๐ซ๐ท
COMAITE
2026-09-22 12:19:49
(22 minutes ago)
Suspicious URL access.
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-22 11:41:59
(1 hour ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:13:02
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.229.158.15 (15.158.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.158.15 (15.158.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:12:57.867361 2026] [security2:error] [pid 20479:tid 20479] [client 35.229.158.15:44220] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||iplayriichi.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "iplayriichi.com"] [uri "/z9x8c7v6b5-debug-trigger-iplayriichi.com"] [unique_id "arJiuR_W80h6mHRgQtFxywAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 10:55:44
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.229.158.15 (15.158.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.158.15 (15.158.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:55:38.644951 2026] [security2:error] [pid 7649:tid 7649] [client 35.229.158.15:54420] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||isyourcorporationsafe.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "isyourcorporationsafe.com"] [uri "/z9x8c7v6b5-debug-trigger-isyourcorporationsafe.com"] [unique_id "arJeqjyNUJGV9MVIxolWYAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 10:53:25
(1 hour ago)
Banned by Fail2Ban on server
Web App Attack
๐ฌ๐ง
Swiptly
2026-09-22 10:15:23
(2 hours ago)
Excessive 403/404/405 PHP/CMS errors from scanning or broken bots
...
Web App Attack
๐ฉ๐ช
itsolon
2026-09-22 10:14:48
(2 hours ago)
[22/Sep/2026:12:14:48 +0200] 179007208822.624579 35.229.158.15 50254 217.154.7.177 443
[22/Sep/2026: ...
show more
[22/Sep/2026:12:14:48 +0200] 179007208822.624579 35.229.158.15 50254 217.154.7.177 443
[22/Sep/2026:12:14:48 +0200] 179007208896.726772 35.229.158.15 50254 217.154.7.177 443
[22/Sep/2026:12:14:48 +0200] 179007208862.609136 35.229.158.15 50254 217.154.7.177 443
[22/Sep/2026:12:14:48 +0200] 179007208812.315519 35.229.158.15 50254 217.154.7.177 443
[22/Sep/2026:12:14:48 +0200] 179007208817.141099 35.229.158.15 50254 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 09:56:28
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.229.158.15 (15.158.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.158.15 (15.158.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 05:56:23.567632 2026] [security2:error] [pid 19292:tid 19292] [client 35.229.158.15:35642] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jasonpolland.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jasonpolland.com"] [uri "/z9x8c7v6b5-debug-trigger-jasonpolland.com"] [unique_id "arJQx6Oa6fyU3zJy8qcM2wAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
svr
2026-09-22 09:52:51
(2 hours ago)
Abusive Automated Web Scanner
Web App Attack
๐บ๐ธ
jcbriar
2026-09-22 09:51:44
(2 hours ago)
Searching for vulnerable scripts
Hacking
Web App Attack
๐ช๐ธ
masterguru
2026-09-22 09:41:12
(3 hours ago)
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110- ...
show more
Inbound Anomaly Score Exceeded (Total Score: 5). Operator GE matched 5 at TX:anomaly_score. (949110-122)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 09:35:52
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.229.158.15 (15.158.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.158.15 (15.158.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 05:35:48.005128 2026] [security2:error] [pid 7786:tid 7786] [client 35.229.158.15:40362] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jfexpressfr8.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jfexpressfr8.com"] [uri "/z9x8c7v6b5-debug-trigger-jfexpressfr8.com"] [unique_id "arJL9CVVPWR8TRv0BMlsFgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 09:18:58
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.229.158.15 (15.158.229.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.158.15 (15.158.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 05:18:50.174804 2026] [security2:error] [pid 5912:tid 5912] [client 35.229.158.15:60468] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||john-bell-associates.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "john-bell-associates.com"] [uri "/z9x8c7v6b5-debug-trigger-john-bell-associates.com"] [unique_id "arJH-mcoW3Ql-M98rnLr4AAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
netclix.gr
2026-09-22 09:17:04
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.229.158.15 (TW/Taiwan/15.158.229.35. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.229.158.15 (TW/Taiwan/15.158.229.35.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐ฉ๐ช
konseptit
2026-09-22 09:00:50
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.229.158.15 (TW/Taiwan/15.158.229.35. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.229.158.15 (TW/Taiwan/15.158.229.35.bc.googleusercontent.com)
show less
SQL Injection