๐บ๐ธ
TPI-Abuse
2026-09-23 22:08:42
(5 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.200.9.106 (106.9.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.200.9.106 (106.9.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 18:08:37.987985 2026] [security2:error] [pid 31266:tid 31321] [client 35.200.9.106:53222] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||clinicadelparabrisas.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "clinicadelparabrisas.com"] [uri "/z9x8c7v6b5-debug-trigger-clinicadelparabrisas.com"] [unique_id "arRN5XaCmG89wi3u14gEvAAAAQU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 21:48:27
(25 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.200.9.106 (106.9.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.200.9.106 (106.9.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:48:19.629944 2026] [security2:error] [pid 29988:tid 29988] [client 35.200.9.106:60414] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cloggersunlimited.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cloggersunlimited.com"] [uri "/z9x8c7v6b5-debug-trigger-cloggersunlimited.com"] [unique_id "arRJI850paSmGbzq2vjpCAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
netclix.gr
2026-09-23 21:33:41
(40 minutes ago)
(mod_security) mod_security triggered on hostname [redacted] 35.200.9.106 (JP/Japan/106.9.200.35.bc. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.200.9.106 (JP/Japan/106.9.200.35.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐บ๐ธ
nationaleventpros.com
2026-09-23 21:26:22
(47 minutes ago)
vulnerability scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 21:07:22
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.200.9.106 (106.9.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.200.9.106 (106.9.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:07:14.868059 2026] [security2:error] [pid 15408:tid 15408] [client 35.200.9.106:39500] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||clustershow.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "clustershow.com"] [uri "/z9x8c7v6b5-debug-trigger-clustershow.com"] [unique_id "arQ_gsbMNDzD6-pM9iWfpwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jormaster3k
2026-09-23 21:03:24
(1 hour ago)
Attack against Apache (too many 404s)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 20:51:19
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.200.9.106 (106.9.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.200.9.106 (106.9.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 16:51:11.868449 2026] [security2:error] [pid 1560:tid 1560] [client 35.200.9.106:42506] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cmyk-intl.com"] [uri "/.env.production"] [unique_id "arQ7v-ANe6H3aIG-bn2gEQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
interbiznw.com
2026-09-23 20:10:21
(2 hours ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-23 19:46:46
(2 hours ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.200.9.106 - - [23/Sep/2026:21:46:45 +0200] "GET /@fs/app/.env?raw?? HTTP/2.0" 404 36541 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 19:14:26
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.200.9.106 (106.9.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.200.9.106 (106.9.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 15:14:22.825380 2026] [security2:error] [pid 7189:tid 7189] [client 35.200.9.106:48458] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||coinbracelet.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "coinbracelet.com"] [uri "/z9x8c7v6b5-debug-trigger-coinbracelet.com"] [unique_id "arQlDpsumAPJcr689TpeRgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
rsa
2026-09-23 18:44:00
(3 hours ago)
GET /openapi.json HTTP/1.1
DDoS Attack
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:41:31
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.200.9.106 (106.9.200.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.200.9.106 (106.9.200.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:41:25.415302 2026] [security2:error] [pid 2855849:tid 2855849] [client 35.200.9.106:53464] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||collectorcarconsultants.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "collectorcarconsultants.com"] [uri "/z9x8c7v6b5-debug-trigger-collectorcarconsultants.com"] [unique_id "arQdVb3GVEHGZGkQk2z_wAAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-23 18:34:06
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-23 18:28:13
(3 hours ago)
Banned by Fail2Ban on server
Web App Attack
๐ซ๐ท
COMAITE
2026-09-23 18:06:50
(4 hours ago)
Common web attack from 35.200.9.106.
Web App Attack