๐ฌ๐ง
consul.to
2026-09-24 20:02:33
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐ฉ๐ช
Skyrider
2026-09-24 19:47:16
(4 hours ago)
crowdsecurity/http-probing
Web App Attack
๐ฉ๐ช
findlab
2026-09-24 19:20:02
(4 hours ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-24 15:25:05
(8 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฉ๐ช
neckaralb-admin.de
2026-09-24 14:32:29
(9 hours ago)
(wordpress) Failed login wp-login.php or xmlrpc.php
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-24 14:22:36
(9 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-24 12:12:04
(11 hours ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.227.77.1 (US/United States/1.77.2 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.227.77.1 (US/United States/1.77.227.35.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-09-24 11:48:06
(12 hours ago)
35.227.77.1 - - [24/Sep/2026:11:48:02 +0000] "GET /..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="35. ...
show more
35.227.77.1 - - [24/Sep/2026:11:48:02 +0000] "GET /..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.227.77.1"
35.227.77.1 - - [24/Sep/2026:11:48:02 +0000] "GET /..%2f..%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.227.77.1"
35.227.77.1 - - [24/Sep/2026:11:48:03 +0000] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="35.227.77.1"
35.227.77.1 - - [24/Sep/2026:11:48:03 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/1.1" 400 193 "-" "-" "-" edge="35.227.77.1"
35.227.77.1 - - [24/Sep/2026:11:48:03 +0000] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 193 "-" "-" "-" edge="35.227.77.1"
...
show less
Web Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 11:35:32
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.227.77.1 (1.77.227.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 35.227.77.1 (1.77.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 07:35:25.723592 2026] [security2:error] [pid 31622:tid 31622] [client 35.227.77.1:43598] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.sbip.loneoakhoney.com|F|2"] [data ".sbip.loneoakhoney.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.sbip.loneoakhoney.com"] [uri "/z9x8c7v6b5-debug-trigger-www.sbip.loneoakhoney.com"] [unique_id "arUK_Q4a3X2qDGzq6NxfjAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-09-24 11:20:38
(12 hours ago)
[24/Sep/2026:13:20:38 +0200] 179024883838.108544 35.227.77.1 39474 217.154.7.177 443
[24/Sep/2026:13 ...
show more
[24/Sep/2026:13:20:38 +0200] 179024883838.108544 35.227.77.1 39474 217.154.7.177 443
[24/Sep/2026:13:20:38 +0200] 179024883874.174977 35.227.77.1 39474 217.154.7.177 443
[24/Sep/2026:13:20:38 +0200] 179024883882.723430 35.227.77.1 39474 217.154.7.177 443
[24/Sep/2026:13:20:38 +0200] 179024883825.040108 35.227.77.1 39474 217.154.7.177 443
[24/Sep/2026:13:20:38 +0200] 179024883852.513701 35.227.77.1 39474 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 10:15:38
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.227.77.1 (1.77.227.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 35.227.77.1 (1.77.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 06:15:33.035192 2026] [security2:error] [pid 2122:tid 2122] [client 35.227.77.1:45524] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bonefrog.com|F|2"] [data ".bonefrog.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bonefrog.com"] [uri "/z9x8c7v6b5-debug-trigger-www.bonefrog.com"] [unique_id "arT4RS-dNE2I3hRbTKMAEAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 09:39:39
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.227.77.1 (1.77.227.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 35.227.77.1 (1.77.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 05:39:33.578063 2026] [security2:error] [pid 8968:tid 8968] [client 35.227.77.1:51748] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.service.alccontractorsllc.com|F|2"] [data ".service.alccontractorsllc.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.service.alccontractorsllc.com"] [uri "/z9x8c7v6b5-debug-trigger-www.service.alccontractorsllc.com"] [unique_id "arTv1TJ4jmfWxjxDDEMB8AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 08:50:37
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.227.77.1 (1.77.227.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 35.227.77.1 (1.77.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 04:50:32.064301 2026] [security2:error] [pid 31218:tid 31218] [client 35.227.77.1:46718] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||carpascarpe.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "carpascarpe.com"] [uri "/z9x8c7v6b5-debug-trigger-carpascarpe.com"] [unique_id "arTkWMTPeNZ4QvnPOlOBvwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-24 08:39:36
(15 hours ago)
35.227.77.1 - - [24/Sep/2026:10:39:27 +0200] "GET /z9x8c7v6b5-debug-trigger-crypcool.com HTTP/1.1" 4 ...
show more
35.227.77.1 - - [24/Sep/2026:10:39:27 +0200] "GET /z9x8c7v6b5-debug-trigger-crypcool.com HTTP/1.1" 404 30109
35.227.77.1 - - [24/Sep/2026:10:39:27 +0200] "GET /dist/.vite/manifest.json HTTP/1.1" 404 30109
35.227.77.1 - - [24/Sep/2026:10:39:27 +0200] "GET /dist/manifest.json HTTP/1.1" 404 30109
35.227.77.1 - - [24/Sep/2026:10:39:27 +0200] "GET /kufm2wxlxkxs192klash HTTP/1.1" 404 30109
35.227.77.1 - - [24/Sep/2026:10:39:27 +0200] "GET /build/manifest.json HTTP/1.1" 404 30109
35.227.77.1 - - [24/Sep/2026:10:39:28 +0200] "POST /api/fs/exec HTTP/1.1" 404 29471
35.227.77.1 - - [24/Sep/2026:10:39:27 +0200] "GET /hf0xnwmy4tw5krxyc7j4 HTTP/1.1" 404 30109
35.227.77.1 - - [24/Sep/2026:10:39:30 +0200] "POST /graphql HTTP/1.1" 404 29471
35.227.77.1 - - [24/Sep/2026:10:39:32 +0200] "POST /api/graphql HTTP/1.1" 404 29471
35.227.77.1 - - [24/Sep/2026:10:39:32 +0200] "GET /secrets.json HTTP/1.1" 404 30109
...
show less
Web Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 08:03:33
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.227.77.1 (1.77.227.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 35.227.77.1 (1.77.227.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 04:03:27.261968 2026] [security2:error] [pid 6333:tid 6338] [client 35.227.77.1:52270] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||geekshop.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "geekshop.com"] [uri "/z9x8c7v6b5-debug-trigger-geekshop.com"] [unique_id "arTZTy2rqL5cQHWKF3ICBQAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack