๐ฌ๐ง
poundawebsiteltd
2026-09-20 14:47:50
(3 days ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.201.138 ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.201.138.127 (TW/Taiwan/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 35.201.138.127 (TW/Taiwan/127.138.201.35.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:47:18
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.201.138.127 (127.138.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.138.127 (127.138.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:47:11.607222 2026] [security2:error] [pid 18127:tid 18127] [client 35.201.138.127:60288] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "postermodelsworldwideinc.com"] [uri "/.env"] [unique_id "aq_x72BKRA5k9XtmKp9hHgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
oja
2026-09-20 14:35:39
(3 days ago)
Aggressive web scanner
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:11:27
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.201.138.127 (127.138.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.138.127 (127.138.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:11:23.696141 2026] [security2:error] [pid 10095:tid 10107] [client 35.201.138.127:36166] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mailporte.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mailporte.com"] [uri "/z9x8c7v6b5-debug-trigger-mailporte.com"] [unique_id "aq_pi3FmCuI-OtmwC46VhwAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-09-20 13:51:12
(3 days ago)
[20/Sep/2026:15:51:11 +0200] 178991227167.377121 35.201.138.127 50830 217.154.7.177 443
[20/Sep/2026 ...
show more
[20/Sep/2026:15:51:11 +0200] 178991227167.377121 35.201.138.127 50830 217.154.7.177 443
[20/Sep/2026:15:51:11 +0200] 178991227194.982405 35.201.138.127 50182 217.154.7.177 443
[20/Sep/2026:15:51:11 +0200] 17899122712.087764 35.201.138.127 50182 217.154.7.177 443
[20/Sep/2026:15:51:11 +0200] 178991227193.633183 35.201.138.127 50182 217.154.7.177 443
[20/Sep/2026:15:51:11 +0200] 178991227167.616006 35.201.138.127 50182 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
interbiznw.com
2026-09-20 13:49:57
(3 days ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:41:26
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.201.138.127 (127.138.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.138.127 (127.138.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:41:22.195362 2026] [security2:error] [pid 6297:tid 6297] [client 35.201.138.127:45646] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hi-modulus.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hi-modulus.com"] [uri "/z9x8c7v6b5-debug-trigger-hi-modulus.com"] [unique_id "aq_igunDMFeyQBvXCQ-d7QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-20 13:30:06
(3 days ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
๐ณ๐ฑ
svr
2026-09-20 13:27:05
(3 days ago)
Abusive Automated Web Scanner
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:25:40
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.201.138.127 (127.138.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.138.127 (127.138.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:25:32.468533 2026] [security2:error] [pid 27058:tid 27058] [client 35.201.138.127:56926] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||galaxyretro.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "galaxyretro.com"] [uri "/z9x8c7v6b5-debug-trigger-galaxyretro.com"] [unique_id "aq_ezFX-dcz0NUXRBqLnHwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
TheDjRider
2026-09-20 13:11:15
(3 days ago)
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ba ...
show more
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ban triggered. Detection time (UTC): 2026-09-20T13:11:02.171683074Z. Context: http_status=403, http_status=404
show less
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 13:05:04
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ซ๐ท
dynamix
2026-09-20 13:04:49
(3 days ago)
Multiple WAF Violations
Web App Attack
๐จ๐ฆ
polycoda
2026-09-20 12:47:13
(3 days ago)
AutoBlock: ๐ก Port Scan (Non Decay-Based)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-20 12:41:15
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.201.138.127 (127.138.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.138.127 (127.138.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 08:41:07.314813 2026] [security2:error] [pid 17522:tid 17522] [client 35.201.138.127:60564] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||computersraleigh.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "computersraleigh.com"] [uri "/rclone.conf"] [unique_id "aq_UY1_I-FWZBhdSimJvzQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack