๐ณ๐ฑ
Site.eu
2026-09-16 19:13:05
(2 days ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-16 04:09:38
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.232.224.70 (70.224.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.232.224.70 (70.224.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 00:09:31.408446 2026] [security2:error] [pid 1261:tid 1261] [client 35.232.224.70:35950] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "swampoodlegrounds.com"] [uri "/appearance/../../.env"] [unique_id "aqoWe60qqyKPnYEDYNB2vAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
HostingGroup
2026-09-16 04:06:53
(3 days ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 9. First blocked: 2026-09-16.
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-16 03:21:24
(3 days ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ฉ๐ช
TheDjRider
2026-09-16 03:19:32
(3 days ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-09-16T03:19:29.692134158Z. Context: http_status=200
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 02:07:45
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.232.224.70 (70.224.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.232.224.70 (70.224.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 22:07:40.339912 2026] [security2:error] [pid 16336:tid 16413] [client 35.232.224.70:59142] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kylight.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kylight.com"] [uri "/z9x8c7v6b5-debug-trigger-kylight.com"] [unique_id "aqn57FBvSv77vTaAGXQT_QAAAYE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 00:20:12
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.232.224.70 (70.224.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.232.224.70 (70.224.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:20:05.498128 2026] [security2:error] [pid 20797:tid 20797] [client 35.232.224.70:50426] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "flyingdodopublications.com"] [uri "/js../.env"] [unique_id "aqngtYHWL2Og9fkYwSWnpAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-16 00:02:04
(3 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-15 23:23:33
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.232.224.70 (70.224.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.232.224.70 (70.224.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 19:23:29.269833 2026] [security2:error] [pid 26858:tid 26858] [client 35.232.224.70:42144] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.svn/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "daisydoesoap.com"] [uri "/.svn/entries"] [unique_id "aqnTcThnS-QLtZPwqiREXAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 22:54:38
(3 days ago)
(mod_security) mod_security (id:210580) triggered by 35.232.224.70 (70.224.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210580) triggered by 35.232.224.70 (70.224.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:54:32.000952 2026] [security2:error] [pid 21851:tid 21851] [client 35.232.224.70:51180] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||ciid.info|F|2"] [data "Matched Data: proc/self/environ found within ARGS:filename: file:/proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "ciid.info"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqnMp8_GY0OszjCFb8Y0dQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 22:09:16
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.232.224.70 (70.224.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.232.224.70 (70.224.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:09:08.847191 2026] [security2:error] [pid 25081:tid 25081] [client 35.232.224.70:58514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "banis-associates.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "aqnCBByYO6CIj7hGw95cswAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:45:23
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.232.224.70 (70.224.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.232.224.70 (70.224.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:45:17.332071 2026] [security2:error] [pid 20963:tid 21020] [client 35.232.224.70:50170] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "appraisalteam.net"] [uri "/%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env"] [unique_id "aqm8bYYJeNiXD5h9WRUgKwAAAgA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
big-cloud.nl
2026-09-15 20:56:46
(3 days ago)
Try to access /.aws/credentials
Web App Attack
๐จ๐ฆ
Mediashaker
2026-09-15 20:10:33
(3 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.232.224.70 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.232.224.70 (US/United States/70.224.232.35.bc.googleusercontent.com)
show less
Bad Web Bot
Anonymous
2026-09-15 17:16:09
(3 days ago)
LogGuard auto-report | score=75 | flags=flood | reasons=[+15] burst_10s_suspicious: 95 req in 10s (t ...
show more
LogGuard auto-report | score=75 | flags=flood | reasons=[+15] burst_10s_suspicious: 95 req in 10s (threshold 50); [+10] error_ratio_suspicious: 75% error rate in 60s (71/95); [+25] path_diversity_severe: 83 unique paths in 60s (threshold 50); [+25] probe_paths: Hit 33 known probe paths: /.env, /.env.development, /.env.docker, /.env.js, /.env.local
show less
DDoS Attack