๐บ๐ธ
MPL
2026-09-16 06:25:54
(2 days ago)
tcp ports: 80,443 (16 or more attempts)
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-16 03:03:45
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.232.121.153 (153.121.232.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.232.121.153 (153.121.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 23:03:38.181554 2026] [security2:error] [pid 29293:tid 29416] [client 35.232.121.153:33440] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wwwhst.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wwwhst.com"] [uri "/z9x8c7v6b5-debug-trigger-wwwhst.com"] [unique_id "aqoHCjYUWgpLNDe5-dcvnAAAAk0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 01:53:52
(2 days ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:21:57
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.232.121.153 (153.121.232.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.232.121.153 (153.121.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:21:50.612166 2026] [security2:error] [pid 21062:tid 21085] [client 35.232.121.153:55642] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thebiglies.com"] [uri "/.git/config"] [unique_id "aqnvLoBvZTU6ferFYi1zNwAAARQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 01:03:29
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 35.232.121.153 (153.121.232.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.232.121.153 (153.121.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 21:03:25.538365 2026] [security2:error] [pid 32168:tid 32168] [client 35.232.121.153:48424] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "starrmail.net"] [uri "/@fs/.env"] [unique_id "aqnq3Zmtt6GEN1PKW4JWpAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-09-16 01:03:09
(2 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐บ๐ธ
jormaster3k
2026-09-16 00:54:29
(2 days ago)
Attack against Apache (too many 404s)
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-16 00:39:33
(2 days ago)
20 attempts against mh-misbehave-ban on burne
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-16 00:20:47
(2 days ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
e.fierstra
2026-09-16 00:09:12
(2 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
Alt255
2026-09-15 23:55:53
(2 days ago)
[cb-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.232.121.153 - - [16/Sep/2026:01:55:52 +0200] "GET /assets../.env HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 22:19:07
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.232.121.153 (153.121.232.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.232.121.153 (153.121.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:19:01.829465 2026] [security2:error] [pid 22385:tid 22385] [client 35.232.121.153:53248] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||growtowork.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "growtowork.com"] [uri "/z9x8c7v6b5-debug-trigger-growtowork.com"] [unique_id "aqnEVTmvsl2sBw5rniXsnwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
FeG Deutschland
2026-09-15 21:56:14
(2 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1247
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:38:23
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.232.121.153 (153.121.232.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.232.121.153 (153.121.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:38:19.474980 2026] [security2:error] [pid 1611461:tid 1611461] [client 35.232.121.153:55428] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dynamic-therapy-mn.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dynamic-therapy-mn.com"] [uri "/z9x8c7v6b5-debug-trigger-dynamic-therapy-mn.com"] [unique_id "aqm6y_SBRfjGhsORbVn9QwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack