๐บ๐ธ
TPI-Abuse
2026-09-29 22:15:36
(42 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.198.53.158 (158.53.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.198.53.158 (158.53.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:15:29.548523 2026] [security2:error] [pid 9909:tid 9909] [client 35.198.53.158:38266] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rhysryan.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rhysryan.com"] [uri "/z9x8c7v6b5-debug-trigger-rhysryan.com"] [unique_id "arw4gRrAgBQdvlGBoqE0eAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-29 22:00:34
(57 minutes ago)
Auto-ban: >3000 req/min op 2026-09-29
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-29 21:44:05
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.198.53.158 (158.53.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.53.158 (158.53.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:43:58.096682 2026] [security2:error] [pid 11309:tid 11309] [client 35.198.53.158:41014] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "rohanbyles.com.au"] [uri "/wp-config.php.swp"] [unique_id "arwxHmuIC35g5K09qIOujQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-29 21:43:02
(1 hour ago)
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35. ...
show more
[ti-01ov] Web exploit scanning: 1 suspicious requests detected by fail2ban jail <name>. Example: 35.198.53.158 - - \[29/Sep/2026:23:42:59 +0200\] "GET /.env.development HTTP/1.1" 301 596 "-" "CCBot/2.0 \(https://commoncrawl.org/faq/\)"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-29 21:30:20
(1 hour ago)
Excessive multi-domain requests
Brute-Force
๐ฌ๐ง
consul.to
2026-09-29 19:08:59
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ง๐ฌ
Stoyko Stoykov
2026-09-29 19:06:14
(3 hours ago)
35.198.53.158 - - [29/Sep/2026:22:06:13 +0300] "GET /config/master.key HTTP/2.0" 404 0 "-" "Mozilla/ ...
show more
35.198.53.158 - - [29/Sep/2026:22:06:13 +0300] "GET /config/master.key HTTP/2.0" 404 0 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
...
show less
Hacking
Web App Attack
Anonymous
2026-09-29 18:43:57
(4 hours ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-29 18:36:29
(4 hours ago)
(mod_security) mod_security (id:210580) triggered by 35.198.53.158 (158.53.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 35.198.53.158 (158.53.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 14:36:23.204132 2026] [security2:error] [pid 10144:tid 10144] [client 35.198.53.158:41490] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:apis. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||ringbearerpillows.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:apis: ../../../../../../proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "ringbearerpillows.com"] [uri "/api/console/api_server"] [unique_id "arwFJ15Cdmud4XaHTqDy7gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Anytech
2026-09-29 17:59:50
(4 hours ago)
Blocked by ConnMonitor
Web App Attack
Anonymous
2026-09-29 17:58:12
(5 hours ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ง๐พ
lns.bz
2026-09-29 17:55:25
(5 hours ago)
Too many 404 requests [BY]
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 17:40:51
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.198.53.158 (158.53.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.198.53.158 (158.53.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 13:40:45.780077 2026] [security2:error] [pid 24706:tid 24706] [client 35.198.53.158:42966] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||restaurantfixture.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "restaurantfixture.com"] [uri "/z9x8c7v6b5-debug-trigger-restaurantfixture.com"] [unique_id "arv4HRcPKJw0DwzCrRqiTgAAADE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Marco711
2026-09-29 17:35:19
(5 hours ago)
CrowdSec: LePresidente/http-generic-401-bf
Web App Attack
๐ซ๐ท
dynamix
2026-09-29 17:30:48
(5 hours ago)
Multiple WAF Violations
Web App Attack