๐บ๐ธ
TPI-Abuse
2026-09-22 08:58:48
(51 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.221.200.204 (204.200.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.200.204 (204.200.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:58:43.094026 2026] [security2:error] [pid 27932:tid 27932] [client 35.221.200.204:39588] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||smartstylehair.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "smartstylehair.com"] [uri "/z9x8c7v6b5-debug-trigger-smartstylehair.com"] [unique_id "arJDQ0AqmioQTxqIoqT4NAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-22 08:34:23
(1 hour ago)
[Tue Sep 22 04:34:19.677525 2026] [authz_core:error] [pid 1808416:tid 139704850691840] [client 35.22 ...
show more
[Tue Sep 22 04:34:19.677525 2026] [authz_core:error] [pid 1808416:tid 139704850691840] [client 35.221.200.204:0] AH01630: client denied by server configuration: /var/www/vhosts/smilewithindigo.com/error_docs/forbidden.html, referer: https://smilewithindigo.com/terraform.tfstate
[Tue Sep 22 04:34:21.500375 2026] [authz_core:error] [pid 1808416:tid 139704859084544] [client 35.221.200.204:0] AH01630: client denied by server configuration: /var/www/vhosts/smilewithindigo.com/httpdocs/.ssh, referer: https://smilewithindigo.com/.ssh/id_dsa
[Tue Sep 22 04:34:21.500460 2026] [authz_core:error] [pid 1808416:tid 139704859084544] [client 35.221.200.204:0] AH01630: client denied by server configuration: /var/www/vhosts/smilewithindigo.com/error_docs/forbidden.html, referer: https://smilewithindigo.com/.ssh/id_dsa
[Tue Sep 22 04:34:23.560536 2026] [authz_core:error] [pid 1808416:tid 139704850691840] [client 35.221.200.204:0] AH01630: client denied by server configuration: /var/www/vhosts/smilewithi
...
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 08:32:28
(1 hour ago)
[ti-02ov] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02ov] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.221.200.204 - - [22/Sep/2026:10:32:23 +0200] "GET /admin/.env HTTP/2.0" 301 530 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
35.221.200.204 - - [22/Sep/2026:10:32:23 +0200] "GET /backend/.env HTTP/2.0" 301 534 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-22 08:30:49
(1 hour ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-22 08:18:35
(1 hour ago)
Excessive multi-domain requests
Brute-Force
๐ฆ๐บ
Bay13
2026-09-22 08:09:31
(1 hour ago)
CrowdSec:custom/http-probing
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:06:20
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.221.200.204 (204.200.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.200.204 (204.200.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:06:14.598603 2026] [security2:error] [pid 15966:tid 15966] [client 35.221.200.204:48664] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||smotheredhope.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "smotheredhope.com"] [uri "/z9x8c7v6b5-debug-trigger-smotheredhope.com"] [unique_id "arI29toqZuF7h3EbBoBaOwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 08:01:45
(1 hour ago)
2026/09/22 08:01:42 [error] 4738#4738: *192323 [client 35.221.200.204] ModSecurity: Access denied wi ...
show more
2026/09/22 08:01:42 [error] 4738#4738: *192323 [client 35.221.200.204] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `40' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "smscoregh.com"] [uri "/"] [unique_id "179006410286.284627"] [ref ""], client: 35.221.200.204, server: smscoregh.com, request: "POST / HTTP/2.0", host: "smscoregh.com"
2026/09/22 08:01:42 [error] 4738#4738: *192323 [client 35.221.200.204] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUES
...
show less
Brute-Force
๐ฉ๐ช
BlueWire Hosting
2026-09-22 08:01:39
(1 hour ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐ฎ๐น
VHosting
2026-09-22 08:00:06
(1 hour ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
Anonymous
2026-09-22 07:50:12
(1 hour ago)
| [Dangerous/Taiwan] Aggressive IP 35.221.200.204 (~30 hits). Type: DoS Defender- Web server 400 err ...
show more
| [Dangerous/Taiwan] Aggressive IP 35.221.200.204 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-22 07:48:58
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.221.200.204 (204.200.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.200.204 (204.200.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 03:48:53.528297 2026] [security2:error] [pid 5854:tid 5854] [client 35.221.200.204:47394] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stoneybluff.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stoneybluff.com"] [uri "/z9x8c7v6b5-debug-trigger-stoneybluff.com"] [unique_id "arIy5RGoeVAJwFDy-UlF9QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-22 07:48:27
(2 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
Mundo Bueno
2026-09-22 07:43:23
(2 hours ago)
[ISILIA Protection v2.3] Tentative d'accรจs: /.git/config [RATE LIMITED - 1800s quarantine] | Pays: T ...
show more
[ISILIA Protection v2.3] Tentative d'accรจs: /.git/config [RATE LIMITED - 1800s quarantine] | Pays: TW | UA: Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)
show less
Hacking
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-22 07:36:17
(2 hours ago)
Excessive 404/403 errors
Brute-Force