๐ฌ๐ง
abivia
2026-09-23 03:07:33
(13 hours ago)
Abivia WAF trigger: Rule scriptKiddies: Credential probing uri: /manifest.json
Hacking
๐จ๐ฆ
Mediashaker
2026-09-23 02:56:14
(13 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.229.136.113 (TW/T ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.229.136.113 (TW/Taiwan/113.136.229.35.bc.googleusercontent.com)
show less
Bad Web Bot
๐ฉ๐ช
bazter.pro
2026-09-22 22:19:25
(18 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ฌ๐ง
abivia
2026-09-22 22:08:35
(18 hours ago)
Abivia WAF trigger: Rule scriptKiddies: Credential probing uri: /dist/manifest.json
Hacking
๐บ๐ธ
oralunal
2026-09-22 21:35:28
(19 hours ago)
IP banned by Fail2Ban in jail ah-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-22 19:32:38
(21 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:35:15
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.229.136.113 (113.136.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.136.113 (113.136.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:35:07.772563 2026] [security2:error] [pid 4946:tid 4946] [client 35.229.136.113:59702] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||berklie.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "berklie.com"] [uri "/z9x8c7v6b5-debug-trigger-berklie.com"] [unique_id "arK8SxXCd2szO1bGtMmQegAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 16:08:36
(1 day ago)
Blocked by ModSec and CSF
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-22 16:00:53
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.229.136.113 (113.136.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.229.136.113 (113.136.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:00:50.329894 2026] [security2:error] [pid 8312:tid 8312] [client 35.229.136.113:36434] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brandsmedia.com"] [uri "/wp-config.php.old"] [unique_id "arKmMjt_kLvToWc3C054qgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
magnetosphere-tarpit
2026-09-22 15:26:42
(1 day ago)
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not ...
show more
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not exist on this host. Tarpitted, then banned: 10 requests within 24h0m0s
show less
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:43:30
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.229.136.113 (113.136.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.136.113 (113.136.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:43:23.837290 2026] [security2:error] [pid 10627:tid 10627] [client 35.229.136.113:36088] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||capitalacc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "capitalacc.com"] [uri "/z9x8c7v6b5-debug-trigger-capitalacc.com"] [unique_id "arKUC1-b2e3IzarSdGbb3AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:57:50
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.229.136.113 (113.136.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.136.113 (113.136.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:57:44.088930 2026] [security2:error] [pid 27127:tid 27127] [client 35.229.136.113:41478] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||celebritybikinigossip.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "celebritybikinigossip.com"] [uri "/z9x8c7v6b5-debug-trigger-celebritybikinigossip.com"] [unique_id "arKJWJiDFXT_Ennpt22vkQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:28:04
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.229.136.113 (113.136.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.136.113 (113.136.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:27:58.701334 2026] [security2:error] [pid 8169:tid 8169] [client 35.229.136.113:57104] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cherylpelletier.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cherylpelletier.com"] [uri "/z9x8c7v6b5-debug-trigger-cherylpelletier.com"] [unique_id "arKCXrSYhOEy8vBsz-MUjwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:45:59
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.229.136.113 (113.136.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.136.113 (113.136.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:45:55.225533 2026] [security2:error] [pid 10365:tid 10365] [client 35.229.136.113:53350] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||clossglobal.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "clossglobal.com"] [uri "/z9x8c7v6b5-debug-trigger-clossglobal.com"] [unique_id "arJ4gxmDM0G86ph0CvhSNgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
abivia
2026-09-22 12:41:45
(1 day ago)
Abivia WAF trigger: Rule scriptKiddies: Credential probing uri: /asset-manifest.json
Hacking