c7v6b5-debug-trigger-haworthconsultinggroup.com"] [unique_id "arJ890_wgZ3gU8wlLzakuQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
nhawsjones
2026-09-22 13:04:44
(56 minutes ago)
[Tue Sep 22 22:04:43.301727 2026] [authz_core:error] [pid 40878:tid 40878] [client 35.185.144.4:5946 ...
show more
[Tue Sep 22 22:04:43.301727 2026] [authz_core:error] [pid 40878:tid 40878] [client 35.185.144.4:59464] AH01630: client denied by server configuration: /var/www/external/.htpasswd
...
show less
Brute-Force
๐จ๐ฆ
polycoda
2026-09-22 12:03:10
(1 hour ago)
๐ฅ VERY AGGRESSIVE SCANNER probed over 700 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:14:24
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.185.144.4 (4.144.185.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.185.144.4 (4.144.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:14:22.117638 2026] [security2:error] [pid 7738:tid 7738] [client 35.185.144.4:45252] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||healingtrek.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "healingtrek.com"] [uri "/z9x8c7v6b5-debug-trigger-healingtrek.com"] [unique_id "arJjDly7Oidd-nih8osx_AAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Baking333
2026-09-22 09:56:52
(4 hours ago)
[redacted] 35.185.144.4 - - [22/Sep/2026:10:56:51 +0100] "GET /.zshrc HTTP/1.1" 302 6741 0/38983 "-" ...
show more
[redacted] 35.185.144.4 - - [22/Sep/2026:10:56:51 +0100] "GET /.zshrc HTTP/1.1" 302 6741 0/38983 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://[redacted]/[redacted])" [redacted] 35.185.144.4 - - [22/Sep/2026:10:56:51 +0100] "GET /.bash_profile HTTP/1.1" 302 1499 0/47589 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://[redacted]/)"
show less
Bad Web Bot
Web App Attack
๐ฏ๐ต
bokumin.org
2026-09-22 09:56:31
(4 hours ago)
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/"] [id "949110"] [msg " ...
show more
[id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [uri "/"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"]
show less
Web App Attack
Anonymous
2026-09-22 09:55:52
(4 hours ago)
$f2bV_matches
Brute-Force
Web App Attack
๐ฉ๐ช
Leon A
2026-09-22 08:57:00
(5 hours ago)
Brute-Force
Bad Web Bot
Web App Attack
Web Spam
Port Scan
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-22 08:39:22
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.185.144.4 (4.144.185.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.185.144.4 (4.144.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:39:16.894737 2026] [security2:error] [pid 32130:tid 32130] [client 35.185.144.4:46578] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||heavenwny.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "heavenwny.com"] [uri "/z9x8c7v6b5-debug-trigger-heavenwny.com"] [unique_id "arI-tDyV2o8TVO_mBG_TeAAAAFE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 08:37:06
(5 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ณ๐ด
Bots.go.to.hell
2026-09-22 08:22:31
(5 hours ago)
This IP was detected by CrowdSec triggering custom/http-bad-crawler-ban
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 08:10:44
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.185.144.4 (4.144.185.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.185.144.4 (4.144.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:10:40.349377 2026] [security2:error] [pid 26953:tid 26953] [client 35.185.144.4:46874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mcbrude.com"] [uri "/public/.env"] [unique_id "arI4ANVUDPI-CcrZn-EoUAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
MSC IT for Business GmbH
2026-09-22 08:10:10
(5 hours ago)
GASTO/CrowdSec: gasto/404-flood triggered (via crowdsec-agent, categories 15,21)
Hacking
Web App Attack
๐บ๐ธ
antlac1
2026-09-22 08:09:31
(5 hours ago)
crowdsecurity/http-bad-user-agent
Brute-Force
Web App Attack