๐ซ๐ท
masterguru
2026-09-22 01:22:31
(1 week ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-195)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 00:26:44
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.196.47.66 (66.47.196.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.196.47.66 (66.47.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:26:36.731013 2026] [security2:error] [pid 32071:tid 32071] [client 35.196.47.66:38886] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.grupoporvenir.com"] [uri "/.git/HEAD"] [unique_id "arHLPMCZEZNHwHfj3OomKQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:25:53
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.196.47.66 (66.47.196.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.196.47.66 (66.47.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:25:49.270352 2026] [security2:error] [pid 18181:tid 18181] [client 35.196.47.66:36818] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.serranolopezarquitectos.com|F|2"] [data ".serranolopezarquitectos.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.serranolopezarquitectos.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.serranolopezarquitectos.com"] [unique_id "arGg3XNsa33UcFpXzLIQqwAAAI8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
oja
2026-09-21 20:53:39
(1 week ago)
Aggressive web scanner
Web App Attack
๐ฌ๐ง
consul.to
2026-09-21 20:49:13
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐ช๐ธ
scaballe
2026-09-21 20:16:33
(1 week ago)
Web App Attack
๐ซ๐ท
COMAITE
2026-09-21 19:38:40
(1 week ago)
Common web attack from 35.196.47.66.
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-21 18:41:39
(1 week ago)
[Mon Sep 21 14:41:38.052261 2026] [authz_core:error] [pid 2134417:tid 139705622460160] [client 35.19 ...
show more
[Mon Sep 21 14:41:38.052261 2026] [authz_core:error] [pid 2134417:tid 139705622460160] [client 35.196.47.66:0] AH01630: client denied by server configuration: /usr/share/psa-roundcube/.git-credentials
[Mon Sep 21 14:41:38.259754 2026] [authz_core:error] [pid 2134417:tid 139704942978816] [client 35.196.47.66:0] AH01630: client denied by server configuration: /usr/share/psa-roundcube/.env.live
[Mon Sep 21 14:41:38.942793 2026] [authz_core:error] [pid 2134417:tid 139704473216768] [client 35.196.47.66:0] AH01630: client denied by server configuration: /usr/share/psa-roundcube/@fs
[Mon Sep 21 14:41:38.948889 2026] [authz_core:error] [pid 2134417:tid 139704926193408] [client 35.196.47.66:0] AH01630: client denied by server configuration: /usr/share/psa-roundcube/@fs
[Mon Sep 21 14:41:39.010128 2026] [authz_core:error] [pid 1807105:tid 139705572103936] [client 35.196.47.66:0] AH01630: client denied by server configuration: /usr/share/psa-roundcube/trace.axd
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:33:49
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.196.47.66 (66.47.196.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.196.47.66 (66.47.196.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:33:40.647611 2026] [security2:error] [pid 12533:tid 12533] [client 35.196.47.66:58032] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.shafoo.com|F|2"] [data ".shafoo.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.shafoo.com"] [uri "/z9x8c7v6b5-debug-trigger-www.shafoo.com"] [unique_id "arFARAyODIoCgT1JBJQR9gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 14:24:30
(1 week ago)
Aggressive web scan
Web App Attack
๐ฉ๐ช
rh24
2026-09-21 14:21:15
(1 week ago)
(badbots) Bad bot user-agent [redacted] from 35.196.47.66 (US/United States/66.47.196.35.bc.googleus ...
show more
(badbots) Bad bot user-agent [redacted] from 35.196.47.66 (US/United States/66.47.196.35.bc.googleusercontent.com)
show less
Hacking
๐บ๐ธ
k3rn3l109
2026-09-21 14:19:13
(1 week ago)
Sentinel honeypot: domain-honeypot hit on argocd.sentinelmdm.com UA=Mozilla/5.0 (Macintosh; Intel Ma ...
show more
Sentinel honeypot: domain-honeypot hit on argocd.sentinelmdm.com UA=Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0
show less
Hacking
๐ฉ๐ช
sfmet-admin
2026-09-21 14:12:34
(1 week ago)
35.196.47.66 - - [21/Sep/2026:14:12:33 +0000] "GET /@fs/../.env?raw?? HTTP/2.0" 200 55 "-" "Mozilla/ ...
show more
35.196.47.66 - - [21/Sep/2026:14:12:33 +0000] "GET /@fs/../.env?raw?? HTTP/2.0" 200 55 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
...
show less
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-21 14:00:39
(1 week ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.196.47.66 (US/United States/66.47 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.196.47.66 (US/United States/66.47.196.35.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
Anonymous
2026-09-21 14:00:11
(1 week ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection