๐ธ๐ช
vaia.cloud
2026-09-22 14:55:02
(33 minutes ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:31:13
(57 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.187.175.49 (49.175.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.187.175.49 (49.175.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:31:06.176476 2026] [security2:error] [pid 10535:tid 10535] [client 35.187.175.49:39468] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||hwy251.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hwy251.com"] [uri "/z9x8c7v6b5-debug-trigger-hwy251.com"] [unique_id "arKRKiBXDZgHGxVYFiQV_QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 13:56:53
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ซ๐ท
ELYAZ
2026-09-22 13:47:51
(1 hour ago)
(y3) Failed access -byebye- from 35.187.175.49 (BE/Belgium/49.175.187.35.bc.googleusercontent.com): ...
show more
(y3) Failed access -byebye- from 35.187.175.49 (BE/Belgium/49.175.187.35.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
๐บ๐ธ
legionMCCXV
2026-09-22 13:33:02
(1 hour ago)
Non-HTTP protocol data (e.g. MQTT/TLS handshake bytes) sent to HTTP(S) port.
Port Scan
Hacking
Anonymous
2026-09-22 13:23:27
(2 hours ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
Anonymous
2026-09-22 12:28:56
(2 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:12:58
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.187.175.49 (49.175.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.187.175.49 (49.175.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:12:52.308174 2026] [security2:error] [pid 21217:tid 21217] [client 35.187.175.49:60960] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ianadolphusthomas.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ianadolphusthomas.com"] [uri "/z9x8c7v6b5-debug-trigger-ianadolphusthomas.com"] [unique_id "arJwxNArVpZq-VOGqt0dtQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-22 12:05:21
(3 hours ago)
Too many Status 40X (16)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:56:50
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.187.175.49 (49.175.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.187.175.49 (49.175.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:56:42.932914 2026] [security2:error] [pid 2955:tid 2955] [client 35.187.175.49:57442] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ibcnu.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ibcnu.com"] [uri "/z9x8c7v6b5-debug-trigger-ibcnu.com"] [unique_id "arJs-r1DB9CqokBuFYVgMQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:12:02
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.187.175.49 (49.175.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.187.175.49 (49.175.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:11:56.694985 2026] [security2:error] [pid 25183:tid 25183] [client 35.187.175.49:58474] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||iceofparadise.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "iceofparadise.com"] [uri "/z9x8c7v6b5-debug-trigger-iceofparadise.com"] [unique_id "arJifMbyui4vfOnIBiGccQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Mediashaker
2026-09-22 11:09:22
(4 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.187.175.49 (BE/Be ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.187.175.49 (BE/Belgium/49.175.187.35.bc.googleusercontent.com)
show less
Bad Web Bot
๐ซ๐ท
masterguru
2026-09-22 10:51:05
(4 hours ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-196)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 10:05:24
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.187.175.49 (49.175.187.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.187.175.49 (49.175.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:05:20.509295 2026] [security2:error] [pid 26672:tid 26672] [client 35.187.175.49:59926] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||icwcruisersguide.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "icwcruisersguide.com"] [uri "/z9x8c7v6b5-debug-trigger-icwcruisersguide.com"] [unique_id "arJS4N8bs1mIS7XorjcPzAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-22 09:51:41
(5 hours ago)
230 requests with url.path */proc/*
Brute-Force
Bad Web Bot