Anonymous
2026-09-22 17:10:22
(12 minutes ago)
sensitive path probe detected by fail2ban
...
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:07:47
(14 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.237.214.244 (244.214.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.214.244 (244.214.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:07:43.349933 2026] [security2:error] [pid 6223:tid 6223] [client 35.237.214.244:39898] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lancehancock.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lancehancock.com"] [uri "/z9x8c7v6b5-debug-trigger-lancehancock.com"] [unique_id "arK130Ao_QWO19RhFWzRXQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 16:40:51
(41 minutes ago)
Automated report (2026-09-23T00:40:51+08:00). Scraper detected.
Bad Web Bot
Anonymous
2026-09-22 16:40:51
(41 minutes ago)
Automated report (2026-09-23T00:40:52+08:00). Scraper detected.
Bad Web Bot
๐ณ๐ฑ
Savvii
2026-09-22 15:53:45
(1 hour ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:25:25
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.237.214.244 (244.214.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.214.244 (244.214.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:25:19.359683 2026] [security2:error] [pid 28115:tid 28115] [client 35.237.214.244:42512] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||larrystransmissions.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "larrystransmissions.com"] [uri "/z9x8c7v6b5-debug-trigger-larrystransmissions.com"] [unique_id "arKd37GjlvEatfZPTaTTSwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-22 15:20:15
(2 hours ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-22 15:12:25
(2 hours ago)
35.237.214.244 - - [22/Sep/2026:17:12:22 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e% ...
show more
35.237.214.244 - - [22/Sep/2026:17:12:22 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
35.237.214.244 - - [22/Sep/2026:17:12:22 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2fproc/self/environ HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
35.237.214.244 - - [22/Sep/2026:17:12:22 +0200] "GET /uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/2.0" 404 293 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
35.237.214.244 - - [22/Sep/2026:17:12:22 +0200] "GET /public/plugins/alertlist/../../../../../../../../proc/self/environ HTTP/2.0" 400 323 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
35.237.214.244 - - [22/Sep/2026:17:12:22 +0200] "GET /@fs/proc/self/cwd/.env?raw?? HTTP/2.0" 404 293 "-" "Mozilla/5.0 (compatibl
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 15:10:21
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.237.214.244 (244.214.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.214.244 (244.214.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:10:17.413902 2026] [security2:error] [pid 7933:tid 7970] [client 35.237.214.244:46058] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lasertagmetairie.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lasertagmetairie.com"] [uri "/z9x8c7v6b5-debug-trigger-lasertagmetairie.com"] [unique_id "arKaWaYtTkFWwP-GXBfX3QAAAQY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 14:57:29
(2 hours ago)
[cb-01al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-01al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.237.214.244 - - [22/Sep/2026:16:57:19 +0200] "GET /.env?raw HTTP/2.0" 404 1338 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 14:40:06
(2 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ซ๐ท
pm33
2026-09-22 14:06:40
(3 hours ago)
Excessive crawling HTTP 404
Web App Attack
๐ฆ๐น
penguin-solutions.at
2026-09-22 14:01:11
(3 hours ago)
Excessive 403/404 errors
...
Brute-Force
Web App Attack
๐ฉ๐ช
netclix.gr
2026-09-22 14:00:57
(3 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.237.214.244 (US/United States/244.21 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.237.214.244 (US/United States/244.214.237.35.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐ท๐ด
clauss
2026-09-22 13:24:59
(3 hours ago)
35.237.214.244 - - [22/Sep/2026:16:24:58 +0300] "GET /config.json HTTP/2.0" 301 0 "-" "Mozilla/5.0 ( ...
show more
35.237.214.244 - - [22/Sep/2026:16:24:58 +0300] "GET /config.json HTTP/2.0" 301 0 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
35.237.214.244 - - [22/Sep/2026:16:24:58 +0300] "GET /rclone.conf HTTP/2.0" 403 146 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
...
show less
Web App Attack