๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(2 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐น๐ญ
thaizone.com
2026-09-23 02:18:38
(2 days ago)
Hacking attempts against websites (D1) #2
Web App Attack
Hacking
๐ฌ๐ง
andypiper
2026-09-23 01:01:03
(2 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
Anonymous
2026-09-23 01:00:03
(2 days ago)
suspicious request in access.log
Web App Attack
๐ฉ๐ช
IVski.com
2026-09-23 00:15:24
(2 days ago)
IVski WAF | Next.js Server Action probe
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 22:57:17
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.240.129.107 (107.129.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.129.107 (107.129.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:57:09.766224 2026] [security2:error] [pid 2657:tid 2657] [client 35.240.129.107:42584] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.palm.gisur.com|F|2"] [data ".palm.gisur.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.palm.gisur.com"] [uri "/z9x8c7v6b5-debug-trigger-www.palm.gisur.com"] [unique_id "arMHxbQQkjEhfy0EXIoEQwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-22 21:08:56
(2 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ซ๐ฎ
paissangroup
2026-09-22 19:59:15
(2 days ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-09-22 17:49:41
(2 days ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:32:32
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.240.129.107 (107.129.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.129.107 (107.129.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:32:26.557127 2026] [security2:error] [pid 17296:tid 17296] [client 35.240.129.107:58278] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||alanmariotti.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "alanmariotti.com"] [uri "/z9x8c7v6b5-debug-trigger-alanmariotti.com"] [unique_id "arK7qtnA4oVJhUsfXMh5hAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-22 14:45:44
(2 days ago)
This address is looking for secret files on our sites: .git directories, .env files, credential and ...
show more
This address is looking for secret files on our sites: .git directories, .env files, credential and configuration files, database dumps, backups. This is a targeted search for credentials to break into the sites, blocked at the first request. Please check the machine behind it for an attack tool or malware. | method: GET | path: /.env.save (+3 more) | 2026-09-22 14:45 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:40:28
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.240.129.107 (107.129.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.129.107 (107.129.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:40:22.976172 2026] [security2:error] [pid 12550:tid 12550] [client 35.240.129.107:37034] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||modeltdr.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "modeltdr.com"] [uri "/z9x8c7v6b5-debug-trigger-modeltdr.com"] [unique_id "arJpJicLytAkqLHkUHPkNAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:13:15
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.240.129.107 (107.129.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.129.107 (107.129.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:13:06.431331 2026] [security2:error] [pid 22927:tid 22927] [client 35.240.129.107:59588] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||panama-boat-registration.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "panama-boat-registration.com"] [uri "/z9x8c7v6b5-debug-trigger-panama-boat-registration.com"] [unique_id "arJiwt11qS83xvSgFGkxygAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-22 10:15:22
(3 days ago)
Excessive multi-domain requests
Brute-Force
๐น๐ญ
thaizone.com
2026-09-22 10:10:18
(3 days ago)
Hacking attempts against websites (D1) #1
Web App Attack
Hacking