๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-23 02:23:06
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.230.64.70 (70.64.230.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.230.64.70 (70.64.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 22:22:58.551194 2026] [security2:error] [pid 12304:tid 12304] [client 35.230.64.70:56184] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.avilade.com|F|2"] [data ".avilade.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.avilade.com"] [uri "/z9x8c7v6b5-debug-trigger-www.avilade.com"] [unique_id "arM4AjcTRvriBymLK8iQAQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Philister11
2026-09-23 02:16:42
(1 day ago)
CrowdSec: crowdsecurity/thinkphp-cve-2018-20062 (US/AS396982)
Web App Attack
Hacking
Anonymous
2026-09-23 01:22:01
(1 day ago)
35.230.64.70 - - [22/Sep/2026:16:49:37 +0200] "GET /.env.old HTTP/2.0" 403 317 "https://awo425.com/. ...
show more
35.230.64.70 - - [22/Sep/2026:16:49:37 +0200] "GET /.env.old HTTP/2.0" 403 317 "https://awo425.com/.env.old" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 23:09:46
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.230.64.70 (70.64.230.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.230.64.70 (70.64.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 19:09:39.108489 2026] [security2:error] [pid 7092:tid 7092] [client 35.230.64.70:56528] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.austli.com|F|2"] [data ".austli.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.austli.com"] [uri "/z9x8c7v6b5-debug-trigger-www.austli.com"] [unique_id "arMKsyOYUz5R1962iSXp2AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 22:17:14
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.230.64.70 (70.64.230.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.230.64.70 (70.64.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:17:09.545520 2026] [security2:error] [pid 1407829:tid 1407829] [client 35.230.64.70:49958] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.aupapierjaponais.com|F|2"] [data ".aupapierjaponais.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.aupapierjaponais.com"] [uri "/z9x8c7v6b5-debug-trigger-www.aupapierjaponais.com"] [unique_id "arL-ZY0NgoZbwUuXKtXaSwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
SCHAPPY
2026-09-22 20:59:05
(2 days ago)
Malicious activity from IP detected: crowdsecurity/http-probing.
Web App Attack
Hacking
๐ฉ๐ช
SCHAPPY
2026-09-22 20:33:02
(2 days ago)
Bad bot identified by user agent
Bad Web Bot
๐จ๐ฆ
Mediashaker
2026-09-22 20:29:28
(2 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.230.64.70 (US/Uni ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.230.64.70 (US/United States/70.64.230.35.bc.googleusercontent.com)
show less
Bad Web Bot
๐ณ๐ฑ
ConsulHosting
2026-09-22 20:03:14
(2 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 19:27:21
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.230.64.70 (70.64.230.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.230.64.70 (70.64.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:27:15.430024 2026] [security2:error] [pid 13895:tid 13895] [client 35.230.64.70:33252] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||auditleverage.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "auditleverage.com"] [uri "/z9x8c7v6b5-debug-trigger-auditleverage.com"] [unique_id "arLWk2LBZFJnE8NFFdO7KgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
augustseo
2026-09-22 19:06:26
(2 days ago)
155 exploit-probe requests, each answered 403; 74 requests over the 240/min ceiling, answered 429 be ...
show more
155 exploit-probe requests, each answered 403; 74 requests over the 240/min ceiling, answered 429 between 2026-09-22T19:06:26Z and 2026-09-22T19:06:26Z.
Signatures: secret-file x91, credential-hunt x19, path-traversal x17, server-script x10, scanner-endpoint x8, ssrf x4
Paths: /.env /api/config/ /@fs/app/.env /@fs/src/.env /graphql/ /v1/graphql/ /api/graphql/ /i.php
User agent: Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)
Query strings omitted. Timestamp is the last hit observed.
show less
DDoS Attack
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-22 19:01:34
(2 days ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ฆ๐บ
A.i.D.A.N.N
2026-09-22 18:26:56
(2 days ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web vulnerability scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:08:25
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.230.64.70 (70.64.230.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.230.64.70 (70.64.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:08:18.182597 2026] [security2:error] [pid 17059:tid 17340] [client 35.230.64.70:46652] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||australialifecoach.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "australialifecoach.com"] [uri "/z9x8c7v6b5-debug-trigger-australialifecoach.com"] [unique_id "arLEEuHqF5Pf3Y9511nfoAAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack