๐ฆ๐บ
clapper
2026-10-11 01:24:27
(28 minutes ago)
(mod_security) mod_security (id:980001) triggered by 35.200.25.156 (JP/Japan/156.25.200.35.bc.google ...
show more
(mod_security) mod_security (id:980001) triggered by 35.200.25.156 (JP/Japan/156.25.200.35.bc.googleusercontent.com): 5 in the last 3600 secs; ID: Clar
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
agenciahypelab.com.br
2026-10-11 01:22:16
(30 minutes ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-10-11 01:03:40
(49 minutes ago)
(mod_security) mod_security (id:210580) triggered by 35.200.25.156 (156.25.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 35.200.25.156 (156.25.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 21:03:35.633148 2026] [security2:error] [pid 6576:tid 6576] [client 35.200.25.156:36992] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||riverflow.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "riverflow.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "asrgZ0kqQfIpy3x6z6GYAAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
rh24
2026-10-11 01:00:43
(52 minutes ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.200.25.156 (JP/Ja ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.200.25.156 (JP/Japan/156.25.200.35.bc.googleusercontent.com)
show less
Bad Web Bot
๐ฌ๐ง
andypiper
2026-10-11 01:00:14
(52 minutes ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 00:48:17
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.200.25.156 (156.25.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.200.25.156 (156.25.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 20:48:13.906101 2026] [security2:error] [pid 24161:tid 24161] [client 35.200.25.156:49192] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||my1611.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "my1611.com"] [uri "/z9x8c7v6b5-debug-trigger-my1611.com"] [unique_id "asrczddisHMV-idBzQFRFQAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Catalin Negru
2026-10-11 00:32:33
(1 hour ago)
2026-10-11 03:32:31,341 fail2ban.actions [783]: NOTICE [apache-404] Ban 35.200.25.156
2026-1 ...
show more
2026-10-11 03:32:31,341 fail2ban.actions [783]: NOTICE [apache-404] Ban 35.200.25.156
2026-10-11 03:32:31,342 fail2ban.actions [783]: NOTICE [apache-scan] Ban 35.200.25.156
2026-10-11 03:32:32,151 fail2ban.actions [783]: NOTICE [apache-dirscan] Ban 35.200.25.156
2026-10-11 03:32:32,450 fail2ban.actions [783]: NOTICE [apache-security] Ban 35.200.25.156
2026-10-11 03:32:33,063 fail2ban.actions [783]: NOTICE [web-scanner] Ban 35.200.25.156
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-11 00:24:07
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.200.25.156 (156.25.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.200.25.156 (156.25.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 20:24:00.899998 2026] [security2:error] [pid 25842:tid 25842] [client 35.200.25.156:60876] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gabver.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gabver.com"] [uri "/z9x8c7v6b5-debug-trigger-gabver.com"] [unique_id "asrXII3ja-lyGST5Ohql8AAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-11 00:17:00
(1 hour ago)
XSS Attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-11 00:04:37
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.200.25.156 (156.25.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.200.25.156 (156.25.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 20:04:29.909025 2026] [security2:error] [pid 18443:tid 18443] [client 35.200.25.156:39390] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||boatregistrationdelaware.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "boatregistrationdelaware.com"] [uri "/z9x8c7v6b5-debug-trigger-boatregistrationdelaware.com"] [unique_id "asrSjS7L12nmA8Twsc4EMQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-10 23:54:55
(1 hour ago)
[BestVouchers.net] Honeypot trap triggered | Path: /.env | Time: 2026-10-10T23:54:54.942Z | UA: Mozi ...
show more
[BestVouchers.net] Honeypot trap triggered | Path: /.env | Time: 2026-10-10T23:54:54.942Z | UA: Mozilla/5.0 (compatible; Meta-ExternalFetcher/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler) | Action: Automatically blocked for 24h and reported
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-10 23:47:27
(2 hours ago)
35.200.25.156 - - [11/Oct/2026:01:47:01 +0200] "GET HTTP/2.0" 403 272 "-" "Mozilla/5.0 (Linux; Andr ...
show more
35.200.25.156 - - [11/Oct/2026:01:47:01 +0200] "GET HTTP/2.0" 403 272 "-" "Mozilla/5.0 (Linux; Android 6.0.1; Nexus 5X Build/MMB29P) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Mobile Safari/537.36 (compatible; Googlebot/2.1; +http://www
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
๐ฉ๐ช
Hazzard
2026-10-10 23:31:34
(2 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted]): (CF_ENABLE)
Bad Web Bot
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-10 23:31:27
(2 hours ago)
2026/10/11 00:31:25 [error] 4060693#4060693: *1974708 access forbidden by rule, client: 35.200.25.15 ...
show more
2026/10/11 00:31:25 [error] 4060693#4060693: *1974708 access forbidden by rule, client: 35.200.25.156, server: bestasquadradas.org, request: "GET /api/data/..%2f..%2f.env HTTP/2.0", host: "bestasquadradas.org"
2026/10/11 00:31:25 [error] 4060693#4060693: *1974718 access forbidden by rule, client: 35.200.25.156, server: bestasquadradas.org, request: "GET /api/orders/..%2f..%2f.env HTTP/2.0", host: "bestasquadradas.org"
2026/10/11 00:31:25 [error] 4060697#4060697: *1974715 access forbidden by rule, client: 35.200.25.156, server: bestasquadradas.org, request: "GET /_nuxt/../.env HTTP/2.0", host: "bestasquadradas.org"
show less
Brute-Force
Web App Attack
Anonymous
2026-10-10 23:24:11
(2 hours ago)
Bot / seems abusive / Apache connections: 26
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack