๐ซ๐ท
IRISIO
2026-10-01 08:29:07
(2 days ago)
scans/SQL injection/spam posts : 5318 queries
Web App Attack
SQL Injection
๐ณ๐ฑ
Site.eu
2026-09-30 19:32:19
(3 days ago)
Excessive multi-domain requests
Brute-Force
๐ซ๐ท
IRISIO
2026-09-30 17:20:55
(3 days ago)
scans/SQL injection/spam posts : 3811 queries
Web App Attack
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-30 15:24:19
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.198.14.112 (112.14.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.198.14.112 (112.14.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:24:12.983446 2026] [security2:error] [pid 13027:tid 13027] [client 35.198.14.112:33616] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wwfstudio.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wwfstudio.com"] [uri "/z9x8c7v6b5-debug-trigger-wwfstudio.com"] [unique_id "ar0pnEpvMKw--unjg2LlYAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:07:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.198.14.112 (112.14.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.14.112 (112.14.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:06:57.300432 2026] [security2:error] [pid 18517:tid 18517] [client 35.198.14.112:58464] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.yacht-register-holland.com"] [uri "/.env.php.bak"] [unique_id "ar0lkSLFtyKtjEq8k49hIAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
IRISIO
2026-09-30 14:56:05
(3 days ago)
scans/SQL injection/spam posts : 3759 queries
Web App Attack
SQL Injection
Anonymous
2026-09-30 14:33:00
(3 days ago)
Excessive crawling/scraping. Vulnerable file probing.
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 13:12:41
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 35.198.14.112 (112.14.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 35.198.14.112 (112.14.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 09:12:37.853733 2026] [security2:error] [pid 4383:tid 4383] [client 35.198.14.112:44984] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.woodlandventures.com"] [uri "/server.key"] [unique_id "ar0KxerB0C5BNq8IzDqO4AAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
IRISIO
2026-09-30 13:08:43
(3 days ago)
scans/SQL injection/spam posts : 3134 queries
Web App Attack
SQL Injection
๐ณ๐ฑ
Savvii
2026-09-30 12:46:27
(3 days ago)
20 attempts against mh-misbehave-ban on lunar
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:38:08
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.198.14.112 (112.14.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.198.14.112 (112.14.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:38:00.872571 2026] [security2:error] [pid 11617:tid 11617] [client 35.198.14.112:36654] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||yalaz.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "yalaz.com"] [uri "/z9x8c7v6b5-debug-trigger-yalaz.com"] [unique_id "ar0CqJ3Qdu7SMIzk3-WvUAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
WebNiraj
2026-09-30 12:35:12
(3 days ago)
(mod_security) mod_security (id:949110) triggered by 35.198.14.112 (BR/Brazil/112.14.198.35.bc.googl ...
show more
(mod_security) mod_security (id:949110) triggered by 35.198.14.112 (BR/Brazil/112.14.198.35.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-30 12:07:52
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.198.14.112 (112.14.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.198.14.112 (112.14.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:07:47.164788 2026] [security2:error] [pid 2386:tid 2501] [client 35.198.14.112:58874] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wicca-love-spells.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wicca-love-spells.com"] [uri "/z9x8c7v6b5-debug-trigger-wicca-love-spells.com"] [unique_id "arz7k3z5zw5Z8UrhJKQKkQAAAIc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-30 12:05:15
(3 days ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
Anonymous
2026-09-30 12:05:06
(3 days ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack