Anonymous
2026-10-01 08:50:52
(1 day ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-01 06:02:44
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.205.35.165 (165.35.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.205.35.165 (165.35.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 02:02:40.504597 2026] [security2:error] [pid 2480:tid 2480] [client 35.205.35.165:46928] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.cosentient.com|F|2"] [data ".cosentient.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.cosentient.com"] [uri "/z9x8c7v6b5-debug-trigger-www.cosentient.com"] [unique_id "ar33gGI_gEYH1cL3B5yjigAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 05:43:29
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.205.35.165 (165.35.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.205.35.165 (165.35.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:43:24.797206 2026] [security2:error] [pid 1982:tid 1982] [client 35.205.35.165:57086] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||miraclepunchy.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "miraclepunchy.com"] [uri "/z9x8c7v6b5-debug-trigger-miraclepunchy.com"] [unique_id "ar3y_H0jDYDNbvjOKNAg2wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 04:59:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.205.35.165 (165.35.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.35.165 (165.35.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 00:59:37.022371 2026] [security2:error] [pid 16452:tid 16452] [client 35.205.35.165:36144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wholesalelivelobsters.com"] [uri "/dist../.env"] [unique_id "ar3ouWW1A4kAnbuAjbN4ggAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 02:16:21
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.205.35.165 (165.35.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.205.35.165 (165.35.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 22:16:16.868868 2026] [security2:error] [pid 9339:tid 9339] [client 35.205.35.165:33626] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||srtmanagementservices.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "srtmanagementservices.com"] [uri "/z9x8c7v6b5-debug-trigger-srtmanagementservices.com"] [unique_id "ar3CcEXNmg3nPi7USKAZkQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
IVski.com
2026-10-01 01:59:59
(1 day ago)
IVski WAF | Next.js Server Action probe
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 01:36:13
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.205.35.165 (165.35.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.205.35.165 (165.35.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 21:36:07.331674 2026] [security2:error] [pid 6378:tid 6451] [client 35.205.35.165:49816] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||minutosrobados.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "minutosrobados.com"] [uri "/z9x8c7v6b5-debug-trigger-minutosrobados.com"] [unique_id "ar25B35S0kbsJEo0kDfaAwAAAVM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Vegascosmetics
2026-10-01 01:20:22
(1 day ago)
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after repeated server-error fuzzing. Eviden ...
show more
Kingcopy.org AI-IDS (Vegas Cosmetics shop): auto-blocked after repeated server-error fuzzing. Evidence: Repeated Server Errors (500)
show less
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 01:16:57
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.205.35.165 (165.35.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.205.35.165 (165.35.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 21:16:53.251510 2026] [security2:error] [pid 30779:tid 30841] [client 35.205.35.165:45462] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.missmadlove.com"] [uri "/web.config"] [unique_id "ar20haefsK571sIigJmIbgAAAYI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-01 01:11:45
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 00:02:20
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.205.35.165 (165.35.205.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.205.35.165 (165.35.205.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 20:02:14.838749 2026] [security2:error] [pid 18397:tid 18397] [client 35.205.35.165:42816] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.motioncontrolpartners.com|F|2"] [data ".motioncontrolpartners.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.motioncontrolpartners.com"] [uri "/z9x8c7v6b5-debug-trigger-www.motioncontrolpartners.com"] [unique_id "ar2jBjHzGz0jdpaYhxlwwwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-30 22:31:44
(1 day ago)
499 requests with url.path *.env
183 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Alt255
2026-09-30 17:26:02
(1 day ago)
[cb-03al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-03al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.205.35.165 - - [30/Sep/2026:19:25:45 +0200] "GET /.ssh/config HTTP/2.0" 401 348 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-30 15:54:23
(1 day ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .b ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .back/ .backup/ .bak/ .bck/ .bk/ .bkp/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .cnf/ .com/ .compositefont/ .config/ .conf/ .copy/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jks/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .sav/ .save/ .scr/ .sct/ .sh/ .shs/ .sql/ .sqlite/ .sqlite3/ .swap/ .swo/ .swp/ .sys/ .temp/ .tfstate/ .tlb/ .tmp/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-193)
show less
Hacking
๐ซ๐ท
COMAITE
2026-09-30 15:44:54
(1 day ago)
Common web attack from 35.205.35.165.
Web App Attack