๐ธ๐ช
vaia.cloud
2026-09-24 15:05:02
(14 minutes ago)
crowdsecurity/http-cve-2021-41773
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 11:51:06
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.205.150.184 (184.150.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.205.150.184 (184.150.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 07:51:02.570969 2026] [security2:error] [pid 8886:tid 8886] [client 35.205.150.184:52172] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kozyramodularhomebuilder.com|F|2"] [data ".kozyramodularhomebuilder.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kozyramodularhomebuilder.com"] [uri "/z9x8c7v6b5-debug-trigger-www.kozyramodularhomebuilder.com"] [unique_id "arUOpjV3j2WQN-mEPQIWdwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-24 11:27:06
(3 hours ago)
69 attempts against mh-misbehave-ban on bean
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
kosada.com
2026-09-24 11:21:41
(3 hours ago)
Repeated exploit attempts, for example: /.env.old /.env (HTTP/1.1 port 443, user agent: "Mozilla/5.0 ...
show more
Repeated exploit attempts, for example: /.env.old /.env (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)")
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 10:43:43
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.205.150.184 (184.150.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.205.150.184 (184.150.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 06:43:38.115626 2026] [security2:error] [pid 3249:tid 3249] [client 35.205.150.184:44776] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kontikimotorcycles.com|F|2"] [data ".kontikimotorcycles.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kontikimotorcycles.com"] [uri "/z9x8c7v6b5-debug-trigger-www.kontikimotorcycles.com"] [unique_id "arT-2pFdyqGY20T9LxBGRQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-24 09:40:31
(5 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐น๐ท
ycoskun41
2026-09-24 09:25:46
(5 hours ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 07:46:47
(7 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.205.150.184 (184.150.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.150.184 (184.150.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:46:43.806955 2026] [security2:error] [pid 11596:tid 11596] [client 35.205.150.184:35966] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arsenaultartistmanagement.com"] [uri "/.env.prod"] [unique_id "arTVY-Myj5jpCOMWaXT89gAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 07:28:38
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.205.150.184 (184.150.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.205.150.184 (184.150.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:28:31.516229 2026] [security2:error] [pid 1431:tid 1431] [client 35.205.150.184:41868] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||daveslawncare.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "daveslawncare.com"] [uri "/z9x8c7v6b5-debug-trigger-daveslawncare.com"] [unique_id "arTRH0-DhNm867iTmhETZAAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
demomodule
2026-09-24 07:27:51
(7 hours ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-24 07:18:17
(8 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ง๐ช
taivas.nl
2026-09-24 07:02:14
(8 hours ago)
Bad_requests
Bad Web Bot
๐บ๐ธ
helios.live
2026-09-24 06:50:51
(8 hours ago)
2026/09/24 06:50:48 [error] 2119495#2119495: *4567226 access forbidden by rule, client: 35.205.150.1 ...
show more
2026/09/24 06:50:48 [error] 2119495#2119495: *4567226 access forbidden by rule, client: 35.205.150.184, server: kocervpn.com, request: "GET /dist/.vite/manifest.json HTTP/1.1", host: "kocervpn.com"
2026/09/24 06:50:48 [error] 2119495#2119495: *4567416 access forbidden by rule, client: 35.205.150.184, server: kocervpn.com, request: "GET /.vite/manifest.json HTTP/1.1", host: "kocervpn.com"
2026/09/24 06:50:49 [error] 2119495#2119495: *4567416 access forbidden by rule, client: 35.205.150.184, server: kocerroxy.com, request: "GET /dist/.vite/manifest.json HTTP/1.1", host: "kocerroxy.com"
2026/09/24 06:50:49 [error] 2119495#2119495: *4567226 access forbidden by rule, client: 35.205.150.184, server: kocerroxy.com, request: "GET /.vite/manifest.json HTTP/1.1", host: "kocerroxy.com"
2026/09/24 06:50:51 [error] 2119495#2119495: *4567493 access forbidden by rule, client: 35.205.150.184, server: kocervpn.com, request: "GET /admin%2F.env HTTP/1.1", host: "kocervpn.com"
...
show less
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-24 06:00:03
(9 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-24 05:40:05
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.205.150.184 (184.150.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.205.150.184 (184.150.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 01:39:54.424039 2026] [security2:error] [pid 3369:tid 3369] [client 35.205.150.184:52474] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kooroshvaziri.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kooroshvaziri.com"] [uri "/z9x8c7v6b5-debug-trigger-kooroshvaziri.com"] [unique_id "arS3qmfIJHLj11ELLeVDbQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack