๐ซ๐ท
tecnoacquisti.com
2026-09-22 17:35:40
(53 seconds ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:30:38
(5 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.194.213.25 (25.213.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.213.25 (25.213.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:30:31.591595 2026] [security2:error] [pid 27194:tid 27194] [client 35.194.213.25:38434] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||teenybikinigirls.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "teenybikinigirls.com"] [uri "/z9x8c7v6b5-debug-trigger-teenybikinigirls.com"] [unique_id "arK7Nw51GU8YLWYX04LW4wAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Starburst SysOp Team
2026-09-22 17:19:47
(16 minutes ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-mnz6-1)
show less
Bad Web Bot
๐ช๐ธ
robotstxt
2026-09-22 17:17:08
(19 minutes ago)
35.194.213.25 - - [22/Sep/2026:17:16:16 +0000] "GET /admin/.env HTTP/2.0" 403 16021 "-" "Mozilla/5.0 ...
show more
35.194.213.25 - - [22/Sep/2026:17:16:16 +0000] "GET /admin/.env HTTP/2.0" 403 16021 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
35.194.213.25 - - [22/Sep/2026:17:16:16 +0000] "GET /api/.env HTTP/2.0" 403 16020 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
35.194.213.25 - - [22/Sep/2026:17:16:16 +0000] "GET /.env.save HTTP/2.0" 403 16021 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
35.194.213.25 - - [22/Sep/2026:17:16:16 +0000] "GET /.env.old HTTP/2.0" 403 16021 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
35.194.213.25 - - [22/Sep/2026:17:16:16 +0000] "GET /src/.env HTTP/2.0" 403 16021 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
...
show less
Web App Attack
๐ซ๐ท
Rom74
2026-09-22 16:59:24
(37 minutes ago)
[Tue Sep 22 18:59:16.383935 2026] [security2:error] [pid 1387306:tid 129072675837632] [client 35.194 ...
show more
[Tue Sep 22 18:59:16.383935 2026] [security2:error] [pid 1387306:tid 129072675837632] [client 35.194.213.25:0] [client 35.194.213.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 15)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "teslogiciels.com"] [uri "/"] [unique_id "arKz5CbZW6bDAm9HS2slGQAAAAU"]
[Tue Sep 22 18:59:23.078764 2026] [security2:error] [pid 1387306:tid 129072692623040] [client 35.194.213.25:0] [client 35.194.213.25] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5
...
show less
Web App Attack
๐บ๐ธ
lavnet.net
2026-09-22 16:53:42
(42 minutes ago)
35.194.213.25 - - [22/Sep/2026:16:53:42 +0000] "GET /wu2nhttzrkumvcqiaypr HTTP/2.0" 404 1901 "-" "Mo ...
show more
35.194.213.25 - - [22/Sep/2026:16:53:42 +0000] "GET /wu2nhttzrkumvcqiaypr HTTP/2.0" 404 1901 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
35.194.213.25 - - [22/Sep/2026:16:53:42 +0000] "GET /secure HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
35.194.213.25 - - [22/Sep/2026:16:53:42 +0000] "GET /sign-in HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
35.194.213.25 - - [22/Sep/2026:16:53:42 +0000] "GET /user/login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
35.194.213.25 - - [22/Sep/2026:16:53:42 +0000] "GET /login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHT
...
show less
Brute-Force
๐น๐ญ
thaizone.com
2026-09-22 16:42:30
(54 minutes ago)
Brute Force Attack on a Web Resources #1
DDoS Attack
Web Spam
Brute-Force
Web App Attack
๐ฉ๐ช
thesimonmanuel
2026-09-22 16:23:59
(1 hour ago)
35.194.213.25 - - [22/Sep/2026:21:53:58 +0530] "GET /api/uploads/%2e%2e%2f%2e%2e%2f.env HTTP/2.0" 40 ...
show more
35.194.213.25 - - [22/Sep/2026:21:53:58 +0530] "GET /api/uploads/%2e%2e%2f%2e%2e%2f.env HTTP/2.0" 403 106 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:23:23
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.194.213.25 (25.213.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.213.25 (25.213.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:23:16.671825 2026] [security2:error] [pid 26056:tid 26056] [client 35.194.213.25:37026] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thebeesgold.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thebeesgold.com"] [uri "/z9x8c7v6b5-debug-trigger-thebeesgold.com"] [unique_id "arKrdF6izqPOQ3hKRy3y-wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:49:43
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.194.213.25 (25.213.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.213.25 (25.213.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:49:38.049001 2026] [security2:error] [pid 25732:tid 25732] [client 35.194.213.25:53660] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||theledman.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "theledman.com"] [uri "/z9x8c7v6b5-debug-trigger-theledman.com"] [unique_id "arKVgmZwC7O5HkjngCc7OAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
svr
2026-09-22 14:32:24
(3 hours ago)
Abusive Automated Web Scanner
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:22:57
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.194.213.25 (25.213.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.213.25 (25.213.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:22:53.460306 2026] [security2:error] [pid 13569:tid 13569] [client 35.194.213.25:57246] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thepenandquill.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thepenandquill.com"] [uri "/z9x8c7v6b5-debug-trigger-thepenandquill.com"] [unique_id "arKPPYu1rpkPOzQwG1esPAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:46:28
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.194.213.25 (25.213.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.213.25 (25.213.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:46:24.225315 2026] [security2:error] [pid 25734:tid 25734] [client 35.194.213.25:56354] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thewarmachineguns.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thewarmachineguns.com"] [uri "/z9x8c7v6b5-debug-trigger-thewarmachineguns.com"] [unique_id "arKGsFG8xcikkJnyuNiKswAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
anotherwatcher
2026-09-22 13:36:45
(3 hours ago)
bad bot
Bad Web Bot
๐ฉ๐ช
4server
2026-09-22 12:51:26
(4 hours ago)
[TueSep2214:51:22.6974982026][security2:error][pid783378:tid783421][client35.194.213.25:0]ModSecurit ...
show more
[TueSep2214:51:22.6974982026][security2:error][pid783378:tid783421][client35.194.213.25:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Stringmatchwithin\".asa/.asax/.ascx/.backup/.bak/.bat/.cdx/.cer/.cfg/.cmd/.com/.config/.conf/.cs/.csproj/.csr/.dat/.db/.dbf/.dll/.dos/.htr/.htw/.ida/.idc/.idq/.inc/.ini/.key/.licx/.lnk/.log/.mdb/.old/.pass/.pdb/.pol/.printer/.pwd/.rdb/.resources/.resx/.sql/.swp/.sys/.vb/.vbs/.vbproj/.vsdisco/.webinfo/.xsx/\"atTX:extension.[file\"/etc/apache2/conf.d/modsec_rules/00_asl_zz_strict.conf\"][line\"91\"][id\"390716\"][rev\"2\"][msg\"Atomicorp.comWAFRules:URLfileextensionisrestrictedbypolicy\"][data\".com\"][severity\"ERROR\"][hostname\"titrasloco.com\"][uri\"/z9x8c7v6b5-debug-trigger-titrasloco.com\"][unique_id\"arJ5ykw__gNdqrCWr1SFJQAAAEU\"]
show less
Port Scan
Brute-Force
Web App Attack