๐ณ๐ฑ
Alboweb B.V.
2026-10-01 16:11:03
(6 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
Anonymous
2026-10-01 15:53:53
(6 days ago)
IP matched detection query 50 and more bad rqs apache.
Hacking
Bad Web Bot
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 15:10:33
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.189.226.124 (124.226.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.189.226.124 (124.226.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:10:27.576853 2026] [security2:error] [pid 5631:tid 5704] [client 35.189.226.124:57886] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||maryschalkdesign.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "maryschalkdesign.com"] [uri "/z9x8c7v6b5-debug-trigger-maryschalkdesign.com"] [unique_id "ar5346S9q4VW2KoeNpCMngAAAUY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-10-01 15:10:05
(6 days ago)
Bad behaviour
Web Spam
Anonymous
2026-10-01 15:03:22
(6 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฎ๐น
VHosting
2026-10-01 14:25:02
(6 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ช๐ธ
robotstxt
2026-10-01 14:23:41
(6 days ago)
35.189.226.124 - - [01/Oct/2026:14:23:39 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e% ...
show more
35.189.226.124 - - [01/Oct/2026:14:23:39 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="35.189.226.124"
35.189.226.124 - - [01/Oct/2026:14:23:39 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.189.226.124"
35.189.226.124 - - [01/Oct/2026:14:23:39 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.189.226.124"
35.189.226.124 - - [01/Oct/2026:14:23:39 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="35.189.226.124"
35.189.226.124 - - [01/Oct/2026:14:23:39 +0000] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.189.226.124"
...
show less
Web Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:20:23
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.189.226.124 (124.226.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.189.226.124 (124.226.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:20:15.888107 2026] [security2:error] [pid 30355:tid 30355] [client 35.189.226.124:41946] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||marcelacalvet.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "marcelacalvet.com"] [uri "/z9x8c7v6b5-debug-trigger-marcelacalvet.com"] [unique_id "ar5sH_XEi1SPIwVApktLAAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-10-01 13:56:00
(6 days ago)
Wordpress hacking attempt
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:22:56
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.189.226.124 (124.226.189.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.226.124 (124.226.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:22:51.664859 2026] [security2:error] [pid 16675:tid 16675] [client 35.189.226.124:60164] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.extreme-atv.com"] [uri "/.htpasswd"] [unique_id "ar5eq_mHu0M2k-ylCTuYSQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 13:20:06
(6 days ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ณ๐ฑ
Site.eu
2026-10-01 13:11:59
(6 days ago)
Excessive 404/403 errors
Brute-Force
๐ซ๐ท
masterguru
2026-10-01 13:11:49
(6 days ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
Anonymous
2026-10-01 12:59:49
(6 days ago)
Aggressive web scan
Web App Attack
๐ซ๐ท
dynamix
2026-10-01 12:55:02
(6 days ago)
Multiple WAF Violations
Web App Attack