๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(23 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-09-23 04:31:37
(1 day ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐บ๐ธ
TPI-Abuse
2026-09-23 01:53:56
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.237.220.196 (196.220.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.220.196 (196.220.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 21:53:51.988397 2026] [security2:error] [pid 26905:tid 26905] [client 35.237.220.196:54548] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hardcountryrock.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hardcountryrock.com"] [uri "/z9x8c7v6b5-debug-trigger-hardcountryrock.com"] [unique_id "arMxLwFeJmvQKdb7eWLXzAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 01:33:59
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.237.220.196 (196.220.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.220.196 (196.220.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 21:33:56.350171 2026] [security2:error] [pid 17326:tid 17326] [client 35.237.220.196:43572] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lahamradio.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lahamradio.com"] [uri "/z9x8c7v6b5-debug-trigger-lahamradio.com"] [unique_id "arMshEDhbY3qjCznaznE9wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-09-23 01:01:45
(1 day ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 00:46:43
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.237.220.196 (196.220.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.220.196 (196.220.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 20:46:40.371554 2026] [security2:error] [pid 16118:tid 16118] [client 35.237.220.196:33610] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||leighcunningham.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "leighcunningham.com"] [uri "/z9x8c7v6b5-debug-trigger-leighcunningham.com"] [unique_id "arMhcGTfqdNeR28kh-J25gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ฐ
HostingGroup
2026-09-23 00:26:53
(1 day ago)
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shiel ...
show more
Automated malicious activity (Honeypot Trap) detected and blocked at the CDN edge by NordicCDN Shield. Offenses: 3. First blocked: 2026-09-23.
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-23 00:20:09
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-23 00:13:27
(1 day ago)
35.237.220.196 - - [23/Sep/2026:02:13:24 +0200] "GET /.git-credentials HTTP/2.0" 403 297 "http://[si ...
show more
35.237.220.196 - - [23/Sep/2026:02:13:24 +0200] "GET /.git-credentials HTTP/2.0" 403 297 "http://[site]/.git-credentials" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
35.237.220.196 - - [23/Sep/2026:02:13:24 +0200] "GET //.env HTTP/1.1" 301 520 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)"
35.237.220.196 - - [23/Sep/2026:02:13:24 +0200] "GET /.//.env HTTP/1.1" 301 520 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://openai.com/searchbot"
35.237.220.196 - - [23/Sep/2026:02:13:24 +0200] "GET /secrets.env HTTP/1.1" 301 534 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
35.237.220.196 - - [23/Sep/2026:02:13:24 +0200] "GET /service-account.json HTTP/1.1" 301 552 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/do
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-22 23:47:33
(1 day ago)
(mod_security) mod_security (id:949110) triggered by 35.237.220.196 (196.220.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 35.237.220.196 (196.220.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 19:47:26.617324 2026] [security2:error] [pid 22449:tid 22449] [client 35.237.220.196:48734] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "lenukuhivabookings.com"] [uri "/z9x8c7v6b5-debug-trigger-lenukuhivabookings.com"] [unique_id "arMTjt4hY4OnmPy-Xstv4gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
BlueWire Hosting
2026-09-22 23:36:07
(1 day ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐จ๐ฆ
polycoda
2026-09-22 22:57:19
(1 day ago)
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - ๐ก Port Scan (Non Decay-Based) - โช๏ธ Excessive ...
show more
AutoBlock: ๐ฏ Vulnerability Scanner (Non Decay-Based) - ๐ก Port Scan (Non Decay-Based) - โช๏ธ Excessive 30X Errors (Decay-Based)
show less
Port Scan
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
netclix.gr
2026-09-22 22:28:51
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted] 35.237.220.196 (US/United States/196.22 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.237.220.196 (US/United States/196.220.237.35.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
๐ฉ๐ช
LRob
2026-09-22 22:27:59
(1 day ago)
This address swept through a list of pages that do not exist on our site within seconds โ a scanner ...
show more
This address swept through a list of pages that do not exist on our site within seconds โ a scanner working through its wordlist of exploitable paths. Blocked; please check the machine behind it for a scanner or malware. | method: GET | path: /assets/manifest.json (+11 more) | 2026-09-22 22:27 UTC
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 21:59:58
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.237.220.196 (196.220.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.220.196 (196.220.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:59:49.929249 2026] [security2:error] [pid 11038:tid 11133] [client 35.237.220.196:48536] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||letterstomyhusband.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "letterstomyhusband.com"] [uri "/z9x8c7v6b5-debug-trigger-letterstomyhusband.com"] [unique_id "arL6VYPKw4GHJR-BvLmv4QAAAM0"]
show less
Brute-Force
Bad Web Bot
Web App Attack