Anonymous
2026-09-23 15:10:16
(10 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
๐จ๐ฆ
zXero
2026-09-23 12:41:55
(12 hours ago)
Fail2Ban automatic report - jail: recidive
Brute-Force
SSH
DDoS Attack
๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(19 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ง๐ช
taivas.nl
2026-09-23 04:32:29
(20 hours ago)
Many_bad_calls
Web App Attack
๐ง๐ช
taivas.nl
2026-09-23 03:02:10
(22 hours ago)
Bad_requests
Bad Web Bot
๐ช๐ธ
robotstxt
2026-09-23 02:47:52
(22 hours ago)
35.239.53.30 - - [23/Sep/2026:02:46:52 +0000] "GET /z9x8c7v6b5-debug-trigger-nataliecapell.com HTTP/ ...
show more
35.239.53.30 - - [23/Sep/2026:02:46:52 +0000] "GET /z9x8c7v6b5-debug-trigger-nataliecapell.com HTTP/2.0" 403 49220 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" "-" edge="35.239.53.30"
35.239.53.30 - - [23/Sep/2026:02:46:52 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 55883 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.239.53.30"
35.239.53.30 - - [23/Sep/2026:02:46:52 +0000] "POST / HTTP/2.0" 403 46702 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" "-" edge="35.239.53.30"
35.239.53.30 - - [23/Sep/2026:02:46:52 +0000] "GET /dist/manifest.json HTTP/2.0" 403 55882 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.239.53.30"
35.239.53.30 - - [23/Sep/2026:02:46:52 +0000] "GET /build/manifest.json HTTP/2.0" 403 55886 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 22:53:42
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.239.53.30 (30.53.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.239.53.30 (30.53.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:53:37.104520 2026] [security2:error] [pid 27170:tid 27170] [client 35.239.53.30:41310] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nctreillc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nctreillc.com"] [uri "/z9x8c7v6b5-debug-trigger-nctreillc.com"] [unique_id "arMG8QHtQQLNmie7aXwiOAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 22:28:00
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.239.53.30 (30.53.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.239.53.30 (30.53.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:27:55.187189 2026] [security2:error] [pid 1419437:tid 1419437] [client 35.239.53.30:55634] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nearfieldchrist.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nearfieldchrist.com"] [uri "/z9x8c7v6b5-debug-trigger-nearfieldchrist.com"] [unique_id "arMA6_oi01Jk5iONwsToogAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LoneRider
2026-09-22 22:06:51
(1 day ago)
[23/Sep/2026:00:06:50.417145 +0200] arL7-h72nY0XhcMQU41gMwAAAAA 35.239.53.30 52332 127.0.0.1 7081
[2 ...
show more
[23/Sep/2026:00:06:50.417145 +0200] arL7-h72nY0XhcMQU41gMwAAAAA 35.239.53.30 52332 127.0.0.1 7081
[23/Sep/2026:00:06:51.199805 +0200] arL7-32vzMivlOLBrIim5wAAAAM 35.239.53.30 52536 127.0.0.1 7081
[23/Sep/2026:00:06:51.224881 +0200] arL7-511JQTR3nkvHbzZGgAAAAQ 35.239.53.30 52598 127.0.0.1 7081
...
show less
Hacking
Anonymous
2026-09-22 21:42:06
(1 day ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-09-22 21:12:33
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.239.53.30 (30.53.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.239.53.30 (30.53.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:12:28.327057 2026] [security2:error] [pid 12422:tid 12422] [client 35.239.53.30:39720] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nekstlevel.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nekstlevel.com"] [uri "/z9x8c7v6b5-debug-trigger-nekstlevel.com"] [unique_id "arLvPKHOyqvcy0HXvNNExAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
Inartis
2026-09-22 20:44:07
(1 day ago)
35.239.53.30 - - [22/Sep/2026:22:44:06 +0200] "GET /admin HTTP/2.0" 302 45 "-" "Mozilla/5.0 (Linux; ...
show more
35.239.53.30 - - [22/Sep/2026:22:44:06 +0200] "GET /admin HTTP/2.0" 302 45 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 20:19:43
(1 day ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-22 19:50:04
(1 day ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ช๐ธ
netfactotum
2026-09-22 19:29:20
(1 day ago)
Hacking
Web App Attack