๐ฉ๐ช
DEV-DNS
2026-09-22 15:56:30
(47 minutes ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-22 15:51:17
(52 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.193.151.170 (170.151.193.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.193.151.170 (170.151.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:51:12.070605 2026] [security2:error] [pid 10963:tid 10963] [client 35.193.151.170:50214] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||krankybitchguitars.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "krankybitchguitars.com"] [uri "/z9x8c7v6b5-debug-trigger-krankybitchguitars.com"] [unique_id "arKj8PI06nBHOLi2InttlwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-22 14:46:01
(1 hour ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-22 14:42:51
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.193.151.170 (170.151.193.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.193.151.170 (170.151.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:42:47.653947 2026] [security2:error] [pid 30743:tid 30743] [client 35.193.151.170:55222] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||krmartindale.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "krmartindale.com"] [uri "/z9x8c7v6b5-debug-trigger-krmartindale.com"] [unique_id "arKT5zMufLoincB45J31fQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:23:05
(2 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.193.151.170 (170.151.193.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 35.193.151.170 (170.151.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:23:00.085177 2026] [security2:error] [pid 29880:tid 29880] [client 35.193.151.170:59600] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "krupaandsons.com"] [uri "/z9x8c7v6b5-debug-trigger-krupaandsons.com"] [unique_id "arKPRCbIHkkhNoORkdnSCAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 13:10:52
(3 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:39:14
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.193.151.170 (170.151.193.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.193.151.170 (170.151.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:39:10.393174 2026] [security2:error] [pid 4199:tid 4199] [client 35.193.151.170:59892] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kulprid.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kulprid.com"] [uri "/z9x8c7v6b5-debug-trigger-kulprid.com"] [unique_id "arJ27pBhcdf1yYqRI2tczAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-22 12:18:48
(4 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:16:39
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.193.151.170 (170.151.193.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.193.151.170 (170.151.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:16:33.792930 2026] [security2:error] [pid 23145:tid 23145] [client 35.193.151.170:33386] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kunzteam.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kunzteam.com"] [uri "/z9x8c7v6b5-debug-trigger-kunzteam.com"] [unique_id "arJxoejqW_EaCn0BUzsinQAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:00:33
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.193.151.170 (170.151.193.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.193.151.170 (170.151.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:00:27.893229 2026] [security2:error] [pid 10133:tid 10133] [client 35.193.151.170:35802] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kurtkaufman.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kurtkaufman.com"] [uri "/z9x8c7v6b5-debug-trigger-kurtkaufman.com"] [unique_id "arJt27GGDBikPVxIYLwtfAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:21:01
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.193.151.170 (170.151.193.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.193.151.170 (170.151.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:20:57.999264 2026] [security2:error] [pid 13000:tid 13000] [client 35.193.151.170:41432] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kwijlen.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kwijlen.com"] [uri "/z9x8c7v6b5-debug-trigger-kwijlen.com"] [unique_id "arJkmXNYDjWJMtBDJ_OMZgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-22 10:05:25
(6 hours ago)
Scanning/Probing (15)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 09:59:13
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.193.151.170 (170.151.193.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.193.151.170 (170.151.193.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 05:59:06.396226 2026] [security2:error] [pid 29187:tid 29216] [client 35.193.151.170:34854] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kylight.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kylight.com"] [uri "/z9x8c7v6b5-debug-trigger-kylight.com"] [unique_id "arJRagryjH4lXkD7zYHL5gAAAJE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ambor
2026-09-22 09:18:23
(7 hours ago)
L0ss Honeypot: Git configuration file access attempt. Path: /.git/config
Web App Attack
๐ซ๐ท
dynamix
2026-09-22 08:50:23
(7 hours ago)
Multiple WAF Violations
Web App Attack