๐ฉ๐ช
findlab
2026-08-21 03:25:02
(48 minutes ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 02:50:23
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.196.162.79 (79.162.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.196.162.79 (79.162.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 22:50:15.958866 2026] [security2:error] [pid 5446:tid 5446] [client 35.196.162.79:56190] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||caminorfoundation.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "caminorfoundation.org"] [uri "/rclone.conf"] [unique_id "aoe856ZtUpLb_ze0BSoLNQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 02:32:12
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.196.162.79 (79.162.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.196.162.79 (79.162.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 22:32:07.221913 2026] [security2:error] [pid 1067:tid 1067] [client 35.196.162.79:49492] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||coolingsprings.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "coolingsprings.org"] [uri "/rclone.conf"] [unique_id "aoe4p2CUGjtTO6KWpcZ5UQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
pixiekat
2026-08-21 02:25:08
(1 hour ago)
[Fri Aug 21 02:25:07.639494 2026] [authz_core:error] [pid 976578:tid 976601] [client 35.196.162.79:5 ...
show more
[Fri Aug 21 02:25:07.639494 2026] [authz_core:error] [pid 976578:tid 976601] [client 35.196.162.79:50714] AH01630: client denied by server configuration: /var/www/vhosts/dcinetwork.org/docroot/.aws
[Fri Aug 21 02:25:07.739272 2026] [authz_core:error] [pid 976578:tid 976598] [client 35.196.162.79:50776] AH01630: client denied by server configuration: /var/www/vhosts/dcinetwork.org/docroot/.aws
[Fri Aug 21 02:25:07.792319 2026] [authz_core:error] [pid 976549:tid 976562] [client 35.196.162.79:50828] AH01630: client denied by server configuration: /var/www/vhosts/dcinetwork.org/docroot/.env.example
[Fri Aug 21 02:25:07.804589 2026] [authz_core:error] [pid 976578:tid 976586] [client 35.196.162.79:50750] AH01630: client denied by server configuration: /var/www/vhosts/dcinetwork.org/docroot/.env
[Fri Aug 21 02:25:07.825465 2026] [authz_core:error] [pid 976549:tid 976563] [client 35.196.162.79:50838] AH01630: client denied by server configuration: /var/www/vhosts/dcinetwork.org/docroot/.env.pr
...
show less
Brute-Force
Anonymous
2026-08-21 02:06:05
(2 hours ago)
Trying to access config files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 02:00:33
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.162.79 (79.162.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.162.79 (79.162.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 22:00:27.518880 2026] [security2:error] [pid 31984:tid 31994] [client 35.196.162.79:42704] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "culturallyyours.org"] [uri "/.git/config"] [unique_id "aoexOxC3Hwx6IIBpLKSfGgAAAYc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 01:39:02
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.196.162.79 (79.162.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.162.79 (79.162.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 21:38:57.490830 2026] [security2:error] [pid 28370:tid 28370] [client 35.196.162.79:52874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "comitedelafamille.org"] [uri "/.git/config"] [unique_id "aoesMV4TreEfVZ5i2UkMPAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
grassau.com
2026-08-21 00:56:09
(3 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.196.162.79 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.196.162.79 (US/United States/South Carolina/North Charleston/79.162.196.35.bc.googleusercontent.com)
show less
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-08-21 00:54:19
(3 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
hyena
2026-08-21 00:34:23
(3 hours ago)
Repeated mod_security events.
Web App Attack
๐ซ๐ท
โจ
2026-08-21 00:02:18
(4 hours ago)
Domain : cambriaseascouts.org
Rule : hack
2026-08-21 00:00:38 ***hidden-privacy*** GET /.env.bak - 4 ...
show more
Domain : cambriaseascouts.org
Rule : hack
2026-08-21 00:00:38 ***hidden-privacy*** GET /.env.bak - 443 - 35.196.162.79 HTTP/2 Mozilla/5.0 (compatible; FacebookBot/1.0; https://developers.facebook.com/docs/sharing/webmasters/crawler) - cambriaseascouts.org 404 0 2 1556 239 88 - -
show less
Hacking
SQL Injection
Brute-Force
๐ณ๐ฑ
CryptoYakari
2026-08-20 23:27:44
(4 hours ago)
2026-08-21 02:27:28,030 fail2ban.actions [918]: NOTICE [nginx-404] Ban 35.196.162.79
2026-08 ...
show more
2026-08-21 02:27:28,030 fail2ban.actions [918]: NOTICE [nginx-404] Ban 35.196.162.79
2026-08-21 02:27:28,273 fail2ban.actions [918]: NOTICE [nginx-baduris] Ban 35.196.162.79
...
show less
Hacking
๐ฉ๐ช
ghostwarriors
2026-08-20 23:20:03
(4 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 23:07:00
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.196.162.79 (79.162.196.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.196.162.79 (79.162.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 19:06:55.814308 2026] [security2:error] [pid 31806:tid 31806] [client 35.196.162.79:53084] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||coolwebsites.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "coolwebsites.org"] [uri "/rclone.conf"] [unique_id "aoeIjz4I0EXhrnJ8-ABqxAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-08-20 22:57:56
(5 hours ago)
35.196.162.79 - - [21/Aug/2026:00:57:53 +0200] "GET /.bashrc HTTP/2.0" 404 316 "-" "Mozilla/5.0 (com ...
show more
35.196.162.79 - - [21/Aug/2026:00:57:53 +0200] "GET /.bashrc HTTP/2.0" 404 316 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
35.196.162.79 - - [21/Aug/2026:00:57:53 +0200] "GET /.mcp.json HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
35.196.162.79 - - [21/Aug/2026:00:57:53 +0200] "GET /.zshrc HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
35.196.162.79 - - [21/Aug/2026:00:57:53 +0200] "GET /.bash_profile HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
35.196.162.79 - - [21/Aug/2026:00:57:53 +0200] "GET /.profile HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
35.196.162.79 - - [21/Aug/2026:00:57:53 +0200] "GET /wp-config.php.bak HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/grokbot)"
35.196.162.79 - - [21/Aug/2026:00:57:53 +0200] "GET /wp-config.php.old HTTP/2.0" 404 293 "-" "Mozilla/5.0
show less
Bad Web Bot