๐ฒ๐ฝ
octageeks.com
2026-09-22 04:22:35
(2 weeks ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-22 03:06:20
(2 weeks ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-22 01:42:42
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 35.205.241.148 (148.241.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.205.241.148 (148.241.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:42:35.233124 2026] [security2:error] [pid 3154:tid 3154] [client 35.205.241.148:50450] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||picayunity.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "picayunity.com"] [uri "/z9x8c7v6b5-debug-trigger-picayunity.com"] [unique_id "arHdCzyjp2eChWnSdwbqhwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
antlac1
2026-09-21 23:12:41
(2 weeks ago)
crowdsecurity/http-path-traversal-probing
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 20:31:38
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.205.241.148 (148.241.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.241.148 (148.241.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 16:31:30.910526 2026] [security2:error] [pid 24021:tid 24021] [client 35.205.241.148:46770] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.goatedlottosecrets.com"] [uri "/scripts/.env"] [unique_id "arGUIucHQFPPTqK0HEpMbwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 19:03:09
(2 weeks ago)
Multiple pen test attempts.
Web App Attack
Anonymous
2026-09-21 18:54:57
(2 weeks ago)
Aggressive web scan
Web App Attack
๐ฆ๐บ
aranguren.org
2026-09-21 16:46:27
(2 weeks ago)
35.205.241.148 - - [22/Sep/2026:02:46:26 +1000] "GET /api/.env HTTP/2.0" 404 994 "-" "Mozilla/5.0 (c ...
show more
35.205.241.148 - - [22/Sep/2026:02:46:26 +1000] "GET /api/.env HTTP/2.0" 404 994 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
35.205.241.148 - - [22/Sep/2026:02:46:26 +1000] "GET /api/v1/.env HTTP/2.0" 404 994 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
35.205.241.148 - - [22/Sep/2026:02:46:26 +1000] "GET /project/.env HTTP/2.0" 404 994 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
35.205.241.148 - - [22/Sep/2026:02:46:26 +1000] "GET /.env.old HTTP/2.0" 404 994 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
35.205.241.148 - - [22/Sep/2026:02:46:26 +1000] "GET /.env.bak HTTP/2.0" 404 994 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
35.205.241.148 - - [22/Sep/2026:02:46:26 +1000] "GET /z9x8c7v6b5-debug-
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 15:31:40
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 35.205.241.148 (148.241.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.205.241.148 (148.241.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 11:31:33.021948 2026] [security2:error] [pid 19404:tid 19404] [client 35.205.241.148:44090] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||uppercervicaloc.daebakdesign.com|F|2"] [data ".daebakdesign.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "uppercervicaloc.daebakdesign.com"] [uri "/z9x8c7v6b5-debug-trigger-uppercervicaloc.daebakdesign.com"] [unique_id "arFN1SkfP78nP1nVf4iTCwAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
antlac1
2026-09-21 14:36:32
(2 weeks ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:34:04
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 35.205.241.148 (148.241.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.205.241.148 (148.241.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:33:55.173291 2026] [security2:error] [pid 24518:tid 24518] [client 35.205.241.148:50822] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mapleleaf-marketing.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mapleleaf-marketing.com"] [uri "/z9x8c7v6b5-debug-trigger-mapleleaf-marketing.com"] [unique_id "arFAUy81qpnnwGErZBI4eQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 14:30:05
(2 weeks ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ซ๐ท
Quarks Solutions
2026-09-21 14:15:13
(2 weeks ago)
crowdsecurity/appsec-vpatch
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 14:01:32
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 35.205.241.148 (148.241.205.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.205.241.148 (148.241.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 10:01:23.679368 2026] [security2:error] [pid 21324:tid 21324] [client 35.205.241.148:50326] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.michaelward.com|F|2"] [data ".michaelward.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.michaelward.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.michaelward.com"] [unique_id "arE4sx5KAthy3eEDI3c9RgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
noise.agency
2026-09-21 13:59:10
(2 weeks ago)
35.205.241.148 (BE/Belgium/148.241.205.35.bc.googleusercontent.com), more than 10 Apache 403 hits
Hacking