Anonymous
2026-10-05 06:51:06
(4 hours ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
π¦πΊ
rubixstudios
2026-10-05 05:52:02
(5 hours ago)
Excessive HTTP requests consistent with automated attack behaviour detected by Imunify360
DDoS Attack
Brute-Force
Web App Attack
π§πͺ
cmbplf
2026-10-05 05:06:22
(6 hours ago)
379 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
π³π±
Site.eu
2026-10-05 04:19:03
(6 hours ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-10-05 04:16:01
(6 hours ago)
Blocked by ModSec and CSF
Port Scan
πΊπΈ
TPI-Abuse
2026-10-05 04:13:38
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.234.65.195 (195.65.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.65.195 (195.65.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 00:13:34.599337 2026] [security2:error] [pid 498:tid 498] [client 35.234.65.195:49772] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bostonscience.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bostonscience.com"] [uri "/z9x8c7v6b5-debug-trigger-bostonscience.com"] [unique_id "asMj7ojteHPZSlEHWpavZAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
robotstxt
2026-10-05 03:49:55
(7 hours ago)
35.234.65.195 - - [05/Oct/2026:03:49:42 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 36348 "-" "Mo ...
show more
35.234.65.195 - - [05/Oct/2026:03:49:42 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 36348 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "35.234.65.195" edge="162.159.106.182"
35.234.65.195 - - [05/Oct/2026:03:49:45 +0000] "GET /.npmrc HTTP/2.0" 403 2 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" "35.234.65.195" edge="172.68.192.132"
35.234.65.195 - - [05/Oct/2026:03:49:46 +0000] "GET /.ssh/config HTTP/2.0" 403 36351 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "35.234.65.195" edge="172.68.192.132"
35.234.65.195 - - [05/Oct/2026:03:49:46 +0000] "GET /.zshrc HTTP/2.0" 403 2 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)" "35.234.65.195" edge="172.68.192.132"
35.234.65.195 - - [05/Oct/2026:03:49:47 +0000] "GET /@fs/home/ec2-user/.aws/credentials?raw?? HTTP/2.0" 403 36350
...
show less
Web App Attack
π«π·
Stara
2026-10-05 03:33:43
(7 hours ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 03:33:00
(7 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.234.65.195 (195.65.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.65.195 (195.65.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 23:32:56.884522 2026] [security2:error] [pid 32752:tid 32752] [client 35.234.65.195:39618] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||bikiniwatersports.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bikiniwatersports.com"] [uri "/z9x8c7v6b5-debug-trigger-bikiniwatersports.com"] [unique_id "asMaaKkUE_OVxx1GWPx6XwAAAGc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π·πΈ
pexodelic
2026-10-05 03:05:03
(8 hours ago)
Automated report from web, SSH and FTP server logs: 56 requests probing for exposed secrets (.env, . ...
show more
Automated report from web, SSH and FTP server logs: 56 requests probing for exposed secrets (.env, .git, config files). First reported 2026-10-05 04:05 UTC, last reported 2026-10-05 05:05 UTC; counts cover the current log rotation window.
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 02:54:07
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.234.65.195 (195.65.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.65.195 (195.65.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 22:54:04.167874 2026] [security2:error] [pid 26169:tid 26169] [client 35.234.65.195:44044] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||be4ventures.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "be4ventures.com"] [uri "/z9x8c7v6b5-debug-trigger-be4ventures.com"] [unique_id "asMRTBjG8w7poF8dMC5QBwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 01:21:34
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.234.65.195 (195.65.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.234.65.195 (195.65.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 21:21:26.848274 2026] [security2:error] [pid 8330:tid 8330] [client 35.234.65.195:36606] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aroilcontrolsystem.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aroilcontrolsystem.com"] [uri "/z9x8c7v6b5-debug-trigger-aroilcontrolsystem.com"] [unique_id "asL7lsUnE-kBNkkoiiobMgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-10-05 01:14:09
(9 hours ago)
Excessive 404/403 errors
Brute-Force
πΊπΈ
TPI-Abuse
2026-10-05 00:41:55
(10 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.234.65.195 (195.65.234.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.234.65.195 (195.65.234.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 20:41:49.408578 2026] [security2:error] [pid 5320:tid 5320] [client 35.234.65.195:43606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "andysharp.com"] [uri "/css../.env"] [unique_id "asLyTR8nPHxFtAta7UJ2gQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
oralunal
2026-10-05 00:35:48
(10 hours ago)
IP banned by Fail2Ban in jail ah-suss access.log mvfnds
...
Bad Web Bot
Web App Attack