🇧🇪
cmbplf
2026-09-07 01:40:14
(6 hours ago)
108 requests with url.path *.ssh/*
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-07 00:27:10
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.234.41.167 (167.41.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.41.167 (167.41.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 20:27:05.657461 2026] [security2:error] [pid 2044:tid 2044] [client 35.234.41.167:48740] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.rassehundeverein.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.rassehundeverein.com"] [uri "/rclone.conf"] [unique_id "ap4E2e_n_LP0I7ZMJRS4KAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇸🇪
SkyDancer
2026-09-07 00:06:03
(7 hours ago)
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by Sk ...
show more
Multiple unauthorized attempts to access using wrong credentials. Attack automatically blocked by SkyDancer Ai. EXT-SYS-Vx
show less
Hacking
Brute-Force
SSH
🇺🇸
TPI-Abuse
2026-09-06 23:56:14
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.234.41.167 (167.41.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.41.167 (167.41.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 19:56:09.748346 2026] [security2:error] [pid 17658:tid 17658] [client 35.234.41.167:52114] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||honeybeeplace.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "honeybeeplace.com"] [uri "/rclone.conf"] [unique_id "ap39mSVj9Y1wCYE4Ykz6cwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
FeG Deutschland
2026-09-06 23:37:14
(8 hours ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 1248
Exploited Host
Web App Attack
🇳🇱
enpepet
2026-09-06 22:49:22
(9 hours ago)
GENERAL: parametres: [url:git=] UA:Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Ch ...
show more
GENERAL: parametres: [url:git=] UA:Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ChatGPT-User/1.0; +https://openai.com/bot) URL:/.git/config
show less
Port Scan
Hacking
Brute-Force
Bad Web Bot
🇳🇱
Site.eu
2026-09-06 22:46:13
(9 hours ago)
Excessive multi-domain requests
Brute-Force
🇺🇸
TPI-Abuse
2026-09-06 22:43:36
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.41.167 (167.41.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.41.167 (167.41.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:43:30.233187 2026] [security2:error] [pid 23013:tid 23013] [client 35.234.41.167:40242] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "veneye.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "ap3skmzQHyjDnCrTJ9njvwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
Feelautom
2026-09-06 22:39:47
(9 hours ago)
[FeelAutom Auto-Ban] BotIdentityRotation: /id_ed25519 (Score: 266)
Hacking
🇧🇷
Halux
2026-09-06 22:17:26
(9 hours ago)
35.234.41.167 Probing protected path or service
Web App Attack
🇳🇱
homeshowdomain.nl
2026-09-06 22:00:29
(9 hours ago)
Auto-ban: >3000 req/min op 2026-09-06
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-09-06 21:20:43
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.234.41.167 (167.41.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.41.167 (167.41.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 17:20:36.691451 2026] [security2:error] [pid 18149:tid 18149] [client 35.234.41.167:37482] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mqyr.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mqyr.com"] [uri "/z9x8c7v6b5-debug-trigger-mqyr.com"] [unique_id "ap3ZJAcS1XVs_dhE133cHgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 20:40:33
(11 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.41.167 (167.41.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.41.167 (167.41.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:40:29.884808 2026] [security2:error] [pid 26884:tid 26884] [client 35.234.41.167:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "perl-photo.com"] [uri "/.git/config"] [unique_id "ap3PveCDE2PmEQCWkoHnIQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
WeCloudit-Anti-Abuse
2026-09-06 20:09:13
(11 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
Anonymous
2026-09-06 19:06:11
(12 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack