๐บ๐ธ
TPI-Abuse
2026-10-02 14:41:28
(57 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.201.228.149 (149.228.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.228.149 (149.228.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 10:41:21.543572 2026] [security2:error] [pid 19757:tid 19757] [client 35.201.228.149:51510] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||braintechsoftwaresolutions.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "braintechsoftwaresolutions.com"] [uri "/z9x8c7v6b5-debug-trigger-braintechsoftwaresolutions.com"] [unique_id "ar_CkRhZXZn-sMyKr0v7GwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
[email protected]
2026-10-02 14:25:18
(1 hour ago)
CrowdSec ban: crowdsecurity/http-crawl-non_statics (duration: 71h59m58s)
Web App Attack
๐ฉ๐ช
TheDjRider
2026-10-02 14:20:49
(1 hour ago)
CrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-bad-user-agent. ...
show more
CrowdSec detected Malicious web crawler or bad web bot. Scenario: crowdsecurity/http-bad-user-agent. Automatic ban triggered. Detection time (UTC): 2026-10-02T14:20:47.516515469Z. Context: http_status=503, http_status=200
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 12:26:54
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.201.228.149 (149.228.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.228.149 (149.228.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:26:49.615534 2026] [security2:error] [pid 8284:tid 8284] [client 35.201.228.149:54868] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||broadcastit.gulftelecom.com|F|2"] [data ".gulftelecom.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "broadcastit.gulftelecom.com"] [uri "/z9x8c7v6b5-debug-trigger-broadcastit.gulftelecom.com"] [unique_id "ar-jCcJNTuqZCGFBwWnYaAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 12:10:21
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.201.228.149 (149.228.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.228.149 (149.228.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:10:14.019328 2026] [security2:error] [pid 5787:tid 5787] [client 35.201.228.149:52778] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||brinkworthdungeon.brinkworthmodels.com|F|2"] [data ".brinkworthmodels.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "brinkworthdungeon.brinkworthmodels.com"] [uri "/z9x8c7v6b5-debug-trigger-brinkworthdungeon.brinkworthmodels.com"] [unique_id "ar-fJtnkMiWVrynSbElRewAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-10-02 11:14:23
(4 hours ago)
[02/Oct/2026:13:14:21 +0200] 179093966142.360822 35.201.228.149 42556 217.154.7.177 443
[02/Oct/2026 ...
show more
[02/Oct/2026:13:14:21 +0200] 179093966142.360822 35.201.228.149 42556 217.154.7.177 443
[02/Oct/2026:13:14:22 +0200] 17909396625.911395 35.201.228.149 42556 217.154.7.177 443
[02/Oct/2026:13:14:22 +0200] 179093966290.752791 35.201.228.149 42556 217.154.7.177 443
[02/Oct/2026:13:14:22 +0200] 179093966274.791778 35.201.228.149 42556 217.154.7.177 443
[02/Oct/2026:13:14:22 +0200] 179093966246.552137 35.201.228.149 42556 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
zUnlegit
2026-10-02 11:12:22
(4 hours ago)
Automated web scanner requested sensitive path: /config/env/aws_credentials.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 11:10:42
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.228.149 (149.228.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.228.149 (149.228.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:10:38.707597 2026] [security2:error] [pid 29721:tid 29721] [client 35.201.228.149:33242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.jbaydeliveries.com"] [uri "/core/.env"] [unique_id "ar-RLrJFYd9Olll9bc5acgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 10:55:34
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.201.228.149 (149.228.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.228.149 (149.228.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 06:55:28.336341 2026] [security2:error] [pid 9155:tid 9155] [client 35.201.228.149:59846] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jen-eric.com|F|2"] [data ".jen-eric.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jen-eric.com"] [uri "/z9x8c7v6b5-debug-trigger-www.jen-eric.com"] [unique_id "ar-NoGq0gcxbfg6QnB1urAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
CDO
2026-10-02 10:41:08
(4 hours ago)
URL Injection attempt detected. Automated web attack.
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-10-02 10:32:55
(5 hours ago)
git/env leak probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 10:31:04
(5 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.228.149 (149.228.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.228.149 (149.228.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 06:30:59.482996 2026] [security2:error] [pid 25976:tid 25976] [client 35.201.228.149:36936] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.braddonengineering.com"] [uri "/.env.development"] [unique_id "ar-H46OrAF-YZ3Je-Q51lAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 08:08:23
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.201.228.149 (149.228.201.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.201.228.149 (149.228.201.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 04:08:18.930945 2026] [security2:error] [pid 29328:tid 29390] [client 35.201.228.149:53456] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.btoelsalvador.com"] [uri "/dist/.env"] [unique_id "ar9mcgQUUE5FbfA2oBqmrQAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
TheDjRider
2026-10-02 07:48:04
(7 hours ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-10-02T07:48:01.562259906Z. Context: http_status=200
show less
Web App Attack
๐ฌ๐ง
Apache
2026-10-02 07:45:47
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.201.228.149 (TW/Taiwan/149.228.201.35.bc.goo ...
show more
(mod_security) mod_security (id:210730) triggered by 35.201.228.149 (TW/Taiwan/149.228.201.35.bc.googleusercontent.com): 5 in the last 300 secs
show less
Brute-Force
Web App Attack