Anonymous
2026-06-10 00:42:36
(1 hour ago)
(caddyscan) Scanner path probe from 35.236.43.68 (US/United States/68.43.236.35.bc.googleusercontent ...
show more
(caddyscan) Scanner path probe from 35.236.43.68 (US/United States/68.43.236.35.bc.googleusercontent.com): 5 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: [REDACTED] 200 2627 35.236.43.68 - - [10/Jun/2026:00:42:33 +0000] "GET /actuator/configprops HTTP/1.1"
[REDACTED] 200 2627 35.236.43.68 - - [10/Jun/2026:00:42:33 +0000] "GET /actuator/httptrace HTTP/1.1"
[REDACTED] 200 2627 35.236.43.68 - - [10/Jun/2026:00:42:33 +0000] "GET /actuator/logfile HTTP/1.1"
[REDACTED] 200 2627 35.236.43.68 - - [10/Jun/2026:00:42:33 +0000] "GET /actuator/dump HTTP/1.1"
[REDACTED] 200 2627 35.236.43.68 - - [10/Jun/2026:00:42:33 +0000] "GET /actuator/heapdump HTTP/1.1"
show less
Port Scan
๐บ๐ธ
mnsf
2026-06-10 00:07:55
(2 hours ago)
Abuse Detected (14)
Brute-Force
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:02:40
(4 hours ago)
Auto-ban: >3000 req/min op 2026-06-09
Web App Attack
SSH
Hacking
๐ณ๐ฑ
Site.eu
2026-06-09 21:06:31
(5 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
Hazzard
2026-06-09 18:06:11
(8 hours ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐ง๐ช
cmbplf
2026-06-09 17:28:52
(9 hours ago)
203 requests with url.path *credentials.json
125 requests with url.path *config.yml
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-09 12:49:38
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.236.43.68 (68.43.236.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.43.68 (68.43.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 08:49:31.457306 2026] [security2:error] [pid 26398:tid 26398] [client 35.236.43.68:39178] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||azfilmguild.org|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "azfilmguild.org"] [uri "/.config/gcloud/credentials.db"] [unique_id "aigL2_5AJIl_wv2RwtHLNQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
Saec
2026-06-09 10:45:13
(15 hours ago)
Jarvis auto-ban: CF top attacker on saec.ovh (382 hits, US)
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 10:22:01
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.236.43.68 (68.43.236.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.43.68 (68.43.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 06:21:53.871602 2026] [security2:error] [pid 2465:tid 2465] [client 35.236.43.68:50390] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.playmakersinc.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.playmakersinc.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aifpQRFBsUud1IRag09KUwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 08:53:12
(17 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.236.43.68 (68.43.236.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.43.68 (68.43.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 04:53:04.065203 2026] [security2:error] [pid 11766:tid 11766] [client 35.236.43.68:52232] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||allfloridamedia.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "allfloridamedia.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aifUcGmzs2-XTXKK2mAnigAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 07:11:17
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.236.43.68 (68.43.236.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.236.43.68 (68.43.236.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 03:11:14.736331 2026] [security2:error] [pid 8677:tid 8677] [client 35.236.43.68:49942] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||servicios.imerka.com.mx|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "servicios.imerka.com.mx"] [uri "/.config/gcloud/credentials.db"] [unique_id "aie8koTspqOzAO5gvLC4qwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Ba-Yu
2026-06-09 06:39:28
(19 hours ago)
General hacking/exploits/scanning
Web Spam
Hacking
Brute-Force
Exploited Host
Web App Attack
๐ณ๐ฑ
Savvii
2026-06-09 05:06:51
(21 hours ago)
20 attempts against mh-misbehave-ban on frost
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-09 03:23:46
(23 hours ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ฎ๐น
VHosting
2026-06-09 03:05:02
(23 hours ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack