🇮🇳
evicky2002
2026-09-11 06:00:00
(18 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-09-11 05:33:36
(19 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
🇵🇱
lns.bz
2026-09-11 05:24:30
(19 hours ago)
Web app attack [PL.Lu]
Exploited Host
Web App Attack
🇵🇱
gandaflux
2026-09-11 05:01:34
(19 hours ago)
35.221.45.41 [redacted-domain] - [11/Sep/2026:07:01:33 +0200] "GET /.aws/config HTTP/2.0" 403 158 "- ...
show more
35.221.45.41 [redacted-domain] - [11/Sep/2026:07:01:33 +0200] "GET /.aws/config HTTP/2.0" 403 158 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [redacted-email])"
35.221.45.41 [redacted-domain] - [11/Sep/2026:07:01:33 +0200] "GET /.git/HEAD HTTP/2.0" 403 158 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +[redacted-url]/searchbot)"
35.221.45.41 [redacted-domain] - [11/Sep/2026:07:01:33 +0200] "GET /.git-credentials HTTP/2.0" 403 158 "-" "Mozilla/5.0 (compatible; Bytespider; [redacted-email]) AppleWebKit/537.36"
show less
Web App Attack
🇺🇸
[email protected]
2026-09-11 04:58:45
(19 hours ago)
CrowdSec ban: crowdsecurity/http-crawl-non_statics (duration: 71h59m57s)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 04:36:29
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.221.45.41 (41.45.221.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.45.41 (41.45.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 11 00:36:24.132794 2026] [security2:error] [pid 16913:tid 16913] [client 35.221.45.41:38610] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||manty.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "manty.com"] [uri "/z9x8c7v6b5-debug-trigger-manty.com"] [unique_id "aqOFSLUEPulmT6CV7yd1bwAAAIU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 03:57:09
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.221.45.41 (41.45.221.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.45.41 (41.45.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 23:57:04.681733 2026] [security2:error] [pid 6236:tid 6236] [client 35.221.45.41:40032] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||landjudging.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "landjudging.com"] [uri "/rclone.conf"] [unique_id "aqN8EObs0OlRPpMruGb1AgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Savvii
2026-09-11 03:38:35
(20 hours ago)
20 attempts against mh-misbehave-ban on choy
Brute-Force
Bad Web Bot
Web App Attack
🇧🇾
lns.bz
2026-09-11 02:45:57
(21 hours ago)
Too many 404 requests [BY]
Web App Attack
🇺🇸
mnsf
2026-09-11 02:05:06
(22 hours ago)
Abuse Detected (9)
Brute-Force
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-11 02:04:45
(22 hours ago)
High-confidence malicious configuration/VCS probe
Web App Attack
🇺🇸
TPI-Abuse
2026-09-11 01:50:12
(22 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.45.41 (41.45.221.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.45.41 (41.45.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 10 21:50:03.620159 2026] [security2:error] [pid 2388:tid 2388] [client 35.221.45.41:51390] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "hakkawok.com"] [uri "/.env"] [unique_id "aqNeS49JuGANFpAsN51sFwAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
Shaik Sai Meera
2026-09-11 01:35:05
(22 hours ago)
IM360 WAF: Hidden file access
Brute-Force
🇨🇦
Anytech
2026-09-11 01:24:06
(23 hours ago)
Blocked by Conn-Monitor: env-probing
Web App Attack
Hacking
🇬🇧
andypiper
2026-09-11 01:02:29
(23 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack