๐บ๐ธ
TPI-Abuse
2026-09-24 09:28:33
(14 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.201.215.230 (230.215.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.215.230 (230.215.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 05:28:29.316492 2026] [security2:error] [pid 3927:tid 3935] [client 35.201.215.230:57894] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ep-dh.com|F|2"] [data ".ep-dh.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ep-dh.com"] [uri "/z9x8c7v6b5-debug-trigger-www.ep-dh.com"] [unique_id "arTtPe040VojfPXKyJAZ0wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-24 08:58:24
(44 minutes ago)
Web scanning / probing for vulnerable paths
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 08:36:34
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.201.215.230 (230.215.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.215.230 (230.215.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 04:36:26.854542 2026] [security2:error] [pid 25269:tid 25269] [client 35.201.215.230:36662] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.enselme.com|F|2"] [data ".enselme.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.enselme.com"] [uri "/z9x8c7v6b5-debug-trigger-www.enselme.com"] [unique_id "arThCibmDhoqXcBEAPcn2gAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yvoictra
2026-09-24 08:15:49
(1 hour ago)
Bloqueado automรกticamente por CrowdSec. Escenario: crowdsecurity/http-sensitive-files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 07:57:13
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.201.215.230 (230.215.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.215.230 (230.215.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:57:09.422458 2026] [security2:error] [pid 31122:tid 31122] [client 35.201.215.230:37958] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.engelhardtkraatz.com"] [uri "/.htpasswd"] [unique_id "arTX1WALrG_PYfAwK9IpXQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 06:10:20
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.201.215.230 (230.215.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.215.230 (230.215.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 02:10:17.646581 2026] [security2:error] [pid 5064:tid 5064] [client 35.201.215.230:38280] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.emmtrucking.com|F|2"] [data ".emmtrucking.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.emmtrucking.com"] [uri "/z9x8c7v6b5-debug-trigger-www.emmtrucking.com"] [unique_id "arS-yU-WuLOHo04TOsPNcAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 05:13:23
(4 hours ago)
35.201.215.230 - - [24/Sep/2026:00:13:22 -0500] "GET /index.php?s=index/\\think\\app/invokefunction& ...
show more
35.201.215.230 - - [24/Sep/2026:00:13:22 -0500] "GET /index.php?s=index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=file_get_contents&vars[1][]=/proc/self/environ HTTP/2.0" 403 17006 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
35.201.215.230 - - [24/Sep/2026:00:13:22 -0500] "GET /index.php?s=index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]=env HTTP/2.0" 200 105779 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
35.201.215.230 - - [24/Sep/2026:00:13:22 -0500] "GET /index.php?s=index/\\think\\app/invokefunction&function=call_user_func_array&vars[0]=file_get_contents&vars[1][]=.env HTTP/2.0" 200 105779 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
creoline GmbH
2026-09-24 03:50:23
(5 hours ago)
[WAF] Multiple suspicious HTTP requests has been blocked
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 03:34:52
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.201.215.230 (230.215.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.215.230 (230.215.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 23:34:46.809576 2026] [security2:error] [pid 9048:tid 9174] [client 35.201.215.230:41608] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.energy.brucejoell.com|F|2"] [data ".energy.brucejoell.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.energy.brucejoell.com"] [uri "/z9x8c7v6b5-debug-trigger-www.energy.brucejoell.com"] [unique_id "arSaVr-G0BOJ-wXblJdobwAAAhE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 03:01:06
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.201.215.230 (230.215.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.215.230 (230.215.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 23:01:00.637792 2026] [security2:error] [pid 7668:tid 7668] [client 35.201.215.230:34614] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ev.alitcogroup.com|F|2"] [data ".ev.alitcogroup.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ev.alitcogroup.com"] [uri "/z9x8c7v6b5-debug-trigger-www.ev.alitcogroup.com"] [unique_id "arSSbNbg-JKi0p7VANOLLQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-09-24 02:48:19
(6 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /asset-manifest.json (HTTP/2.0 port ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /asset-manifest.json (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36")
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 02:21:12
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.215.230 (230.215.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.215.230 (230.215.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 22:21:08.014626 2026] [security2:error] [pid 30072:tid 30072] [client 35.201.215.230:34600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brittb.com"] [uri "/laravel/.env"] [unique_id "arSJFINNN8NsDmeAueDNIwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-09-24 01:27:01
(8 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "applebot" at REQUEST_HEADERS:user-agent. (1100000-1 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "applebot" at REQUEST_HEADERS:user-agent. (1100000-122)
show less
Bad Web Bot
๐ซ๐ท
ELYAZ
2026-09-24 01:23:40
(8 hours ago)
(y3) Failed access -byebye- from 35.201.215.230 (TW/Taiwan/230.215.201.35.bc.googleusercontent.com): ...
show more
(y3) Failed access -byebye- from 35.201.215.230 (TW/Taiwan/230.215.201.35.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
๐ฌ๐ง
andypiper
2026-09-24 01:03:13
(8 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack