๐บ๐ธ
TPI-Abuse
2026-09-22 12:55:33
(46 seconds ago)
(mod_security) mod_security (id:210730) triggered by 35.229.245.248 (248.245.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.245.248 (248.245.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:55:29.462807 2026] [security2:error] [pid 6749:tid 6749] [client 35.229.245.248:44670] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||495metro.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "495metro.com"] [uri "/z9x8c7v6b5-debug-trigger-495metro.com"] [unique_id "arJ6wUQv8ILgprPZS6YpBAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-22 12:50:03
(6 minutes ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 12:42:10
(14 minutes ago)
[cb-01al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-01al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.229.245.248 - - [22/Sep/2026:14:41:59 +0200] "GET /.env.old HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-22 12:20:15
(36 minutes ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.229.245.248 (TW/Taiwan/248.245.22 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.229.245.248 (TW/Taiwan/248.245.229.35.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐จ๐ฆ
Mediashaker
2026-09-22 10:14:12
(2 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.229.245.248 (TW/T ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.229.245.248 (TW/Taiwan/248.245.229.35.bc.googleusercontent.com)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 09:56:12
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.229.245.248 (248.245.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.245.248 (248.245.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 05:56:05.142766 2026] [security2:error] [pid 2076:tid 2076] [client 35.229.245.248:36732] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||callalbany.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "callalbany.com"] [uri "/z9x8c7v6b5-debug-trigger-callalbany.com"] [unique_id "arJQtQ6s5ypXoBOGDR0bwAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 09:36:05
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.229.245.248 (248.245.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.245.248 (248.245.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 05:35:58.971436 2026] [security2:error] [pid 486792:tid 486792] [client 35.229.245.248:38716] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dynamic-therapy-mn.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dynamic-therapy-mn.com"] [uri "/z9x8c7v6b5-debug-trigger-dynamic-therapy-mn.com"] [unique_id "arJL_j_X4hP4XwwYKDdITAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-22 09:30:46
(3 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 09:16:34
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.229.245.248 (248.245.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.245.248 (248.245.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 05:16:29.711902 2026] [security2:error] [pid 14095:tid 14095] [client 35.229.245.248:53690] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||growtowork.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "growtowork.com"] [uri "/z9x8c7v6b5-debug-trigger-growtowork.com"] [unique_id "arJHbWU4vzGG81eQ0nSk4QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-22 09:10:22
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:40:47
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.229.245.248 (248.245.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.245.248 (248.245.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:40:39.276282 2026] [security2:error] [pid 29761:tid 29761] [client 35.229.245.248:33772] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||micahgartman.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "micahgartman.com"] [uri "/z9x8c7v6b5-debug-trigger-micahgartman.com"] [unique_id "arI_BxYrFkdDL3jewDrXEQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:24:35
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.229.245.248 (248.245.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.229.245.248 (248.245.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:24:28.063293 2026] [security2:error] [pid 12247:tid 12247] [client 35.229.245.248:54842] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||paleopathologist.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "paleopathologist.com"] [uri "/z9x8c7v6b5-debug-trigger-paleopathologist.com"] [unique_id "arI7PJy9_qTv2dpDnj7oZQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:08:35
(4 hours ago)
(mod_security) mod_security (id:210580) triggered by 35.229.245.248 (248.245.229.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 35.229.245.248 (248.245.229.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:08:27.891552 2026] [security2:error] [pid 27829:tid 27829] [client 35.229.245.248:37452] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:vars[1][]. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||riverflow.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:vars[1][]: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "riverflow.com"] [uri "/index.php"] [unique_id "arI3ewFwdqSEvYS-65QtIwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 07:55:28
(5 hours ago)
Banned by Fail2Ban on server
Web App Attack
๐ธ๐ช
vaia.cloud
2026-09-22 07:50:03
(5 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack