Anonymous
2026-09-13 10:12:26
(4 minutes ago)
2026/09/13 10:12:24 [error] 199233#199233: *503831 [client 35.221.239.203] ModSecurity: Access denie ...
show more
2026/09/13 10:12:24 [error] 199233#199233: *503831 [client 35.221.239.203] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "ingeltechgh.com"] [uri "/static//app/.env"] [unique_id "178929434424.007166"] [ref ""], client: 35.221.239.203, server: ingeltechgh.com, request: "GET /static//app/.env HTTP/2.0", host: "ingeltechgh.com"
2026/09/13 10:12:24 [error] 199233#199233: *503831 [client 35.221.239.203] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `5' ) [file "/us
...
show less
Brute-Force
Anonymous
2026-09-13 10:04:22
(12 minutes ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
🇩🇪
bazter.pro
2026-09-13 09:43:32
(33 minutes ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-13 09:37:50
(39 minutes ago)
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ ...
show more
URL file extension is restricted by policy. String match within ".ani/ .asa/ .asax/ .ascx/ .backup/ .bak/ .bat/ .cdx/ .cer/ .cfg/ .cmd/ .com/ .compositefont/ .config/ .conf/ .crt/ .cs/ .csproj/ .csr/ .dat/ .db/ .dbf/ .dist/ .dll/ .dos/ .dpkg-dist/ .drv/ .gadget/ .hta/ .htr/ .htw/ .ida/ .idc/ .idq/ .inc/ .inf/ .ini/ .jse/ .key/ .licx/ .lnk/ .log/ .mdb/ .msc/ .ocx/ .old/ .pass/ .pdb/ .pfx/ .pif/ .pem/ .pol/ .prf/ .printer/ .pwd/ .rdb/ .rdp/ .reg/ .resources/ .resx/ .scr/ .sct/ .shs/ .sql/ .swp/ .sys/ .tlb/ .tmp/ .url/ .vb/ .vbe/ .vbs/ .vbproj/ .vsdisco/ .vxd/ .webinfo/ .ws/ .wsc/ .wsf/ .wsh/ .xsd/ .xsx/" at TX:extension. (920440-195)
show less
Hacking
🇳🇱
MyGlobalFlowers
2026-09-13 09:35:26
(41 minutes ago)
Multiple WAF Violations
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 09:28:08
(49 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.221.239.203 (203.239.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.239.203 (203.239.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 05:27:59.053982 2026] [security2:error] [pid 12672:tid 12672] [client 35.221.239.203:59976] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ewingmissouri.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ewingmissouri.com"] [uri "/z9x8c7v6b5-debug-trigger-ewingmissouri.com"] [unique_id "aqZsnxmXq7H9TCv-UZzPJgAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-13 09:23:18
(54 minutes ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-13 09:11:34
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.221.239.203 (203.239.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.239.203 (203.239.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 05:11:31.620845 2026] [security2:error] [pid 14625:tid 14625] [client 35.221.239.203:55508] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||disenowebprofesional.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "disenowebprofesional.com"] [uri "/z9x8c7v6b5-debug-trigger-disenowebprofesional.com"] [unique_id "aqZow4Yp3pE6qNP5G-RZ_wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇬🇧
consul.to
2026-09-13 09:08:39
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
🇨🇭
dalslab ltd
2026-09-13 09:03:24
(1 hour ago)
35.221.239.203 - - [13/Sep/2026:11:03:22 +0200] "POST /graphql HTTP/1.1" 405 556 "http://dalslab.com ...
show more
35.221.239.203 - - [13/Sep/2026:11:03:22 +0200] "POST /graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
35.221.239.203 - - [13/Sep/2026:11:03:22 +0200] "GET /public/plugins/grafana-clock-panel/../../../../../../../../proc/self/environ HTTP/1.1" 400 154 "-" "-"
35.221.239.203 - - [13/Sep/2026:11:03:23 +0200] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 154 "-" "-"
35.221.239.203 - - [13/Sep/2026:11:03:23 +0200] "POST /api/graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36"
35.221.239.203 - - [13/Sep/2026:11:03:23 +0200] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/proc/self/environ HTTP/1.1" 400 154 "-" "-"
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 08:45:07
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.221.239.203 (203.239.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.239.203 (203.239.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 04:45:00.303007 2026] [security2:error] [pid 5327:tid 5327] [client 35.221.239.203:52316] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||centuryabsinthe.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "centuryabsinthe.com"] [uri "/z9x8c7v6b5-debug-trigger-centuryabsinthe.com"] [unique_id "aqZijPot_oqBTdRun8RgGwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
interbiznw.com
2026-09-13 08:40:07
(1 hour ago)
fail2ban-ban
Hacking
Brute-Force
Exploited Host
Web App Attack
Anonymous
2026-09-13 08:35:11
(1 hour ago)
git/env leak probe
Web App Attack
🇸🇬
Cloudkul Cloudkul
2026-09-13 08:25:35
(1 hour ago)
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requ ...
show more
Attempted Not Found (404 status code) requests on our application, more than 30% of their total requests.
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 08:23:57
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.221.239.203 (203.239.221.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.239.203 (203.239.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 04:23:50.319285 2026] [security2:error] [pid 22352:tid 22352] [client 35.221.239.203:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bbproductionsonline.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bbproductionsonline.com"] [uri "/z9x8c7v6b5-debug-trigger-bbproductionsonline.com"] [unique_id "aqZdlpaxg0aFwaVE3jdC2gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack