๐ฆ๐บ
OneLuca
2026-09-24 14:41:23
(25 minutes ago)
#1: malicious bot (user agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (K ...
show more
#1: malicious bot (user agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36; method: GET; path: /secure); #2: probing for known vulnerabilities (GET /account/login); #3: probing for known vulnerabilities (GET /admin); #4: malicious bot (user agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36; method: GET; path: /sign-in); #5: malicious bot (user agent: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] ); method: GET; path: /z9x8c7v6b5-debug-trigger-sentinel.1luca.com); #6: malicious bot (user agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36; method: GET; path: /reset-password); #7: malicious bot (user agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36; method: GET;
show less
Web App Attack
๐ณ๐ฑ
javierin
2026-09-24 12:51:39
(2 hours ago)
35.185.188.142 - sermama.javierin.com - - [24/Sep/2026:12:51:38 +0000] "GET / HTTP/2.0" 200 4552 "-" ...
show more
35.185.188.142 - sermama.javierin.com - - [24/Sep/2026:12:51:38 +0000] "GET / HTTP/2.0" 200 4552 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
35.185.188.142 - sermama.javierin.com - - [24/Sep/2026:12:51:39 +0000] "GET /manifest.json HTTP/2.0" 404 2297 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/151.0.0.0 Safari/537.36"
...
show less
Web App Attack
Hacking
๐ฉ๐ช
IloGus
2026-09-24 11:46:49
(3 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 11:39:07
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.185.188.142 (142.188.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.185.188.142 (142.188.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 07:39:00.916227 2026] [security2:error] [pid 29103:tid 29103] [client 35.185.188.142:36146] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||service.alccontractorsllc.com|F|2"] [data ".alccontractorsllc.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "service.alccontractorsllc.com"] [uri "/z9x8c7v6b5-debug-trigger-service.alccontractorsllc.com"] [unique_id "arUL1DFjtADdebkjJZHekgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-24 10:46:04
(4 hours ago)
35.185.188.142 - - [24/Sep/2026:10:45:05 +0000] "POST / HTTP/2.0" 403 22257 "-" "Mozilla/5.0 (compat ...
show more
35.185.188.142 - - [24/Sep/2026:10:45:05 +0000] "POST / HTTP/2.0" 403 22257 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" "-" edge="35.185.188.142"
35.185.188.142 - - [24/Sep/2026:10:45:05 +0000] "GET /build/manifest.json HTTP/2.0" 403 20052 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.185.188.142"
35.185.188.142 - - [24/Sep/2026:10:45:05 +0000] "GET /dist/manifest.json HTTP/2.0" 403 20052 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.185.188.142"
35.185.188.142 - - [24/Sep/2026:10:45:06 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 20052 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.185.188.142"
35.185.188.142 - - [24/Sep/2026:10:45:06 +0000] "GET /z9x8c7v6b5-debug-trigger-sevilla.monteroespinosaonline.com
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 09:33:35
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.185.188.142 (142.188.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.185.188.142 (142.188.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 05:33:29.792496 2026] [security2:error] [pid 15462:tid 15462] [client 35.185.188.142:53060] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||shadowfree.souldata.com|F|2"] [data ".souldata.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "shadowfree.souldata.com"] [uri "/z9x8c7v6b5-debug-trigger-shadowfree.souldata.com"] [unique_id "arTuacK07uVeocp5w8L5jwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
raph
2026-09-24 09:06:45
(6 hours ago)
[PROTECTED PATHS] crawler credentials.ini, aws.ini, aws.yml, etc.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-24 09:05:40
(6 hours ago)
15 attempts against mh-modsecurity-ban on pf221108
Brute-Force
Web App Attack
Anonymous
2026-09-24 08:14:34
(6 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.185.188.142 (SG/Singapore/142.188.18 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.185.188.142 (SG/Singapore/142.188.185.35.bc.googleusercontent.com)
show less
SQL Injection
๐ซ๐ท
francoisunix
2026-09-24 06:27:13
(8 hours ago)
35.185.188.142 - - [24/Sep/2026:06:27:08 +0000] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Linux; Andr ...
show more
35.185.188.142 - - [24/Sep/2026:06:27:08 +0000] "GET / HTTP/1.1" 444 0 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"
35.185.188.142 - - [24/Sep/2026:06:27:09 +0000] "GET /w4e54w78flvk8bvjxfxh HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
35.185.188.142 - - [24/Sep/2026:06:27:09 +0000] "GET /z9x8c7v6b5-debug-trigger-test.eco-conscient.com HTTP/1.1" 444 0 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
35.185.188.142 - - [24/Sep/2026:06:27:09 +0000] "GET /04c8jm8ptbfitj1d7688 HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
35.185.188.142 - - [24/Sep/2026:06:27:09 +0000] "POST /api/v1/validate/code HTTP/1.1" 444 0 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-24 06:00:03
(9 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-24 04:54:02
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.185.188.142 (142.188.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.185.188.142 (142.188.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:53:56.939716 2026] [security2:error] [pid 2660:tid 2660] [client 35.185.188.142:34408] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.talkingmess.com|F|2"] [data ".talkingmess.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.talkingmess.com"] [uri "/z9x8c7v6b5-debug-trigger-www.talkingmess.com"] [unique_id "arSs5PnaRl7-HfVgfJRhpAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
sfmet-admin
2026-09-24 04:23:13
(10 hours ago)
35.185.188.142 - - [24/Sep/2026:04:23:12 +0000] "GET /.git-credentials HTTP/2.0" 200 36 "-" "Mozilla ...
show more
35.185.188.142 - - [24/Sep/2026:04:23:12 +0000] "GET /.git-credentials HTTP/2.0" 200 36 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 04:08:57
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.185.188.142 (142.188.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.185.188.142 (142.188.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:08:52.941130 2026] [security2:error] [pid 16326:tid 16326] [client 35.185.188.142:40852] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.sfholidayrentals.com|F|2"] [data ".sfholidayrentals.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.sfholidayrentals.com"] [uri "/z9x8c7v6b5-debug-trigger-www.sfholidayrentals.com"] [unique_id "arSiVBgFC7csaFRmuXGBcwAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 02:54:33
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.185.188.142 (142.188.185.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.185.188.142 (142.188.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:54:30.158354 2026] [security2:error] [pid 6320:tid 6320] [client 35.185.188.142:36668] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.sentientresearch.com|F|2"] [data ".sentientresearch.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.sentientresearch.com"] [uri "/z9x8c7v6b5-debug-trigger-www.sentientresearch.com"] [unique_id "arSQ5vY75sjbiwBSZb07EwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack