๐บ๐ธ
TPI-Abuse
2026-06-10 20:13:18
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.237.237.166 (166.237.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.237.166 (166.237.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 16:13:11.072083 2026] [security2:error] [pid 20411:tid 20428] [client 35.237.237.166:60760] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||whitecrosslibrary.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "whitecrosslibrary.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "ainFV-vzdyyASmUrZq1IDAAAAs4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Octopuce
2026-06-10 18:16:05
(8 hours ago)
Aggressive web search of vulnerable pages: /info.php /phptest.php /debug.php /phpinfo.php /test.php ...
show more
Aggressive web search of vulnerable pages: /info.php /phptest.php /debug.php /phpinfo.php /test.php /api/phpinfo.php /php.php /admin/phpinfo.ph ...
show less
Web App Attack
๐ณ๐ฑ
Cloud86 B.V.
2026-06-10 11:00:02
(15 hours ago)
categories: DDoS Attack
DDoS Attack
๐ฉ๐ช
wsyq
2026-06-10 09:26:10
(17 hours ago)
Fail2Ban - \[NGINX\]40x-Forcing to access a restricted resource
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 06:20:06
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.237.237.166 (166.237.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.237.166 (166.237.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 02:19:59.713625 2026] [security2:error] [pid 19870:tid 19870] [client 35.237.237.166:54832] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.gapanda.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.gapanda.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aikCDwjtUw_fmAmGBwI-LQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 05:26:08
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.237.237.166 (166.237.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.237.166 (166.237.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 01:26:02.652868 2026] [security2:error] [pid 3514:tid 3514] [client 35.237.237.166:47830] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fastpc.biz|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fastpc.biz"] [uri "/.config/gcloud/credentials.db"] [unique_id "aij1ahwdJajaJUY-_Ebu9QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 04:27:19
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.237.237.166 (166.237.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.237.237.166 (166.237.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 00:27:11.414653 2026] [security2:error] [pid 8733:tid 8733] [client 35.237.237.166:34476] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rcjav.com.lordhari.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rcjav.com.lordhari.com"] [uri "/.config/gcloud/credentials.db"] [unique_id "aijnn7BJ2iN_GBh3kSPyogAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Active8
2026-06-10 01:03:13
(1 day ago)
(CT) IP 35.237.237.166 (US/United States/166.237.237.35.bc.googleusercontent.com) found to have 369 ...
show more
(CT) IP 35.237.237.166 (US/United States/166.237.237.35.bc.googleusercontent.com) found to have 369 connections
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-09 23:56:23
(1 day ago)
(mod_security) mod_security (id:210831) triggered by 35.237.237.166 (166.237.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210831) triggered by 35.237.237.166 (166.237.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 19:56:16.395035 2026] [security2:error] [pid 2265:tid 2265] [client 35.237.237.166:49786] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||belgiophar.net|F|4"] [data "Microsoft URL"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "belgiophar.net"] [uri "/actuator/auditevents"] [unique_id "aiioIMLnwl1dgzfBRXrbIwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-09 22:01:40
(1 day ago)
Auto-ban: >3000 req/min op 2026-06-09
Web App Attack
SSH
Hacking
Anonymous
2026-06-09 17:36:29
(1 day ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 16:51:44
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.237.237.166 (166.237.237.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.237.237.166 (166.237.237.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 12:51:37.243292 2026] [security2:error] [pid 20901:tid 20901] [client 35.237.237.166:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/config.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.empoweruamerica.org"] [uri "/config/config.yml"] [unique_id "aihEmVHZRQKGNpfy3ZyWyQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-06-09 13:07:30
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ฆ
URAN Publishing Service
2026-06-09 12:48:23
(1 day ago)
35.237.237.166 - - [09/Jun/2026:15:48:18 +0300] "GET /config.env HTTP/1.1" 404 3293 "-" "Mozilla/5.0 ...
show more
35.237.237.166 - - [09/Jun/2026:15:48:18 +0300] "GET /config.env HTTP/1.1" 404 3293 "-" "Mozilla/5.0 (Windows NT 10.0; ARM; Lumia 950 Dual SIM) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/51.0.2704.79 Safari/537.36 Edge/14.14393"
35.237.237.166 - - [09/Jun/2026:15:48:19 +0300] "GET /wp-config.php.old HTTP/1.1" 404 3292 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 11_3 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1"
...
show less
Web App Attack
๐บ๐ธ
agenciahypelab.com.br
2026-06-09 11:09:41
(1 day ago)
WordPress login brute-force detectado e bloqueado pelo CSF/LFD. Trigger: LF_TRIGGER
Brute-Force
SSH