Anonymous
2026-09-30 19:00:06
(5 days ago)
Multiple pen test attempts.
Web App Attack
๐น๐ญ
thaizone.com
2026-09-30 17:30:13
(5 days ago)
Brute Force Attack on a Web Resources #1
DDoS Attack
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
NXTwoThou
2026-09-30 13:32:17
(5 days ago)
/graphql
Web App Attack
๐น๐ญ
thaizone.com
2026-09-30 13:27:21
(5 days ago)
Brute Force Attack on a Web Resources (repeated 404) #1
DDoS Attack
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:20:57
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.200.64.130 (130.64.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.200.64.130 (130.64.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:20:51.444602 2026] [security2:error] [pid 8211:tid 8211] [client 35.200.64.130:34074] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||windsorpalms.iainrealtor.com|F|2"] [data ".iainrealtor.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "windsorpalms.iainrealtor.com"] [uri "/z9x8c7v6b5-debug-trigger-windsorpalms.iainrealtor.com"] [unique_id "arz-ozNLZbm-iWjVydtsUwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 12:03:00
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.200.64.130 (130.64.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.200.64.130 (130.64.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 08:02:51.858043 2026] [security2:error] [pid 8892:tid 8892] [client 35.200.64.130:53380] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||test.artfranz.com|F|2"] [data ".artfranz.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "test.artfranz.com"] [uri "/z9x8c7v6b5-debug-trigger-test.artfranz.com"] [unique_id "arz6axdTvFkw20TOibS4JwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-30 11:36:05
(5 days ago)
excessive HTTP 404 errors
Bad Web Bot
Anonymous
2026-09-30 11:31:33
(5 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-30 11:27:38
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.200.64.130 (130.64.200.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.200.64.130 (130.64.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 07:27:30.942986 2026] [security2:error] [pid 25465:tid 25465] [client 35.200.64.130:49076] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||albionglobalmarketing.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "albionglobalmarketing.com"] [uri "/z9x8c7v6b5-debug-trigger-albionglobalmarketing.com"] [unique_id "arzyIolRADIpNRv4eFQ8BAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-30 11:19:06
(5 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
konseptit
2026-09-30 11:08:44
(5 days ago)
(mod_security) mod_security triggered on hostname [redacted] 35.200.64.130 (JP/Japan/130.64.200.35.b ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.200.64.130 (JP/Japan/130.64.200.35.bc.googleusercontent.com)
show less
SQL Injection
๐ณ๐ฑ
Alt255
2026-09-30 11:06:00
(5 days ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.200.64.130 - - [30/Sep/2026:13:05:45 +0200] "GET /.ssh/id_ed25519 HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
XICTRON
2026-09-30 11:00:09
(5 days ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐ฉ๐ช
rh24
2026-09-30 10:57:14
(5 days ago)
(badbots) Bad bot user-agent [redacted] from 35.200.64.130 (JP/Japan/130.64.200.35.bc.googleusercont ...
show more
(badbots) Bad bot user-agent [redacted] from 35.200.64.130 (JP/Japan/130.64.200.35.bc.googleusercontent.com)
show less
Hacking
๐ซ๐ท
dynamix
2026-09-30 10:07:19
(5 days ago)
Multiple WAF Violations
Web App Attack