๐ฒ๐ฝ
octageeks.com
2026-09-22 04:11:50
(1 week ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
wbsouza
2026-09-22 03:22:24
(1 week ago)
CrowdSec: crowdsecurity/http-probing โ automated firewall drops on self-hosted IDS sensor
Hacking
๐ณ๐ฑ
Site.eu
2026-09-22 00:48:22
(1 week ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-21 23:18:23
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.195.147.144 (144.147.195.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.195.147.144 (144.147.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:18:16.428263 2026] [security2:error] [pid 32117:tid 32177] [client 35.195.147.144:53798] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.rosicruciansociety.com|F|2"] [data ".rosicruciansociety.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.rosicruciansociety.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.rosicruciansociety.com"] [unique_id "arG7OOjPE2gcsqkHyJTIOwAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 19:16:40
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.195.147.144 (144.147.195.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.147.144 (144.147.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 15:16:34.140904 2026] [security2:error] [pid 26976:tid 26976] [client 35.195.147.144:39696] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.rosemeadefarms.com"] [uri "/.env.local"] [unique_id "arGCknonNl9Q4k3Jq8xRIwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-21 18:23:15
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 16:31:09
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.195.147.144 (144.147.195.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.195.147.144 (144.147.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 12:31:01.240999 2026] [security2:error] [pid 9714:tid 9714] [client 35.195.147.144:55182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.rphenry.com"] [uri "/.env.example"] [unique_id "arFbxU-kzMjUWbd2PlJX4QAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
GabrielJST
2026-09-21 15:27:41
(1 week ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.195.147.144 (BE/B ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.195.147.144 (BE/Belgium/144.147.195.35.bc.googleusercontent.com)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 15:21:21
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.195.147.144 (144.147.195.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.195.147.144 (144.147.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:21:13.089461 2026] [security2:error] [pid 23261:tid 23261] [client 35.195.147.144:57878] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||midwayisland.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "midwayisland.com"] [uri "/z9x8c7v6b5-debug-trigger-midwayisland.com"] [unique_id "arFLab-hrwV0uWUX8PVEhQAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-21 15:13:47
(1 week ago)
20 attempts against mh-misbehave-ban on ethyl
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-21 14:48:13
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-21 14:28:45
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.195.147.144 (144.147.195.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.195.147.144 (144.147.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:28:38.180057 2026] [security2:error] [pid 4644:tid 4644] [client 35.195.147.144:33864] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.roselowry.com|F|2"] [data ".roselowry.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.roselowry.com"] [uri "/z9x8c7v6b5-debug-trigger-www.roselowry.com"] [unique_id "arE_FqroLukKvdr9NYWPpAAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
eliosbrocchi
2026-09-21 14:16:06
(1 week ago)
35.195.147.144 - - [21/Sep/2026:16:16:05 +0200] "GET /@fs/.env?url&raw?? HTTP/2.0" 200 682 "-" "Mozi ...
show more
35.195.147.144 - - [21/Sep/2026:16:16:05 +0200] "GET /@fs/.env?url&raw?? HTTP/2.0" 200 682 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
...
show less
VPN IP
๐ฑ๐ป
garmtech.com
2026-09-21 14:15:09
(1 week ago)
Attempted access to sensitive endpoint (/.env.php.bak) detected. Automated scan or unauthorized prob ...
show more
Attempted access to sensitive endpoint (/.env.php.bak) detected. Automated scan or unauthorized probing.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:13:16
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.195.147.144 (144.147.195.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.195.147.144 (144.147.195.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:13:09.727625 2026] [security2:error] [pid 26294:tid 26294] [client 35.195.147.144:44112] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||training.oxfordgliding.com|F|2"] [data ".oxfordgliding.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "training.oxfordgliding.com"] [uri "/z9x8c7v6b5-debug-trigger-training.oxfordgliding.com"] [unique_id "arE7dV83gC1ognAlZJU_DwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack