Anonymous
2026-10-07 03:30:04
(2 days ago)
CrowdSec decision: crowdsecurity/http-admin-interface-probing (origin: crowdsec)
Web App Attack
๐บ๐ธ
JustMeHere
2026-10-06 19:48:29
(2 days ago)
[Tue Oct 06 15:48:25.132074 2026] [security2:error] [pid 1249:tid 1278] [client 35.229.151.43:49098] ...
show more
[Tue Oct 06 15:48:25.132074 2026] [security2:error] [pid 1249:tid 1278] [client 35.229.151.43:49098] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:blocking_inbound_anomaly_score. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "233"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [ver "OWASP_CRS/4.15.0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "yorknation.com"] [uri "/"] [unique_id "asVQiZGlSUsbYuhhFIDm0gAAAME"]
...
show less
Web App Attack
๐ช๐ธ
robotstxt
2026-10-06 19:45:14
(2 days ago)
35.229.151.43 - - [06/Oct/2026:19:44:47 +0000] "GET /wp-content/plugins/gp-premium/general/js/smooth ...
show more
35.229.151.43 - - [06/Oct/2026:19:44:47 +0000] "GET /wp-content/plugins/gp-premium/general/js/smooth-scroll.min.js?ver=2.5.6 HTTP/2.0" 403 16172 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0" "-" edge="35.229.151.43"
35.229.151.43 - - [06/Oct/2026:19:44:47 +0000] "GET /wp-content/themes/generatepress/assets/js/back-to-top.min.js?ver=3.6.1 HTTP/2.0" 403 16172 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0" "-" edge="35.229.151.43"
35.229.151.43 - - [06/Oct/2026:19:44:47 +0000] "GET /wp-content/themes/generatepress/assets/js/navigation-search.min.js?ver=3.6.1 HTTP/2.0" 403 16172 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0" "-" edge="35.229.151.43"
35.229.151.43 - - [06/Oct/2026:19:44:47 +0000] "GET /wp-content/themes/g
...
show less
Web App Attack
๐ฒ๐พ
Rizzy
2026-10-06 19:24:46
(2 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐น๐ญ
thaizone.com
2026-10-06 19:20:43
(2 days ago)
Brute Force Attack on a Web Resources #1
DDoS Attack
Web Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 18:51:47
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.229.151.43 (43.151.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.151.43 (43.151.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 14:51:44.091449 2026] [security2:error] [pid 29119:tid 29178] [client 35.229.151.43:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||raytbrown.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "raytbrown.com"] [uri "/z9x8c7v6b5-debug-trigger-raytbrown.com"] [unique_id "asVDQBFW7elAZHalk9Kd2QAAANg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-10-06 18:20:05
(2 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
23p02732
2026-10-06 18:18:20
(2 days ago)
Automated web scanning and malicious probing
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-06 18:04:02
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted] 35.229.151.43 (TW/Taiwan/43.151.229.35. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.229.151.43 (TW/Taiwan/43.151.229.35.bc.googleusercontent.com)
show less
SQL Injection
๐ฉ๐ช
yitzhaq
2026-10-06 17:53:50
(2 days ago)
35.229.151.43 - - [06/Oct/2026:19:53:46 +0200] "GET /.env.development?raw HTTP/2.0" 303 390 "-" "CCB ...
show more
35.229.151.43 - - [06/Oct/2026:19:53:46 +0200] "GET /.env.development?raw HTTP/2.0" 303 390 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
35.229.151.43 - - [06/Oct/2026:19:53:46 +0200] "GET /.env.local?.svg?.wasm?init HTTP/2.0" 303 401 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
35.229.151.43 - - [06/Oct/2026:19:53:46 +0200] "GET /.env?.svg?.wasm?init HTTP/2.0" 403 297 "-" "Mozilla/5.0 (compatible; Bytespider; [email]) AppleWebKit/537.36"
35.229.151.43 - - [06/Oct/2026:19:53:46 +0200] "GET /@fs/.env?raw?? HTTP/2.0" 303 382 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
35.229.151.43 - - [06/Oct/2026:19:53:46 +0200] "GET /@fs/root/.env?raw?? HTTP/2.0" 303 389 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
35.229.151.43 - - [06/Oct/2026:19:53:47 +0200] "GET /.env::$DATA?raw HTTP/2.0" 403 320 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Clau
show less
Web App Attack
Hacking
๐ณ๐ฑ
Alt255
2026-10-06 17:53:21
(2 days ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.229.151.43 - - [06/Oct/2026:19:53:10 +0200] "GET /.htpasswd HTTP/2.0" 403 1858 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-06 17:00:29
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฌ๐ง
oja
2026-10-06 16:58:22
(2 days ago)
Aggressive web scanner
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 12:57:45
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.229.151.43 (43.151.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.151.43 (43.151.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 08:57:41.140751 2026] [security2:error] [pid 16306:tid 16306] [client 35.229.151.43:46990] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||petercoadandthecoadsisters.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "petercoadandthecoadsisters.com"] [uri "/z9x8c7v6b5-debug-trigger-petercoadandthecoadsisters.com"] [unique_id "asTwRWHDWV1x-BNAVRaohwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-06 12:54:23
(2 days ago)
Excessive multi-domain requests
Brute-Force