Anonymous
2026-09-30 04:19:58
(7 hours ago)
Aggressive web scan
Web App Attack
π³π±
Savvii
2026-09-30 03:45:31
(8 hours ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 03:28:51
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.234.46.148 (148.46.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.46.148 (148.46.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:28:45.712818 2026] [security2:error] [pid 20876:tid 20876] [client 35.234.46.148:49064] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||teamsewusa.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "teamsewusa.com"] [uri "/z9x8c7v6b5-debug-trigger-teamsewusa.com"] [unique_id "aryB7dYlxCEBORuewUfWKQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 02:41:17
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.234.46.148 (148.46.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.46.148 (148.46.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:41:13.875755 2026] [security2:error] [pid 29452:tid 29452] [client 35.234.46.148:55946] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||teenybikini.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "teenybikini.com"] [uri "/z9x8c7v6b5-debug-trigger-teenybikini.com"] [unique_id "arx2ybXEw1caeTdvaH2tQQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 02:04:44
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.234.46.148 (148.46.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.46.148 (148.46.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:04:39.457781 2026] [security2:error] [pid 10179:tid 10179] [client 35.234.46.148:45366] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||swwpccpa.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "swwpccpa.com"] [uri "/z9x8c7v6b5-debug-trigger-swwpccpa.com"] [unique_id "arxuN5hWlZHPQx6vdyiJSgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
maxpower
2026-09-30 01:54:10
(9 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.234.46.148 (TW/Taiwan/148.46.234.35.b ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.234.46.148 (TW/Taiwan/148.46.234.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.234.46.148 - - [30/Sep/2026:03:54:08 +0200] "GET /@fs/root/.aws/credentials?raw?? HTTP/2.0" 200 11989 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "-" host=tecnousatopescara.it
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-09-30 01:46:05
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.46.148 (148.46.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.46.148 (148.46.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:45:59.276173 2026] [security2:error] [pid 12815:tid 12815] [client 35.234.46.148:45954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tech-support.biz"] [uri "/.env"] [unique_id "arxp1x4EoEytXmh_k2eRXQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2026-09-30 01:39:04
(10 hours ago)
427 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-30 00:29:45
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.234.46.148 (148.46.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.46.148 (148.46.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:29:41.125175 2026] [security2:error] [pid 12845:tid 12845] [client 35.234.46.148:46908] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tell-me-first.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tell-me-first.com"] [uri "/z9x8c7v6b5-debug-trigger-tell-me-first.com"] [unique_id "arxX9Q1IVxsE_qhyXloWegAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 23:38:04
(12 hours ago)
35.234.46.148 - - [29/Sep/2026:20:38:02 -0300] "GET /.env.prod HTTP/2.0" 444 0 "-" "Mozilla/5.0 (com ...
show more
35.234.46.148 - - [29/Sep/2026:20:38:02 -0300] "GET /.env.prod HTTP/2.0" 444 0 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
35.234.46.148 - - [29/Sep/2026:20:38:03 -0300] "GET /.env.example HTTP/2.0" 444 0 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)"
35.234.46.148 - - [29/Sep/2026:20:38:03 -0300] "GET /.env HTTP/2.0" 444 0 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
35.234.46.148 - - [29/Sep/2026:20:38:03 -0300] "GET /.env.local HTTP/2.0" 444 0 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
35.234.46.148 - - [29/Sep/2026:20:38:03 -0300] "GET /.env.production HTTP/2.0" 444 0 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
...
show less
Port Scan
πΊπΈ
TPI-Abuse
2026-09-29 23:27:06
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.46.148 (148.46.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.46.148 (148.46.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:26:59.159539 2026] [security2:error] [pid 30031:tid 30031] [client 35.234.46.148:39270] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "tcmu.org"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "arxJQ3Az2YHOatBsXRX8UwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
pscriptos
2026-09-29 23:09:07
(12 hours ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
π³π±
Site.eu
2026-09-29 22:55:52
(12 hours ago)
Excessive multi-domain requests
Brute-Force
π¬π§
Celtic
2026-09-29 22:53:41
(12 hours ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
πΈπͺ
vaia.cloud
2026-09-29 21:50:01
(14 hours ago)
crowdsecurity/http-cve-2021-41773
Brute-Force
Web App Attack