๐บ๐ธ
TPI-Abuse
2026-09-22 17:03:34
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.231.26.5 (5.26.231.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.26.5 (5.26.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:03:29.566107 2026] [security2:error] [pid 15727:tid 15727] [client 35.231.26.5:39394] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||creareformis.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "creareformis.com"] [uri "/z9x8c7v6b5-debug-trigger-creareformis.com"] [unique_id "arK04ZW_4TSFOcr5VoYWNwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 16:25:10
(2 hours ago)
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-30al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.231.26.5 - - [22/Sep/2026:18:25:09 +0200] "GET /@fs/../.env?raw?? HTTP/2.0" 301 527 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:45:56
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.231.26.5 (5.26.231.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.26.5 (5.26.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:45:49.498001 2026] [security2:error] [pid 15147:tid 15147] [client 35.231.26.5:46630] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||creektech.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "creektech.com"] [uri "/z9x8c7v6b5-debug-trigger-creektech.com"] [unique_id "arKirfNUAydbVm8w_-GDrgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Petros Stefanakis
2026-09-22 15:29:00
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.231.26.5 (US/United States/5.26.231. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.231.26.5 (US/United States/5.26.231.35.bc.googleusercontent.com)
show less
SQL Injection
๐ซ๐ฎ
Christopher Hughes
2026-09-22 15:19:33
(3 hours ago)
35.231.26.5 - - [22/Sep/2026:16:19:32 +0100] "GET /@fs/app/.env?raw?? HTTP/2.0" 200 6011 "-" "Mozill ...
show more
35.231.26.5 - - [22/Sep/2026:16:19:32 +0100] "GET /@fs/app/.env?raw?? HTTP/2.0" 200 6011 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-22 15:04:58
(3 hours ago)
Web scanning / probing for vulnerable paths | URL: /.git/config | Evidence: www.crisalidatours.com 3 ...
show more
Web scanning / probing for vulnerable paths | URL: /.git/config | Evidence: www.crisalidatours.com 35.231.26.5 - - [22/Sep/2026:17:04:41 +0200] \"GET /.git/config HTTP/1.1\" 404 4019 \"-\" \"Mozilla/5.0 (compatible; Bytespider; [email]) AppleWebKit/537.36\" GEOIP_COUNTRY_CODE=US | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
๐จ๐ท
Klicks
2026-09-22 14:54:00
(3 hours ago)
Request URL: https://1.com:443/trace.axd
Request path: /trace.axd
User host addres ...
show more
Request URL: https://1.com:443/trace.axd
Request path: /trace.axd
User host address: 35.231.26.5
show less
Bad Web Bot
Web App Attack
Web Spam
๐บ๐ธ
TPI-Abuse
2026-09-22 14:46:30
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.231.26.5 (5.26.231.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210730) triggered by 35.231.26.5 (5.26.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:46:26.102546 2026] [security2:error] [pid 6155:tid 6155] [client 35.231.26.5:46070] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||criticalmassofficial.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "criticalmassofficial.com"] [uri "/z9x8c7v6b5-debug-trigger-criticalmassofficial.com"] [unique_id "arKUwoKtkQOgJCjwFg61fwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-09-22 14:25:34
(4 hours ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-22 13:17:43
(5 hours ago)
35.231.26.5 - - [22/Sep/2026:15:17:34 +0200] "GET /z9x8c7v6b5-debug-trigger-crypcool.com HTTP/1.1" 4 ...
show more
35.231.26.5 - - [22/Sep/2026:15:17:34 +0200] "GET /z9x8c7v6b5-debug-trigger-crypcool.com HTTP/1.1" 404 30044
35.231.26.5 - - [22/Sep/2026:15:17:34 +0200] "GET /dist/manifest.json HTTP/1.1" 404 30044
35.231.26.5 - - [22/Sep/2026:15:17:34 +0200] "GET /yoab3k7rxzr05rtf2n2o HTTP/1.1" 404 30044
35.231.26.5 - - [22/Sep/2026:15:17:34 +0200] "GET /dist/.vite/manifest.json HTTP/1.1" 404 30044
35.231.26.5 - - [22/Sep/2026:15:17:34 +0200] "GET /z775g2t1q5mntf41gby9 HTTP/1.1" 404 30044
35.231.26.5 - - [22/Sep/2026:15:17:34 +0200] "GET /build/manifest.json HTTP/1.1" 404 30044
35.231.26.5 - - [22/Sep/2026:15:17:34 +0200] "POST /api/fs/exec HTTP/1.1" 404 29409
35.231.26.5 - - [22/Sep/2026:15:17:36 +0200] "POST /graphql HTTP/1.1" 404 29409
35.231.26.5 - - [22/Sep/2026:15:17:39 +0200] "GET /@fs/..%252f..%252f..%252f..%252f..%252fproc/self/environ?raw?? HTTP/1.1" 404 27869
35.231.26.5 - - [22/Sep/2026:15:17:39 +0200] "GET /secrets.yml HTTP/1.1" 404 30044
...
show less
Web Spam
Web App Attack
Anonymous
2026-09-22 12:50:04
(5 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-22 12:33:05
(5 hours ago)
(mod_security) mod_security (id:210580) triggered by 35.231.26.5 (5.26.231.35.bc.googleusercontent.c ...
show more
(mod_security) mod_security (id:210580) triggered by 35.231.26.5 (5.26.231.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:32:58.812664 2026] [security2:error] [pid 25598:tid 25598] [client 35.231.26.5:40752] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||csiwebdesigns.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "csiwebdesigns.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "arJ1ekB57pCr5o5O2ULSuQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-09-22 12:09:46
(6 hours ago)
[ISILIA Protection v2.3] Tentative d'accรจs: /config/.env [RATE LIMITED - 1800s quarantine] | Pays: U ...
show more
[ISILIA Protection v2.3] Tentative d'accรจs: /config/.env [RATE LIMITED - 1800s quarantine] | Pays: US | UA: Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; +claudebot@anthropic
show less
Hacking
Web App Attack
๐บ๐ธ
mnsf
2026-09-22 12:05:37
(6 hours ago)
Too many Status 40X (18)
Brute-Force
Web App Attack
๐ฌ๐ง
consul.to
2026-09-22 12:00:58
(6 hours ago)
Web attack/malicious scanning detected
Web App Attack