๐ฟ๐ฆ
conure.sh
2026-09-23 12:13:48
(11 hours ago)
csagent: score 22.4: 404 noise floor x10, secrets grab x2; 1 domain(s) in 18s
Web App Attack
๐ช๐ธ
pipeline.es
2026-09-23 09:54:19
(13 hours ago)
Web scanning / probing for vulnerable paths
Port Scan
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(17 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ณ๐ฑ
Alt255
2026-09-23 02:46:34
(20 hours ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.238.232.194 - - [23/Sep/2026:04:46:17 +0200] "GET /@fs/app/.env?raw?? HTTP/2.0" 301 319 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
...
show less
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-23 01:55:37
(21 hours ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 01:34:14
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.238.232.194 (194.232.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.238.232.194 (194.232.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 21:34:10.211651 2026] [security2:error] [pid 11171:tid 11171] [client 35.238.232.194:52530] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||miraclepunchy.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "miraclepunchy.com"] [uri "/z9x8c7v6b5-debug-trigger-miraclepunchy.com"] [unique_id "arMskjYkceR9EACi-Kr33wAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 01:20:12
(22 hours ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ฌ๐ง
andypiper
2026-09-23 01:01:31
(22 hours ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 00:53:24
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.238.232.194 (194.232.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.238.232.194 (194.232.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 20:53:21.071889 2026] [security2:error] [pid 32618:tid 32618] [client 35.238.232.194:33390] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||misscrankypants.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "misscrankypants.com"] [uri "/z9x8c7v6b5-debug-trigger-misscrankypants.com"] [unique_id "arMjAX0ChmdIzGsvkwJA8wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 00:14:13
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.238.232.194 (194.232.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.238.232.194 (194.232.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 20:14:06.231110 2026] [security2:error] [pid 32064:tid 32064] [client 35.238.232.194:37418] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mitchellamazing.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mitchellamazing.com"] [uri "/z9x8c7v6b5-debug-trigger-mitchellamazing.com"] [unique_id "arMZzh88FcsTo7AodsjKxgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 22:38:56
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.238.232.194 (194.232.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.238.232.194 (194.232.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:38:50.850055 2026] [security2:error] [pid 20149:tid 20149] [client 35.238.232.194:40834] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mkdesignndetailing.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mkdesignndetailing.com"] [uri "/z9x8c7v6b5-debug-trigger-mkdesignndetailing.com"] [unique_id "arMDenVTnHWRp_LFz4mIgwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 22:03:23
(1 day ago)
35.238.232.194 - - [23/Sep/2026:06:03:22 +0800] "GET /@fs/../.env?raw?? HTTP/2.0" 403 162 "-" "Mozil ...
show more
35.238.232.194 - - [23/Sep/2026:06:03:22 +0800] "GET /@fs/../.env?raw?? HTTP/2.0" 403 162 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
show less
Brute-Force
SSH
๐ฉ๐ช
maxpower
2026-09-22 22:03:15
(1 day ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.238.232.194 (US/United States/194.232 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 35.238.232.194 (US/United States/194.232.238.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.238.232.194 - - [23/Sep/2026:00:03:12 +0200] "GET /config/env/aws_credentials.env HTTP/2.0" 200 12134 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" "-" host=mlocale.com
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-22 21:32:37
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.238.232.194 (194.232.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.238.232.194 (194.232.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:32:33.921708 2026] [security2:error] [pid 13365:tid 13365] [client 35.238.232.194:45560] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mmipro.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mmipro.com"] [uri "/z9x8c7v6b5-debug-trigger-mmipro.com"] [unique_id "arLz8ae5g8XDel7GTWJaVQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Stara
2026-09-22 21:24:40
(1 day ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack