๐บ๐ธ
TPI-Abuse
2026-09-22 12:22:39
(4 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.222.129.174 (174.129.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.222.129.174 (174.129.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:22:35.595935 2026] [security2:error] [pid 30451:tid 30451] [client 35.222.129.174:46506] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thegamblefamily.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thegamblefamily.com"] [uri "/z9x8c7v6b5-debug-trigger-thegamblefamily.com"] [unique_id "arJzC4RrmUULXe93ClmjIgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:52:35
(34 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.222.129.174 (174.129.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.222.129.174 (174.129.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:52:32.005805 2026] [security2:error] [pid 12694:tid 12694] [client 35.222.129.174:45690] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thegoldreserve.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thegoldreserve.com"] [uri "/z9x8c7v6b5-debug-trigger-thegoldreserve.com"] [unique_id "arJsAHHHJcAdTgbi5PczaQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-22 11:27:21
(59 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 11:24:17
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.222.129.174 (174.129.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.222.129.174 (174.129.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:24:13.892014 2026] [security2:error] [pid 1273:tid 1273] [client 35.222.129.174:60710] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thegrousewoods.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thegrousewoods.com"] [uri "/z9x8c7v6b5-debug-trigger-thegrousewoods.com"] [unique_id "arJlXVUPbYYlTqyQ8UMX6AAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-22 11:13:06
(1 hour ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:02:09
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.222.129.174 (174.129.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.222.129.174 (174.129.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:02:03.938685 2026] [security2:error] [pid 19005:tid 19005] [client 35.222.129.174:42708] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thehealthcontent.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thehealthcontent.com"] [uri "/z9x8c7v6b5-debug-trigger-thehealthcontent.com"] [unique_id "arJgK2O_ga7BjTTW2UKcHwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
conure.sh
2026-09-22 10:59:00
(1 hour ago)
csagent: score 22.2: 404 noise floor x9, secrets grab x2; 1 domain(s) in 1s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 09:56:30
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.222.129.174 (174.129.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.222.129.174 (174.129.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 05:56:22.891898 2026] [security2:error] [pid 8418:tid 8418] [client 35.222.129.174:57210] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thehunterstomb.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thehunterstomb.com"] [uri "/z9x8c7v6b5-debug-trigger-thehunterstomb.com"] [unique_id "arJQxjDC683MTwzYiwkw6QAAAD8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-22 09:28:27
(2 hours ago)
35.222.129.174 - - [22/Sep/2026:05:28:26 -0400] "GET /api/.env HTTP/1.1" 404 4838 "https://thejourne ...
show more
35.222.129.174 - - [22/Sep/2026:05:28:26 -0400] "GET /api/.env HTTP/1.1" 404 4838 "https://thejourneyhomellc.com/api/.env" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )"
35.222.129.174 - - [22/Sep/2026:05:28:27 -0400] "GET /.aws/credentials HTTP/1.1" 404 4838 "https://thejourneyhomellc.com/.aws/credentials" "CCBot/2.0 (https://commoncrawl.org/faq/)"
35.222.129.174 - - [22/Sep/2026:05:28:27 -0400] "GET /@fs/app/.env?raw?? HTTP/1.1" 404 4838 "https://thejourneyhomellc.com/@fs/app/.env?raw??" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
...
show less
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-22 09:26:07
(3 hours ago)
(modsecurity) srv104 ModSecurity 35.222.129.174 (US/United States/174.129.222.35.bc.googleuserconten ...
show more
(modsecurity) srv104 ModSecurity 35.222.129.174 (US/United States/174.129.222.35.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
Lee Daniel
2026-09-22 08:38:40
(3 hours ago)
35.222.129.174 - - [22/Sep/2026:04:38:40 -0400] "GET /.aws/credentials HTTP/1.1" 403 377 "-" "Mozill ...
show more
35.222.129.174 - - [22/Sep/2026:04:38:40 -0400] "GET /.aws/credentials HTTP/1.1" 403 377 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:25:00
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.222.129.174 (174.129.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.222.129.174 (174.129.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:24:55.821180 2026] [security2:error] [pid 21337:tid 21337] [client 35.222.129.174:34034] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||thelowensteinfamily.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thelowensteinfamily.com"] [uri "/z9x8c7v6b5-debug-trigger-thelowensteinfamily.com"] [unique_id "arI7V2Yrm7e6anEfXPJXiAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-22 08:20:05
(4 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-09-22 08:05:23
(4 hours ago)
Scanning/Probing (17)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 07:50:19
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.222.129.174 (174.129.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.222.129.174 (174.129.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 03:50:14.455016 2026] [security2:error] [pid 3512:tid 3512] [client 35.222.129.174:39374] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||themediaplanet.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "themediaplanet.com"] [uri "/z9x8c7v6b5-debug-trigger-themediaplanet.com"] [unique_id "arIzNhNb-31Pi3sCPfDYhAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack