๐ณ๐ฑ
Savvii
2026-10-10 20:20:29
(21 minutes ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 20:10:17
(32 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.204.150.22 (22.150.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.204.150.22 (22.150.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 16:10:10.720193 2026] [security2:error] [pid 25450:tid 25450] [client 35.204.150.22:45256] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||krugmans.org|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "krugmans.org"] [uri "/rclone.conf"] [unique_id "asqbooBpT93SoT-cefdRrQAAAE8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-10-10 20:10:13
(32 minutes ago)
Try to access /backend/.env
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-10-10 19:58:54
(43 minutes ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-10-10 19:58:21
(44 minutes ago)
(modsec_attack) srv101 ModSecurity attack 35.204.150.22 (NL/The Netherlands/22.150.204.35.bc.googleu ...
show more
(modsec_attack) srv101 ModSecurity attack 35.204.150.22 (NL/The Netherlands/22.150.204.35.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐จ๐ฆ
Mediashaker
2026-10-10 19:53:27
(49 minutes ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.204.150.22 (22.15 ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.204.150.22 (22.150.204.35.bc.googleusercontent.com)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-10 19:51:10
(51 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.204.150.22 (22.150.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.204.150.22 (22.150.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 15:51:05.261605 2026] [security2:error] [pid 18645:tid 18645] [client 35.204.150.22:60368] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kristinmoore.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kristinmoore.com"] [uri "/z9x8c7v6b5-debug-trigger-kristinmoore.com"] [unique_id "asqXKd9aCqloQpczyUNBOgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-10-10 19:37:12
(1 hour ago)
2026-10-10 21:35:12 AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/enviro ...
show more
2026-10-10 21:35:12 AH10244: invalid URI path (/icons/.%2e/.%2e/.%2e/.%2e/.%2e/.%2e/proc/self/environ) && 2026-10-10 21:35:12 AH10244: invalid URI path (/%2e%2e/.env) && 2026-10-10 21:35:12 AH10244: invalid URI path (/appearance/../../.env) && 195 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-10 19:31:03
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.204.150.22 (22.150.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.204.150.22 (22.150.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 15:30:57.260760 2026] [security2:error] [pid 22225:tid 22225] [client 35.204.150.22:49880] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kreweofhyatt.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kreweofhyatt.com"] [uri "/z9x8c7v6b5-debug-trigger-kreweofhyatt.com"] [unique_id "asqScbB1drBH9bqKBguUJAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2026-10-10 19:29:46
(1 hour ago)
(apache-scanners) Failed apache-scanners trigger with match [redacted])
Port Scan
๐ฉ๐ช
FeG Deutschland
2026-10-10 19:16:04
(1 hour ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1248
Exploited Host
Web App Attack
๐ง๐ช
cmbplf
2026-10-10 19:07:57
(1 hour ago)
27.817 requests in 1 hour (1w6d23h)
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-10-10 19:07:15
(1 hour ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.204.150.22 - - [10/Oct/2026:21:06:54 +0200] "GET /.git/HEAD HTTP/2.0" 301 323 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
maxxsense
2026-10-10 19:06:35
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 35.204.150.22 (22.150.204.35.bc.googleu ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.204.150.22 (22.150.204.35.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-10 19:01:55
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.204.150.22 (22.150.204.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.204.150.22 (22.150.204.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 10 15:01:51.315285 2026] [security2:error] [pid 22736:tid 22736] [client 35.204.150.22:44412] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "krakowski.org"] [uri "/@fs/proc/self/cwd/.env"] [unique_id "asqLnyVznPpwaCuA1gQYqwAAAEs"]
show less
Brute-Force
Bad Web Bot
Web App Attack