๐ฒ๐ฝ
octageeks.com
2026-09-23 04:08:41
(5 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
wbsouza
2026-09-23 03:24:19
(5 days ago)
CrowdSec: infra/appsec-challenge-requested-log โ automated firewall drops on self-hosted IDS sensor
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 17:24:51
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.201.175.192 (192.175.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.175.192 (192.175.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:24:46.965762 2026] [security2:error] [pid 6793:tid 6793] [client 35.201.175.192:36034] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rosecityexpress.soviaenterprises.com|F|2"] [data ".soviaenterprises.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rosecityexpress.soviaenterprises.com"] [uri "/z9x8c7v6b5-debug-trigger-rosecityexpress.soviaenterprises.com"] [unique_id "arK53jXxeyYCJ7IhOl-u8gAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:08:42
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.201.175.192 (192.175.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.175.192 (192.175.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:08:38.326797 2026] [security2:error] [pid 11364:tid 11364] [client 35.201.175.192:38894] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rota.oxfordgliding.com|F|2"] [data ".oxfordgliding.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rota.oxfordgliding.com"] [uri "/z9x8c7v6b5-debug-trigger-rota.oxfordgliding.com"] [unique_id "arK2Fl0JCA5OUMMUu43uvAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Epimetheus
2026-09-22 16:58:34
(5 days ago)
Zombie network / Bot scanner detected:
[POST] /api/templates/preview
[GET] /.ssh/config
[GET] /hori ...
show more
Zombie network / Bot scanner detected:
[POST] /api/templates/preview
[GET] /.ssh/config
[GET] /horizon/api/stats
[GET] /.streamlit/secrets.toml
[POST] /read-document
[GET] /_ignition/health-check
[GET] /_profiler/latest
[GET] /server-status
[GET] /.env.save
[GET] /.env
[GET] /graphql/console
[GET] /gcp-credentials.json
[GET] /_ignition/health-check
[GET] /dist/.env
[GET] /@fs/var/run/secrets/kubernetes.io/serviceaccount/token
[GET] /__env.js
[GET] /document.php
[GET] /__debugger__
[GET] /app/settings.py
[GET] /workspace/.env
[GET] /ml/.env
[GET] /api/auth/session
[GET] /v1/.env
[GET] /redoc
UA: Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)
show less
Bad Web Bot
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:40:20
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.201.175.192 (192.175.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.175.192 (192.175.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:40:16.104841 2026] [security2:error] [pid 20843:tid 20843] [client 35.201.175.192:38728] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||royalhay.gulftelecom.com|F|2"] [data ".gulftelecom.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "royalhay.gulftelecom.com"] [uri "/z9x8c7v6b5-debug-trigger-royalhay.gulftelecom.com"] [unique_id "arKvcKTCYksPNV-MLEZxmgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:01:58
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.201.175.192 (192.175.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.175.192 (192.175.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:01:54.490262 2026] [security2:error] [pid 8482:tid 8482] [client 35.201.175.192:57020] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.roumer.com|F|2"] [data ".roumer.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.roumer.com"] [uri "/z9x8c7v6b5-debug-trigger-www.roumer.com"] [unique_id "arJ8QuYv5jeF4NtD_cAv4gAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Epimetheus
2026-09-22 11:50:33
(6 days ago)
Zombie network / Bot scanner detected:
[POST] /api/templates/preview
[POST] /icecoder/lib/terminal- ...
show more
Zombie network / Bot scanner detected:
[POST] /api/templates/preview
[POST] /icecoder/lib/terminal-xhr.php
[POST] /api/templates/preview
[POST] /lib/terminal-xhr.php
[POST] /mcp
[DELETE] /api/inngest
[GET] /_nuxt/../.env
[GET] /data/.env
[GET] /bot/.env
[GET] /_image
[GET] /webpack-stats.json
[GET] /core/settings.py
[GET] /user/login
[GET] /register
[GET] /reset-password
[GET] /config.py
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)
show less
Bad Web Bot
Exploited Host
Web App Attack
๐ซ๐ท
dynamix
2026-09-22 11:35:07
(6 days ago)
Multiple WAF Violations
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-09-22 11:30:03
(6 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:26:33
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.201.175.192 (192.175.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.175.192 (192.175.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:26:30.138257 2026] [security2:error] [pid 2480:tid 2480] [client 35.201.175.192:44824] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||deubellzebub.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "deubellzebub.com"] [uri "/z9x8c7v6b5-debug-trigger-deubellzebub.com"] [unique_id "arJl5j5B22Og4MYLg1ptwgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:00:42
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.201.175.192 (192.175.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.175.192 (192.175.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:00:36.746197 2026] [security2:error] [pid 8818:tid 8818] [client 35.201.175.192:51418] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||midwayisland.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "midwayisland.com"] [uri "/z9x8c7v6b5-debug-trigger-midwayisland.com"] [unique_id "arJf1DCJIHzJs7SppTlpmQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 10:10:12
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.201.175.192 (192.175.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.175.192 (192.175.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:10:04.674111 2026] [security2:error] [pid 9027:tid 9027] [client 35.201.175.192:56834] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rohn.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rohn.com"] [uri "/z9x8c7v6b5-debug-trigger-rohn.com"] [unique_id "arJT_CT63HIqNFsKHk4NnwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-22 10:08:07
(6 days ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-22 09:43:32
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.201.175.192 (192.175.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.175.192 (192.175.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 05:43:24.641039 2026] [security2:error] [pid 3960:tid 3960] [client 35.201.175.192:55886] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rosawallas.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rosawallas.com"] [uri "/z9x8c7v6b5-debug-trigger-rosawallas.com"] [unique_id "arJNvDdLMrpOWRsmYEqnxgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack