πΊπΈ
TPI-Abuse
2026-09-20 15:26:04
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.187.7.0 (0.7.187.35.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 35.187.7.0 (0.7.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:25:59.312593 2026] [security2:error] [pid 8868:tid 8868] [client 35.187.7.0:49852] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||skyesongtollers.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "skyesongtollers.com"] [uri "/z9x8c7v6b5-debug-trigger-skyesongtollers.com"] [unique_id "aq_7BzIr6Yo81E05XgtGmgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
dot.mg
2026-09-20 15:22:08
(8 hours ago)
Bad behaviour
Web Spam
π³π±
Savvii
2026-09-20 15:20:40
(8 hours ago)
20 attempts against mh-misbehave-ban on moon
Brute-Force
Bad Web Bot
Web App Attack
π³π±
e.fierstra
2026-09-20 15:17:45
(8 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 15:10:17
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.187.7.0 (0.7.187.35.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.7.0 (0.7.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:10:11.929159 2026] [security2:error] [pid 2752:tid 2752] [client 35.187.7.0:54540] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sjjcox.com"] [uri "/public/.env"] [unique_id "aq_3U6LEI5F4PK8QprsJnwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
netclix.gr
2026-09-20 15:08:43
(8 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.187.7.0 (BE/Belgium/0.7.187.35.bc.go ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.187.7.0 (BE/Belgium/0.7.187.35.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
π©πͺ
yvoictra
2026-09-20 14:57:40
(9 hours ago)
Bloqueado automΓ‘ticamente por CrowdSec. Escenario: crowdsecurity/http-probing
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 14:54:52
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.187.7.0 (0.7.187.35.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210730) triggered by 35.187.7.0 (0.7.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:54:46.662854 2026] [security2:error] [pid 10456:tid 10456] [client 35.187.7.0:56990] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sipkg.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sipkg.com"] [uri "/z9x8c7v6b5-debug-trigger-sipkg.com"] [unique_id "aq_ztpZXT0OPIIEkG777eQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
Mediashaker
2026-09-20 14:54:19
(9 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.187.7.0 (BE/Belgi ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.187.7.0 (BE/Belgium/0.7.187.35.bc.googleusercontent.com)
show less
Bad Web Bot
π«π·
masterguru
2026-09-20 14:45:25
(9 hours ago)
Restricted File Access Attempt. Matched phrase ".gitconfig" at REQUEST_FILENAME. (930130-195)
Hacking
Web App Attack
π©πͺ
thesimonmanuel
2026-09-20 14:37:02
(9 hours ago)
35.187.7.0 - - [20/Sep/2026:20:07:01 +0530] "GET /app/.env HTTP/2.0" 403 106 "-" "Mozilla/5.0 (compa ...
show more
35.187.7.0 - - [20/Sep/2026:20:07:01 +0530] "GET /app/.env HTTP/2.0" 403 106 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
show less
Web App Attack
Anonymous
2026-09-20 14:34:07
(9 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.187.7.0 (BE/Belgium/0.7.187.35.bc.go ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.187.7.0 (BE/Belgium/0.7.187.35.bc.googleusercontent.com)
show less
SQL Injection
π³π±
BlueWire Hosting
2026-09-20 14:30:22
(9 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-20 14:28:54
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.187.7.0 (0.7.187.35.bc.googleusercontent.com ...
show more
(mod_security) mod_security (id:210492) triggered by 35.187.7.0 (0.7.187.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:28:47.890019 2026] [security2:error] [pid 21123:tid 21123] [client 35.187.7.0:60926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "silsby.com"] [uri "/workspace/.env"] [unique_id "aq_tn42uec2vWTv3CQAfUQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
masterguru
2026-09-20 14:25:47
(9 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "bytespider" at REQUEST_HEADERS:User-Agent. (1100000-196)
show less
Bad Web Bot