๐ท๐ธ
pexodelic
2026-09-16 06:06:52
(3 hours ago)
Automated report from web, SSH and FTP server logs: 11 requests probing for exposed secrets (.env, . ...
show more
Automated report from web, SSH and FTP server logs: 11 requests probing for exposed secrets (.env, .git, config files); 71 distinct non-existent paths requested (wordlist scanning); 71 HTTP 4xx responses. First reported 2026-09-15 20:05 UTC, last reported 2026-09-16 06:05 UTC; counts cover the current log rotation window.
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 04:25:56
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.222.203.43 (43.203.222.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.222.203.43 (43.203.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 00:25:50.953017 2026] [security2:error] [pid 30424:tid 30424] [client 35.222.203.43:49468] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vanemby.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vanemby.com"] [uri "/rclone.conf"] [unique_id "aqoaTgZJUguPlbk-QuZEjgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-09-16 04:20:36
(5 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-09-16 02:38:02
(7 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐ณ๐ฑ
ConsulHosting
2026-09-16 02:08:56
(7 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ฌ๐ง
andypiper
2026-09-16 01:00:08
(8 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 00:17:01
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.222.203.43 (43.203.222.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.222.203.43 (43.203.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:16:56.401287 2026] [security2:error] [pid 21394:tid 21394] [client 35.222.203.43:60634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thepotteriesmesilla.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqnf-B9vvBE5awFwHECztQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-16 00:15:59
(9 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.222.203.43 (US/United States/43.203.222.35.b ...
show more
(mod_security) mod_security (id:949110) triggered by 35.222.203.43 (US/United States/43.203.222.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(9 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-15 22:36:19
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.222.203.43 (43.203.222.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.222.203.43 (43.203.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:36:12.572757 2026] [security2:error] [pid 7438:tid 7438] [client 35.222.203.43:32972] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||theonepieceisreal.click|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "theonepieceisreal.click"] [uri "/rclone.conf"] [unique_id "aqnIXDo2LRiPcunb2CviZQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-09-15 22:02:07
(11 hours ago)
Auto-ban: >3000 req/min op 2026-09-15
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-15 21:27:18
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.222.203.43 (43.203.222.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.222.203.43 (43.203.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:27:13.646868 2026] [security2:error] [pid 4118:tid 4118] [client 35.222.203.43:54272] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thendco.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thendco.com"] [uri "/z9x8c7v6b5-debug-trigger-thendco.com"] [unique_id "aqm4MRIJZjw2aPzKcHPyYAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
svr
2026-09-15 21:15:39
(12 hours ago)
Abusive Automated Web Scanner
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 18:38:49
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.222.203.43 (43.203.222.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.222.203.43 (43.203.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:38:44.375648 2026] [security2:error] [pid 11434:tid 11434] [client 35.222.203.43:38432] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thelotsmokehouse.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thelotsmokehouse.com"] [uri "/z9x8c7v6b5-debug-trigger-thelotsmokehouse.com"] [unique_id "aqmQtMRmMhwFmLOTUtiMZwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-09-15 18:24:46
(15 hours ago)
(mod_security) mod_security (id:930130) triggered by 35.222.203.43 (US/United States/43.203.222.35.b ...
show more
(mod_security) mod_security (id:930130) triggered by 35.222.203.43 (US/United States/43.203.222.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
SSH
Web App Attack