๐ฎ๐น
VHosting
2026-10-01 07:45:04
(4 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ง๐ช
cmbplf
2026-10-01 07:41:40
(4 days ago)
111 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 05:47:04
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 35.226.48.0 (0.48.226.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 35.226.48.0 (0.48.226.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 01:46:57.048004 2026] [security2:error] [pid 2158:tid 2158] [client 35.226.48.0:48004] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||reimaginingchess.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "reimaginingchess.com"] [uri "/z9x8c7v6b5-debug-trigger-reimaginingchess.com"] [unique_id "ar3z0UTRuPJWPQSKYlLO8QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 00:18:59
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 35.226.48.0 (0.48.226.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 35.226.48.0 (0.48.226.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 20:18:55.237418 2026] [security2:error] [pid 28331:tid 28331] [client 35.226.48.0:39968] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fruitinthedesert.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fruitinthedesert.com"] [uri "/z9x8c7v6b5-debug-trigger-fruitinthedesert.com"] [unique_id "ar2m704jcLUJNpy77Cs4HAAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-30 21:53:54
(5 days ago)
Crawler ignoring refusals | ua: Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/ ...
show more
Crawler ignoring refusals | ua: Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/), Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatibl, Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36 (+11 more) | path: /lib/terminal-xhr.php, /model/info, /build/manifest.json (+17 more)
show less
Bad Web Bot
๐ซ๐ท
ELYAZ
2026-09-30 20:12:18
(5 days ago)
(y3) Failed access -byebye- from 35.226.48.0 (US/United States/0.48.226.35.bc.googleusercontent.com) ...
show more
(y3) Failed access -byebye- from 35.226.48.0 (US/United States/0.48.226.35.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
๐บ๐ธ
mnsf
2026-09-30 19:05:56
(5 days ago)
Too many Status 40X (18)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 16:13:46
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.226.48.0 (0.48.226.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 35.226.48.0 (0.48.226.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 12:13:39.075457 2026] [security2:error] [pid 20142:tid 20142] [client 35.226.48.0:51106] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.rejuvenationsystems.com|F|2"] [data ".rejuvenationsystems.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.rejuvenationsystems.com"] [uri "/z9x8c7v6b5-debug-trigger-www.rejuvenationsystems.com"] [unique_id "ar01M-GPIQeYr2THfn0PUQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:41:51
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.226.48.0 (0.48.226.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 35.226.48.0 (0.48.226.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:41:46.254010 2026] [security2:error] [pid 15776:tid 15913] [client 35.226.48.0:52720] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.records.emehache.com|F|2"] [data ".records.emehache.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.records.emehache.com"] [uri "/z9x8c7v6b5-debug-trigger-www.records.emehache.com"] [unique_id "ar0tul9UFye6bEn-OQjKKwAAAhA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-30 14:50:15
(5 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
Anonymous
2026-09-30 14:50:00
(5 days ago)
Excessive crawling/scraping. Vulnerable file probing.
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-30 14:47:56
(5 days ago)
35.226.48.0 - - [30/Sep/2026:16:47:54 +0200] "GET /dashboard%2F.env HTTP/2.0" 404 295 "-" "Mozilla/5 ...
show more
35.226.48.0 - - [30/Sep/2026:16:47:54 +0200] "GET /dashboard%2F.env HTTP/2.0" 404 295 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
35.226.48.0 - - [30/Sep/2026:16:47:54 +0200] "GET /uploads../.env HTTP/2.0" 404 295 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
35.226.48.0 - - [30/Sep/2026:16:47:54 +0200] "GET /actuator HTTP/2.0" 404 295 "-" "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)"
35.226.48.0 - - [30/Sep/2026:16:47:54 +0200] "GET /settings.json HTTP/2.0" 403 298 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
35.226.48.0 - - [30/Sep/2026:16:47:54 +0200] "GET /env.js HTTP/2.0" 403 298 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
35.226.48.0 - - [30/Sep/2026:16:47:54 +0200] "GET /actuator/configprops HTTP/2.0" 403 298 "-" "Mozilla/5.0 App
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-30 14:22:06
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.226.48.0 (0.48.226.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 35.226.48.0 (0.48.226.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 10:22:00.043763 2026] [security2:error] [pid 27971:tid 27971] [client 35.226.48.0:46904] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||techlinks.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "techlinks.com"] [uri "/z9x8c7v6b5-debug-trigger-techlinks.com"] [unique_id "ar0bCA0NHd4-8xF5n364-QAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-09-30 14:12:59
(5 days ago)
Remote Command Execution: Direct Unix Command Execution. Pattern match "(?i)(?:^|b (932250-195)
Hacking
๐ซ๐ท
masterguru
2026-09-30 13:48:58
(5 days ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:User-Agent. (1100000-193)
Bad Web Bot