๐ง๐ช
cmbplf
2026-09-24 08:08:13
(1 day ago)
2.246 requests from abuseipdb.com blacklisted IP (4mos3w4d)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-24 07:48:05
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.234.51.245 (245.51.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.51.245 (245.51.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 03:47:56.722016 2026] [security2:error] [pid 29049:tid 29049] [client 35.234.51.245:44178] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.yourbrandhere.com|F|2"] [data ".yourbrandhere.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.yourbrandhere.com"] [uri "/z9x8c7v6b5-debug-trigger-www.yourbrandhere.com"] [unique_id "arTVrJxvaMenrCLsM_Rt7wAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ท
ferique
2026-09-24 07:13:05
(1 day ago)
Real-time Intercept: DNN_AUTH attack. Reference: 2026-09-24 10:12:53.8517 Login failure: 35.234.51. ...
show more
Real-time Intercept: DNN_AUTH attack. Reference: 2026-09-24 10:12:53.8517 Login failure: 35.234.51.245 DNN_AUTH
show less
Web App Attack
Bad Web Bot
๐ซ๐ฎ
paissangroup
2026-09-24 03:47:47
(1 day ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
consul.to
2026-09-24 03:11:52
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-24 02:06:28
(1 day ago)
malicious scanning tool activity
Web App Attack
๐ฌ๐ง
andypiper
2026-09-24 01:00:23
(1 day ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 00:50:52
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.234.51.245 (245.51.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.51.245 (245.51.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 20:50:48.612399 2026] [security2:error] [pid 29510:tid 29510] [client 35.234.51.245:41074] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||yeswecanfruitsandvegetables.vanemby.com|F|2"] [data ".vanemby.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "yeswecanfruitsandvegetables.vanemby.com"] [uri "/z9x8c7v6b5-debug-trigger-yeswecanfruitsandvegetables.vanemby.com"] [unique_id "arRz6EMQ8f6iMWFnmc8WewAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-24 00:16:45
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.234.51.245 (TW/Taiwan/245.51.234. ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.234.51.245 (TW/Taiwan/245.51.234.35.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-23 22:11:30
(1 day ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-23 22:02:45
(1 day ago)
git/env leak probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 21:53:06
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.234.51.245 (245.51.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.51.245 (245.51.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:53:00.068062 2026] [security2:error] [pid 32193:tid 32253] [client 35.234.51.245:56770] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||credit-card-cap.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "credit-card-cap.com"] [uri "/z9x8c7v6b5-debug-trigger-credit-card-cap.com"] [unique_id "arRKPN_9WU-96geH2uRv1wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
beon
2026-09-23 21:38:40
(1 day ago)
[DateTime=>2026-09-23T21:38:40Z to 2026-09-23T21:38:59Z (UTC)] , [HoneyPot_Hits=>90 times] , [HoneyP ...
show more
[DateTime=>2026-09-23T21:38:40Z to 2026-09-23T21:38:59Z (UTC)] , [HoneyPot_Hits=>90 times] , [HoneyPots=>/wp-json, /.env.old, /.env.prod, /.env.save, /api/.env, /backend/.env and others] , [irregular_query_Hits=>35 times] , [404targets=>/asset-manifest.json, /static/manifest.json, /manifest.json, /mkvx3g77z9adbw0ioebt, /dist/manifest.json, /webpack-stats.json and others] , [total_Hits=>196 times] , [hit_per_second=>10.31] , [Keyword=>WordPress, Laravel, PHP web shells, irregular query]
show less
Bad Web Bot
Web App Attack
Hacking
๐ฉ๐ช
bazter.pro
2026-09-23 21:34:16
(1 day ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 21:29:12
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 35.234.51.245 (245.51.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:949110) triggered by 35.234.51.245 (245.51.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 17:29:09.181045 2026] [security2:error] [pid 17217:tid 17217] [client 35.234.51.245:50800] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "hamiltonbookings.com"] [uri "/z9x8c7v6b5-debug-trigger-hamiltonbookings.com"] [unique_id "arREpUVN-C4XqXVMmLi4MAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack