๐บ๐ธ
TPI-Abuse
2026-09-24 13:15:42
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.199.116.147 (147.116.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.116.147 (147.116.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 09:15:38.367481 2026] [security2:error] [pid 3925:tid 3943] [client 35.199.116.147:53160] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.honeyled.com|F|2"] [data ".honeyled.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.honeyled.com"] [uri "/z9x8c7v6b5-debug-trigger-www.honeyled.com"] [unique_id "arUiegzAKQx57BB8B3Ig5AAAAFA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 12:52:09
(1 hour ago)
(mod_security) mod_security (id:949110) triggered by 35.199.116.147 (147.116.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 35.199.116.147 (147.116.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 08:52:01.735724 2026] [security2:error] [pid 25640:tid 25640] [client 35.199.116.147:51950] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 10)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.789-bid.crazycontrols.com"] [uri "/web.config"] [unique_id "arUc8b228WHxEXQWtP1TUQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-09-24 12:34:31
(2 hours ago)
(mod_security) mod_security (id:930120) triggered by 35.199.116.147 (BR/Brazil/147.116.199.35.bc.goo ...
show more
(mod_security) mod_security (id:930120) triggered by 35.199.116.147 (BR/Brazil/147.116.199.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 11:45:40
(2 hours ago)
254 requests with url.path */@fs/*
110 requests with url.path */proc/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-24 11:36:54
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.199.116.147 (147.116.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.116.147 (147.116.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 07:36:50.470399 2026] [security2:error] [pid 7519:tid 7519] [client 35.199.116.147:47664] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.abuscalledfreedom.com|F|2"] [data ".abuscalledfreedom.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.abuscalledfreedom.com"] [uri "/z9x8c7v6b5-debug-trigger-www.abuscalledfreedom.com"] [unique_id "arULUv2wfITxeSKbthu6bwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-24 11:23:15
(3 hours ago)
This address swept through a list of pages that do not exist on our site within seconds โ a scanner ...
show more
This address swept through a list of pages that do not exist on our site within seconds โ a scanner working through its wordlist of exploitable paths. Blocked; please check the machine behind it for a scanner or malware. | method: GET | path: /assets/manifest.json (+5 more) | 2026-09-24 11:23 UTC
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 11:13:41
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.199.116.147 (147.116.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.116.147 (147.116.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 07:13:37.311387 2026] [security2:error] [pid 3247:tid 3247] [client 35.199.116.147:57092] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.abq4you.com|F|2"] [data ".abq4you.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.abq4you.com"] [uri "/z9x8c7v6b5-debug-trigger-www.abq4you.com"] [unique_id "arUF4Yi8CP_DL7fLcO_OHwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 10:48:47
(3 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.116.147 (147.116.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.116.147 (147.116.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 06:48:40.417612 2026] [security2:error] [pid 4119:tid 4119] [client 35.199.116.147:34380] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.abilityimprinting.com"] [uri "/.env.prod"] [unique_id "arUACBdFUcWZuW83aEfufwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 09:30:47
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.199.116.147 (147.116.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.116.147 (147.116.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 05:30:43.645493 2026] [security2:error] [pid 18785:tid 18785] [client 35.199.116.147:59380] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.aallred.com|F|2"] [data ".aallred.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.aallred.com"] [uri "/z9x8c7v6b5-debug-trigger-www.aallred.com"] [unique_id "arTtw5rSPeGTe-S4oyQ1wgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 03:14:41
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.199.116.147 (147.116.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.116.147 (147.116.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 23:14:35.423220 2026] [security2:error] [pid 4797:tid 4797] [client 35.199.116.147:55226] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.72blues.com|F|2"] [data ".72blues.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.72blues.com"] [uri "/z9x8c7v6b5-debug-trigger-www.72blues.com"] [unique_id "arSVm2DrxxNpv3b8rbKEPQAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
sibahota
2026-09-24 02:03:22
(12 hours ago)
35.199.116.147 - - [24/Sep/2026:02:03:22 +0000] www.69moods.com "GET /.streamlit/secrets.toml HTTP/1 ...
show more
35.199.116.147 - - [24/Sep/2026:02:03:22 +0000] www.69moods.com "GET /.streamlit/secrets.toml HTTP/1.1" 404 134 0.001 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" 172.17.0.1:8080 404 0.001 "http://www.69moods.com/.streamlit/secrets.toml"
...
show less
Web App Attack
Brute-Force
๐ณ๐ฑ
Alt255
2026-09-23 22:47:24
(15 hours ago)
[cb-01vi] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-01vi] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.199.116.147 - - [24/Sep/2026:00:47:23 +0200] "GET /.env.save HTTP/2.0" 403 369 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-23 19:57:21
(18 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-23 18:25:57
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.199.116.147 (147.116.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.116.147 (147.116.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:25:51.035031 2026] [security2:error] [pid 4373:tid 4373] [client 35.199.116.147:55014] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||a-absoluteseptic.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "a-absoluteseptic.com"] [uri "/z9x8c7v6b5-debug-trigger-a-absoluteseptic.com"] [unique_id "arQZr-G99AyoLvsdFBDRhgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 17:35:48
(21 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.199.116.147 (147.116.199.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.199.116.147 (147.116.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 13:35:42.986613 2026] [security2:error] [pid 15047:tid 15047] [client 35.199.116.147:33314] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "aantariaconstructions.com"] [uri "/build/.env"] [unique_id "arQN7lfxT4tpyfWCKr4WHAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack