๐ซ๐ท
GabrielJST
2026-09-24 15:33:51
(7 minutes ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.185.241.89 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.185.241.89 (US/United States/89.241.185.35.bc.googleusercontent.com)
show less
Bad Web Bot
๐ฉ๐ช
itsolon
2026-09-24 14:45:58
(55 minutes ago)
[24/Sep/2026:16:45:56 +0200] 179026115668.224838 35.185.241.89 0 217.154.7.177 443
[24/Sep/2026:16:4 ...
show more
[24/Sep/2026:16:45:56 +0200] 179026115668.224838 35.185.241.89 0 217.154.7.177 443
[24/Sep/2026:16:45:56 +0200] 179026115686.567584 35.185.241.89 0 217.154.7.177 443
[24/Sep/2026:16:45:58 +0200] 179026115867.643098 35.185.241.89 0 217.154.7.177 443
[24/Sep/2026:16:45:58 +0200] 179026115871.880267 35.185.241.89 0 217.154.7.177 443
[24/Sep/2026:16:45:58 +0200] 179026115866.317508 35.185.241.89 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
[email protected]
2026-09-24 11:31:52
(4 hours ago)
CrowdSec ban: crowdsecurity/unifi-flood-detection (duration: 71h59m52s)
Port Scan
Anonymous
2026-09-24 11:18:58
(4 hours ago)
XSS Attempt
Hacking
๐บ๐ธ
SX Communications
2026-09-24 10:39:38
(5 hours ago)
Web vulnerability scanning / probing from 35.185.241.89: automated requests for CMS admin paths, log ...
show more
Web vulnerability scanning / probing from 35.185.241.89: automated requests for CMS admin paths, login endpoints, xmlrpc, and common scanner fingerprints over HTTPS. 72 hits; paths: /api/designer/v1/file-content, /api/templates/preview, /.aws/config, /.docker/.env, /.env.
show less
Port Scan
Hacking
Web App Attack
๐บ๐ธ
masterguru
2026-09-24 05:57:45
(9 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "GPTBot" at REQUEST_HEADERS:user-agent. (1100000-169 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "GPTBot" at REQUEST_HEADERS:user-agent. (1100000-169)
show less
Bad Web Bot
๐ฉ๐ช
itsolon
2026-09-24 05:40:23
(10 hours ago)
[24/Sep/2026:07:40:22 +0200] 179022842288.708275 35.185.241.89 54790 217.154.7.177 443
[24/Sep/2026: ...
show more
[24/Sep/2026:07:40:22 +0200] 179022842288.708275 35.185.241.89 54790 217.154.7.177 443
[24/Sep/2026:07:40:22 +0200] 179022842267.097958 35.185.241.89 54790 217.154.7.177 443
[24/Sep/2026:07:40:22 +0200] 17902284225.480405 35.185.241.89 54790 217.154.7.177 443
[24/Sep/2026:07:40:22 +0200] 179022842226.761780 35.185.241.89 54790 217.154.7.177 443
[24/Sep/2026:07:40:22 +0200] 179022842252.604146 35.185.241.89 54790 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 04:51:40
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.185.241.89 (89.241.185.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.185.241.89 (89.241.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:51:36.047407 2026] [security2:error] [pid 8961:tid 9018] [client 35.185.241.89:51158] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.flapjacktoys.com|F|2"] [data ".flapjacktoys.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.flapjacktoys.com"] [uri "/z9x8c7v6b5-debug-trigger-www.flapjacktoys.com"] [unique_id "arSsWHRwkJb_jj1iyXPRggAAARg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 04:16:54
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.185.241.89 (89.241.185.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.185.241.89 (89.241.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:16:46.593564 2026] [security2:error] [pid 22589:tid 22589] [client 35.185.241.89:54124] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.d-sinema.com|F|2"] [data ".d-sinema.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.d-sinema.com"] [uri "/z9x8c7v6b5-debug-trigger-www.d-sinema.com"] [unique_id "arSkLt-LlMotH5cKzpqDAAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-24 03:05:05
(12 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 02:47:54
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.185.241.89 (89.241.185.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.185.241.89 (89.241.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:47:48.241307 2026] [security2:error] [pid 7914:tid 7914] [client 35.185.241.89:37242] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.30daysout.com|F|2"] [data ".30daysout.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.30daysout.com"] [uri "/z9x8c7v6b5-debug-trigger-www.30daysout.com"] [unique_id "arSPVLEj8hG3Q6h7K3_SCAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 02:03:19
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.185.241.89 (89.241.185.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.185.241.89 (89.241.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:03:11.706707 2026] [security2:error] [pid 9025:tid 9046] [client 35.185.241.89:35056] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ardentsi.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ardentsi.com"] [uri "/z9x8c7v6b5-debug-trigger-ardentsi.com"] [unique_id "arSE3wQhJIJTtPlPojbi0gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
debestelapp
2026-09-24 01:55:10
(13 hours ago)
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 01:33:55
(14 hours ago)
134 requests with url.path *.php.bak
100 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-24 01:30:55
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.185.241.89 (89.241.185.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.185.241.89 (89.241.185.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:30:50.905342 2026] [security2:error] [pid 3920:tid 3920] [client 35.185.241.89:38472] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bonefrog.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bonefrog.com"] [uri "/z9x8c7v6b5-debug-trigger-bonefrog.com"] [unique_id "arR9SgUup_rhgK9Pq0FKggAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack