๐บ๐ธ
TPI-Abuse
2026-09-24 07:25:27
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.221.84.92 (92.84.221.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.84.92 (92.84.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:25:21.313356 2026] [security2:error] [pid 19131:tid 19131] [client 35.221.84.92:54590] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.printorganic.com|F|2"] [data ".printorganic.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.printorganic.com"] [uri "/z9x8c7v6b5-debug-trigger-www.printorganic.com"] [unique_id "arTQYdcC6tXDNnYzh1h3lgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-24 06:00:03
(2 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
NXTwoThou
2026-09-24 05:37:08
(2 hours ago)
/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env
Web App Attack
๐จ๐ฆ
Mediashaker
2026-09-24 05:33:34
(2 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.221.84.92 (JP/Jap ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.221.84.92 (JP/Japan/92.84.221.35.bc.googleusercontent.com)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-24 04:05:39
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.221.84.92 (92.84.221.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.84.92 (92.84.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 00:05:34.780777 2026] [security2:error] [pid 19781:tid 19781] [client 35.221.84.92:59954] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.praedari.com|F|2"] [data ".praedari.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.praedari.com"] [uri "/z9x8c7v6b5-debug-trigger-www.praedari.com"] [unique_id "arShjvuaZrFXXrGKdmNOygAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-24 03:51:10
(4 hours ago)
[ti-02ov] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-02ov] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.221.84.92 - - [24/Sep/2026:05:51:09 +0200] "GET /backend/.env HTTP/2.0" 301 510 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
35.221.84.92 - - [24/Sep/2026:05:51:09 +0200] "GET /api/.env HTTP/2.0" 301 502 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
...
show less
Bad Web Bot
Web App Attack
๐ฆ๐บ
Bay13
2026-09-24 03:43:25
(4 hours ago)
CrowdSec:custom/http-probing
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 03:33:40
(4 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.84.92 (92.84.221.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.84.92 (92.84.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 23:33:34.675757 2026] [security2:error] [pid 29109:tid 29109] [client 35.221.84.92:44290] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.powerlinemagazine.com"] [uri "/.env.development"] [unique_id "arSaDlMB1T11nSbL7lP6BQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 02:05:40
(6 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ซ๐ฎ
mnazibo
2026-09-24 02:00:07
(6 hours ago)
Date: 24/Sep/2026 04:19:34 | Reported IP: 35.221.84.92 mod_security | id: 911100 930100 930110 93012 ...
show more
Date: 24/Sep/2026 04:19:34 | Reported IP: 35.221.84.92 mod_security | id: 911100 930100 930110 930120 930130 932160 932250 933160 934100 934130 942550 | JP/group.my_domain/- | Connections: 83 | Blocked: Permanent Block: [LF_MODSEC] | URIs: /admin/.env; /api/designer/v1/file-content; /api/.env; /api/inngest; /api/templates/preview; /api/v1/validate/code; /app/.env; /auth.json; /.aws/config; /.aws/credentials; /backend/.env; /.bashrc; /build/.env; /config/.env.php; /config/gcp-credentials.json; /config.php.bak; /config/secrets.yml; /core/.env; /credentials.json; /dist/.env; /docker-compose.yaml; /docker-compose.yml; /docker/.env; /Dockerfile; /.env.backup; /.env.bak; /.env.dev; /.env.example; /.env.local; /.env.old; /.env.php.bak; /.env.prod; /.env.production; /.env.save; /.env.swp; /firebase-credentials.json; /frontend/.env; /functionRouter; /.git/config; /.git-credentials; /.git/HEAD; /.gitlab-ci.yml; /.htpasswd; /inngest; /laravel/.env
show less
SQL Injection
Brute-Force
Bad Web Bot
๐ณ๐ฑ
Eric
2026-09-24 01:50:31
(6 hours ago)
[Thu Sep 24 01:50:23.069799 2026] [security2:error] [pid 521724:tid 521724] [client 35.221.84.92:0] ...
show more
[Thu Sep 24 01:50:23.069799 2026] [security2:error] [pid 521724:tid 521724] [client 35.221.84.92:0] [client 35.221.84.92] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.pop-the-slots.com"] [uri "/z9x8c7v6b5-debug-trigger-www.pop-the-slots.com"] [unique_id "arSB3yp8sDCF-J_HUFG3XQAAAAM"]
[Thu Sep 24 01:50:27.713905 2026] [security2:error] [pid 521724:tid 521724] [client 35.221.84.92:0] [client 35.221.84.92] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/usr/share/modsecurity-crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Scor
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 01:35:42
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.221.84.92 (92.84.221.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.84.92 (92.84.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 21:35:38.250892 2026] [security2:error] [pid 23370:tid 23370] [client 35.221.84.92:60090] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.pontiacpalace.com|F|2"] [data ".pontiacpalace.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.pontiacpalace.com"] [uri "/z9x8c7v6b5-debug-trigger-www.pontiacpalace.com"] [unique_id "arR-anQZ8rLMKgbaCtY7WQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-24 01:07:13
(7 hours ago)
2.661 requests from abuseipdb.com blacklisted IP (5mos2w2d)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-24 00:54:18
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.221.84.92 (92.84.221.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.221.84.92 (92.84.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:54:10.090612 2026] [security2:error] [pid 5193:tid 5193] [client 35.221.84.92:59706] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.poland-yacht-registration.com|F|2"] [data ".poland-yacht-registration.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.poland-yacht-registration.com"] [uri "/z9x8c7v6b5-debug-trigger-www.poland-yacht-registration.com"] [unique_id "arR0smh1fwOuYZH0eEARsAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 00:21:49
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.221.84.92 (92.84.221.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 35.221.84.92 (92.84.221.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:21:42.674784 2026] [security2:error] [pid 5830:tid 5830] [client 35.221.84.92:45034] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.piratecostumesonline.com"] [uri "/web.config"] [unique_id "arRtFla9Ah0svs144CExHAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack