🇺🇸
TPI-Abuse
2026-09-13 10:39:51
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.237.110.165 (165.110.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.110.165 (165.110.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 06:39:45.200526 2026] [security2:error] [pid 16865:tid 16865] [client 35.237.110.165:52928] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||desoucey.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "desoucey.com"] [uri "/z9x8c7v6b5-debug-trigger-desoucey.com"] [unique_id "aqZ9cWsGGouvXVFgo37BdQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
kosada.com
2026-09-13 10:32:58
(2 hours ago)
Repeated requests for suspicious nonexistent URLs, for example: /config/env/aws_credentials.env (HTT ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /config/env/aws_credentials.env (HTTP/2.0 port 443, user agent: "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)")
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 10:11:41
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.237.110.165 (165.110.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.110.165 (165.110.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 06:11:34.626738 2026] [security2:error] [pid 16899:tid 17011] [client 35.237.110.165:55502] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||desert-automotive.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "desert-automotive.com"] [uri "/z9x8c7v6b5-debug-trigger-desert-automotive.com"] [unique_id "aqZ21h2K3rW2cl5TPHKaFwAAAlI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 09:34:39
(2 hours ago)
(mod_security) mod_security (id:210580) triggered by 35.237.110.165 (165.110.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210580) triggered by 35.237.110.165 (165.110.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 05:34:33.630441 2026] [security2:error] [pid 22779:tid 22779] [client 35.237.110.165:50924] ModSecurity: Access denied with code 403 (phase 2). Matched phrase ".ssh/id_rsa" at ARGS:filename. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||denvercitymotorparts.com|F|2"] [data "Matched Data: .ssh/id_rsa found within ARGS:filename: file:/root/.ssh/id_rsa"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "denvercitymotorparts.com"] [uri "/__vite_rsc_findSourceMapURL"] [unique_id "aqZuKXvvp9VfKBRtXstQHQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 09:11:34
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.237.110.165 (165.110.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.110.165 (165.110.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 05:11:28.312060 2026] [security2:error] [pid 28602:tid 28602] [client 35.237.110.165:42074] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||denkyusalesca.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "denkyusalesca.com"] [uri "/z9x8c7v6b5-debug-trigger-denkyusalesca.com"] [unique_id "aqZowMhg_IdpSk4wxBAbXwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
demomodule
2026-09-13 08:53:40
(3 hours ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 08:42:03
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.237.110.165 (165.110.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.110.165 (165.110.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 04:41:57.081134 2026] [security2:error] [pid 25133:tid 25133] [client 35.237.110.165:51066] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||delunafamily.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "delunafamily.com"] [uri "/z9x8c7v6b5-debug-trigger-delunafamily.com"] [unique_id "aqZh1Y6Q1Arvf7GM2OzhIgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
factor1
2026-09-13 08:22:56
(4 hours ago)
CrowdSec at apollo Reports Abuse
Web App Attack
🇳🇱
ConsulHosting
2026-09-13 08:22:11
(4 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 07:55:46
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.237.110.165 (165.110.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.110.165 (165.110.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 03:55:41.401005 2026] [security2:error] [pid 23741:tid 23741] [client 35.237.110.165:40550] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bsa1688.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bsa1688.com"] [uri "/rclone.conf"] [unique_id "aqZW_T6i18vwMBet3Go6pwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 07:38:11
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.237.110.165 (165.110.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.110.165 (165.110.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 03:38:07.748038 2026] [security2:error] [pid 30004:tid 30004] [client 35.237.110.165:59930] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||artbyrt.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "artbyrt.com"] [uri "/z9x8c7v6b5-debug-trigger-artbyrt.com"] [unique_id "aqZS35zHPL_4UvRERa8cDQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
masterguru
2026-09-13 07:34:21
(4 hours ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:User-Agent. (1100000-193)
Bad Web Bot
Anonymous
2026-09-13 06:38:56
(5 hours ago)
Portscan: TCP/443, TCP/80, TCP/8443 (4x), TCP/8080 (4x)
Port Scan
🇮🇳
evicky2002
2026-09-13 06:00:01
(6 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
🇬🇧
openstrike.co.uk
2026-09-13 05:14:00
(7 hours ago)
334 attacks on env grabbing URLs (type 2), config grabbing URLs (type 2), VC URLs, password/key grab ...
show more
334 attacks on env grabbing URLs (type 2), config grabbing URLs (type 2), VC URLs, password/key grabbing URLs, PHP URLs, env grabbing URLs, directory traversals:
GET /api/w/starter/jobs_u/get_log_file/../../../../proc/self/environ HTTP/1.1
GET /src/amplifyconfiguration.json HTTP/1.1
GET /.git/HEAD HTTP/1.1
GET /__vite_rsc_findSourceMapURL?filename=file:///root/.ssh/id_rsa&environmentName=rsc HTTP/1.1
GET /app_dev.php/_profiler HTTP/1.1
GET /@fs/.env?raw&url?? HTTP/1.1
GET /..%2f..%2f.env HTTP/1.1
show less
Hacking
Web App Attack