๐ซ๐ฎ
oh.mg
2026-10-09 03:30:23
(7 hours ago)
[Fri Oct 09 05:30:22.943891 2026] [security2:error] [pid 1188684:tid 1188703] [client 35.221.182.73: ...
show more
[Fri Oct 09 05:30:22.943891 2026] [security2:error] [pid 1188684:tid 1188703] [client 35.221.182.73:0] [client 35.221.182.73] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [ver "OWASP_CRS/4.10.0-dev"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "api.mmn.ca"] [uri "/"] [unique_id "ashfziJTv0U1YnD3yl7_zAAAAA8"]
...
show less
Web App Attack
Bad Web Bot
๐ฉ๐ช
Bedios GmbH
2026-10-09 03:06:38
(7 hours ago)
Login credentials theft attempt
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-09 01:43:24
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.182.73 (73.182.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.182.73 (73.182.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:43:17.539260 2026] [security2:error] [pid 31811:tid 31811] [client 35.221.182.73:53806] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ramabahama.net"] [uri "/%2e%2e/.env"] [unique_id "ashGtQ2iLXD_9aG_j72i0QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-10-09 01:40:03
(9 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฆ๐บ
clapper
2026-10-09 01:20:18
(9 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.221.182.73 (TW/Taiwan/73.182.221.35.bc.googl ...
show more
(mod_security) mod_security (id:949110) triggered by 35.221.182.73 (TW/Taiwan/73.182.221.35.bc.googleusercontent.com): 3 in the last 3600 secs; ID: LUC
show less
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Site.eu
2026-10-09 01:10:29
(9 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
infra-monitor
2026-10-09 01:00:05
(9 hours ago)
Automated ban via infra-monitor: mgmt-path-probe, crowdsecurity/http-cve-2021-41773, suspicious-prob ...
show more
Automated ban via infra-monitor: mgmt-path-probe, crowdsecurity/http-cve-2021-41773, suspicious-probe, +6 more
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 00:41:13
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.182.73 (73.182.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.182.73 (73.182.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:41:09.743204 2026] [security2:error] [pid 19630:tid 19630] [client 35.221.182.73:39630] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pixals.net"] [uri "/.htpasswd"] [unique_id "asg4JTeAZoBsmLE8YdayAwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Viveronese
2026-10-09 00:34:35
(10 hours ago)
HTTP vulnerability scanning
Web App Attack
๐ช๐ธ
masterguru
2026-10-09 00:25:33
(10 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "PerplexityBot" at REQUEST_HEADERS:User-Agent. (1100 ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "PerplexityBot" at REQUEST_HEADERS:User-Agent. (1100000-122)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-09 00:10:55
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.182.73 (73.182.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.182.73 (73.182.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 20:10:48.446193 2026] [security2:error] [pid 18355:tid 18355] [client 35.221.182.73:60054] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "pappakotis.net"] [uri "/.env.production"] [unique_id "asgxCC0anqr0EYg8qDqBTQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Tha_14
2026-10-08 23:42:36
(11 hours ago)
Excessive spam activity detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 23:40:09
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.182.73 (73.182.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.182.73 (73.182.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:40:02.118687 2026] [security2:error] [pid 23275:tid 23275] [client 35.221.182.73:37822] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "okeetokee.net"] [uri "/.env"] [unique_id "asgp0pwyXof2iLbtd7P2wwAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
findlab
2026-10-08 23:30:01
(11 hours ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 23:14:37
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.182.73 (73.182.221.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.182.73 (73.182.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 19:14:31.881194 2026] [security2:error] [pid 30684:tid 30684] [client 35.221.182.73:45988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nigunensemble.net"] [uri "/.htpasswd"] [unique_id "asgj1_b-GH_fOyyQ854FhwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack