๐ณ๐ฑ
Site.eu
2026-09-16 18:08:08
(1 day ago)
Excessive 404/403 errors
Brute-Force
๐ฟ๐ฆ
conure.sh
2026-09-16 12:07:39
(1 day ago)
csagent: score 22.4: 404 noise floor x10, secrets grab x2; 1 domain(s) in 1s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 06:51:02
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.226.65.189 (189.65.226.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.226.65.189 (189.65.226.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 02:50:58.521133 2026] [security2:error] [pid 4363:tid 4363] [client 35.226.65.189:48574] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||bikiniadvice.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bikiniadvice.com"] [uri "/z9x8c7v6b5-debug-trigger-bikiniadvice.com"] [unique_id "aqo8UrOyyh-HsTXW_FhawwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
GabrielJST
2026-09-16 05:20:58
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 35.226.65.189 (US/United States/189.65. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.226.65.189 (US/United States/189.65.226.35.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-16 05:11:18
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.226.65.189 (189.65.226.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.226.65.189 (189.65.226.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 01:11:14.333363 2026] [security2:error] [pid 28940:tid 28940] [client 35.226.65.189:33026] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "be4ventures.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqok8hZE7zWPBZgAPM-v2gAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 04:00:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.226.65.189 (189.65.226.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.226.65.189 (189.65.226.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 00:00:42.858090 2026] [security2:error] [pid 14793:tid 14793] [client 35.226.65.189:48838] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bairentang.org"] [uri "/.git/config"] [unique_id "aqoUalvZ0YgiyXQJF-8UNQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-09-16 01:14:05
(2 days ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
๐ณ๐ฑ
Savvii
2026-09-16 01:13:28
(2 days ago)
20 attempts against mh_ha-misbehave-ban on ec102950
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-16 01:10:00
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐ท๐ด
clauss
2026-09-16 01:09:30
(2 days ago)
35.226.65.189 - - [16/Sep/2026:04:09:20 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 ...
show more
35.226.65.189 - - [16/Sep/2026:04:09:20 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
35.226.65.189 - - [16/Sep/2026:04:09:30 +0300] "GET /config.json HTTP/2.0" 301 0 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
...
show less
Web App Attack
๐บ๐ธ
oralunal
2026-09-15 22:37:38
(2 days ago)
IP banned by Fail2Ban in jail ah-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:51:49
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.226.65.189 (189.65.226.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.226.65.189 (189.65.226.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:51:42.945086 2026] [security2:error] [pid 26044:tid 26044] [client 35.226.65.189:48334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amazingthailand.net"] [uri "/.env.local"] [unique_id "aqm97kMYFpUXqk06RxuJowAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:30:09
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.226.65.189 (189.65.226.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.226.65.189 (189.65.226.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:30:03.221371 2026] [security2:error] [pid 16076:tid 16076] [client 35.226.65.189:45090] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||altered-egos.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "altered-egos.com"] [uri "/z9x8c7v6b5-debug-trigger-altered-egos.com"] [unique_id "aqm42-Mb7Qm3tjRWkT0q2AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:18:20
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.226.65.189 (189.65.226.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.226.65.189 (189.65.226.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:18:14.369391 2026] [security2:error] [pid 14049:tid 14049] [client 35.226.65.189:49690] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aliamus.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aliamus.com"] [uri "/z9x8c7v6b5-debug-trigger-aliamus.com"] [unique_id "aqmoBg7ypZBwudL-ja3qhQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 19:22:25
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.226.65.189 (189.65.226.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.226.65.189 (189.65.226.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:22:18.281101 2026] [security2:error] [pid 23634:tid 23634] [client 35.226.65.189:53334] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "akmanoto.com"] [uri "/backend/.env"] [unique_id "aqma6vp-j-82U_f90s9CdQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack