๐ณ๐ฑ
Site.eu
2026-10-05 02:25:49
(21 minutes ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-05 01:41:59
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.203.127.97 (97.127.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.203.127.97 (97.127.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 21:41:54.781290 2026] [security2:error] [pid 5136:tid 5136] [client 35.203.127.97:49942] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||butterflygolem.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "butterflygolem.com"] [uri "/z9x8c7v6b5-debug-trigger-butterflygolem.com"] [unique_id "asMAYv_iXnADkboxJMjDdwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
โจ
2026-10-05 01:00:12
(1 hour ago)
Domain : redirect.netenergy.uk
Rule : env
2026-10-05 00:58:55 217.194.210.152 GET /.env - 443 - 35.2 ...
show more
Domain : redirect.netenergy.uk
Rule : env
2026-10-05 00:58:55 217.194.210.152 GET /.env - 443 - 35.203.127.97 HTTP/2 CCBot/2.0 (https://commoncrawl.org/faq/) - businessmoneycheckup.com 404 19 0 1455 425 78 - -
show less
Hacking
SQL Injection
๐บ๐ธ
IndigoRidge
2026-10-05 00:25:18
(2 hours ago)
35.203.127.97 - - [04/Oct/2026:20:25:17 -0400] "GET /static../.env HTTP/1.1" 404 5741 "https://bushr ...
show more
35.203.127.97 - - [04/Oct/2026:20:25:17 -0400] "GET /static../.env HTTP/1.1" 404 5741 "https://bushriverrealty.com/static../.env" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
35.203.127.97 - - [04/Oct/2026:20:25:17 -0400] "GET /media../.env HTTP/1.1" 404 5741 "https://bushriverrealty.com/media../.env" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
35.203.127.97 - - [04/Oct/2026:20:25:17 -0400] "GET /api/.env/public/.env HTTP/1.1" 404 5741 "https://bushriverrealty.com/api/.env/public/.env" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
...
show less
Web App Attack
๐ซ๐ท
masterguru
2026-10-05 00:19:35
(2 hours ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
Anonymous
2026-10-05 00:09:30
(2 hours ago)
35.203.127.97 - - [05/Oct/2026:02:09:19 +0200] "GET /.npmrc HTTP/2.0" 403 272 "-" "Mozilla/5.0 (comp ...
show more
35.203.127.97 - - [05/Oct/2026:02:09:19 +0200] "GET /.npmrc HTTP/2.0" 403 272 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-10-05 00:08:00
(2 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 23:51:51
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.203.127.97 (97.127.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.203.127.97 (97.127.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 19:51:47.089242 2026] [security2:error] [pid 10681:tid 10681] [client 35.203.127.97:41132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "burnbuns.com"] [uri "/.htpasswd"] [unique_id "asLmk7mtOA4dIVIIRBIJMgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-04 23:36:19
(3 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
dbmwebdesign
2026-10-04 23:35:18
(3 hours ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐ซ๐ท
masterguru
2026-10-04 23:33:30
(3 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "ccbot" at REQUEST_HEADERS:User-Agent. (1100000-196)
Bad Web Bot
๐จ๐ฆ
polycoda
2026-10-04 23:30:46
(3 hours ago)
AutoBlock: ๐ก Port Scan (Non Decay-Based) - โ Excessive 40X Errors (Decay-Based)
Port Scan
Bad Web Bot
๐ง๐ช
cmbplf
2026-10-04 23:26:36
(3 hours ago)
703 requests with url.path */@fs/*
288 requests with url.path */proc/*
196 requests with url.path ...
show more
703 requests with url.path */@fs/*
288 requests with url.path */proc/*
196 requests with url.path *config.json
107 requests with url.path *.ssh/*
show less
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-04 23:26:18
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.203.127.97 (97.127.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.203.127.97 (97.127.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 19:26:14.695683 2026] [security2:error] [pid 19728:tid 19728] [client 35.203.127.97:54292] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||burdetteconsulting.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "burdetteconsulting.com"] [uri "/z9x8c7v6b5-debug-trigger-burdetteconsulting.com"] [unique_id "asLglt5XCJyGXFklqemEvAAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
23p02732
2026-10-04 22:58:49
(3 hours ago)
Automated web scanning and malicious probing
Brute-Force
Bad Web Bot
Web App Attack