Anonymous
2026-05-28 00:06:41
(3 months ago)
WAF repeated trigger detected by Fail2Ban
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-27 19:33:41
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 35.236.143.25 (25.143.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.143.25 (25.143.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 15:33:38.229558 2026] [security2:error] [pid 16291:tid 16291] [client 35.236.143.25:41648] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ftp.hdestimating.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ftp.hdestimating.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ahdHEgRio03mm2ot-RndmwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-27 18:59:23
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 35.236.143.25 (25.143.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.143.25 (25.143.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 14:59:19.347519 2026] [security2:error] [pid 23585:tid 23585] [client 35.236.143.25:51722] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.gangnagel.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.gangnagel.com"] [uri "/dump.sql"] [unique_id "ahc_B_Ven_audE26xGEoXwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
markawes
2026-05-27 11:38:02
(3 months ago)
[markis] Auto banned by Fail2Ban. Reason: Malicious web scan / attempted access to sensitive paths. ...
show more
[markis] Auto banned by Fail2Ban. Reason: Malicious web scan / attempted access to sensitive paths. Evidence:
35.236.143.25 - - [27/May/2026:12:38:00 +0100] "GET /.aws/credentials HTTP/1.1" 404 3068 "-" "Mozilla/5.0 (Linux; Android 5.1; C6740N Build/LMY47O) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/42.0.2311.111 Mobile Safari/537.36"
35.236.143.25 - - [27/May/2026:12:38:00 +0100] "GET /actuator/heapdump HTTP/1.1" 404 3067 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/47.0.2526.80 Safari/537.36 Vivaldi/1.0.344.37"
35.236.143.25 - - [27/May/2026:12:38:00 +0100] "GET /actuator/logfile HTTP/1.1" 404 3068 "-" "Mozilla/4.0 (compatible; MSIE 8.0; Windows NT 6.1; WOW64; Trident/4.0; SLCC2; .NET CLR 2.0.50727; .NET CLR 3.5.30729; .NET CLR 3.0.30729; Media Center PC 6.0; .NET4.0C; .NET4.0E; InfoPath.2)"
show less
Port Scan
Hacking
Web App Attack
π³π±
Roderic
2026-05-27 11:10:19
(3 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-05-27 09:52:43
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 35.236.143.25 (25.143.236.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.236.143.25 (25.143.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 05:52:37.684216 2026] [security2:error] [pid 29663:tid 29663] [client 35.236.143.25:49102] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.accpp.link"] [uri "/wp-config.php.bak"] [unique_id "aha-5QHq1fToNkz8sabEEgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-05-27 08:25:19
(3 months ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Savvii
2026-05-27 06:21:25
(3 months ago)
20 attempts against mh-misbehave-ban on ec102966
Brute-Force
Bad Web Bot
Web App Attack
π³π±
e.fierstra
2026-05-27 05:53:30
(3 months ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
Anonymous
2026-05-27 03:00:07
(3 months ago)
| [Dangerous/Taiwan] Aggressive IP 35.236.143.25 (~30 hits). Type: DoS Defender- Web server 400 erro ...
show more
| [Dangerous/Taiwan] Aggressive IP 35.236.143.25 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
π©πͺ
XICTRON
2026-05-27 00:40:09
(3 months ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
π«π·
dynamix
2026-05-26 21:22:02
(3 months ago)
Multiple WAF Violations
Web App Attack