πΊπΈ
TPI-Abuse
2026-09-30 03:03:49
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.240.237.177 (177.237.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.237.177 (177.237.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 23:03:44.458928 2026] [security2:error] [pid 12918:tid 12918] [client 35.240.237.177:54634] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thebarringtongroup.org"] [uri "/build/.env"] [unique_id "arx8EGKdbrWTrtF_wcNskAAAAB4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
lavnet.net
2026-09-30 02:53:09
(1 day ago)
35.240.237.177 - - [30/Sep/2026:02:53:09 +0000] "GET /login HTTP/2.0" 404 1878 "-" "Mozilla/5.0 (Win ...
show more
35.240.237.177 - - [30/Sep/2026:02:53:09 +0000] "GET /login HTTP/2.0" 404 1878 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
35.240.237.177 - - [30/Sep/2026:02:53:09 +0000] "GET /users/login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
35.240.237.177 - - [30/Sep/2026:02:53:09 +0000] "GET /mpcbotbkhcql6eclsj8m HTTP/2.0" 404 1855 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
35.240.237.177 - - [30/Sep/2026:02:53:09 +0000] "GET /account/login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36 Edg/153.0.0.0"
35.240.237.177 - - [30/Sep/2026:02:53:09 +0000] "GET /user/login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/53
...
show less
Brute-Force
πΊπΈ
TPI-Abuse
2026-09-30 02:24:29
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.240.237.177 (177.237.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.237.177 (177.237.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:24:21.633219 2026] [security2:error] [pid 30241:tid 30241] [client 35.240.237.177:38182] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "themillercsefoundation.org"] [uri "/.env"] [unique_id "arxy1WE9_7RwRh2IoeCbhAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 01:42:53
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.240.237.177 (177.237.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.237.177 (177.237.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:42:49.470776 2026] [security2:error] [pid 17470:tid 17470] [client 35.240.237.177:46880] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thehudsonpress.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thehudsonpress.com"] [uri "/z9x8c7v6b5-debug-trigger-thehudsonpress.com"] [unique_id "arxpGfc30vNGvTFF4XRRkgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-30 00:42:21
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.240.237.177 (177.237.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.237.177 (177.237.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:42:16.726815 2026] [security2:error] [pid 15795:tid 15795] [client 35.240.237.177:47708] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||themediaplanet.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "themediaplanet.com"] [uri "/z9x8c7v6b5-debug-trigger-themediaplanet.com"] [unique_id "arxa6Ge5cV1GHqvK2R9GWwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Skyrider
2026-09-29 23:09:46
(1 day ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-29 22:49:51
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.240.237.177 (177.237.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.237.177 (177.237.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:49:44.082565 2026] [security2:error] [pid 14063:tid 14063] [client 35.240.237.177:41450] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thebumans.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thebumans.com"] [uri "/z9x8c7v6b5-debug-trigger-thebumans.com"] [unique_id "arxAiHE-Q1RgbxCeuEMeTwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
WeCloudit-Anti-Abuse
2026-09-29 22:41:23
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
π³π±
Alt255
2026-09-29 21:56:16
(1 day ago)
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-04al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.240.237.177 - - [29/Sep/2026:23:55:58 +0200] "GET /userfiles?path=../../../.env HTTP/2.0" 301 332 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 21:50:05
(1 day ago)
| [Dangerous/Singapore] Aggressive IP 35.240.237.177 (~30 hits). Type: DoS Defender- Web server 400 ...
show more
| [Dangerous/Singapore] Aggressive IP 35.240.237.177 (~30 hits). Type: DoS Defender- Web server 400 error code
show less
Web App Attack
Hacking
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-29 21:28:07
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.240.237.177 (177.237.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.237.177 (177.237.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 17:28:02.023282 2026] [security2:error] [pid 16970:tid 16970] [client 35.240.237.177:42108] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||templeantiques.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "templeantiques.com"] [uri "/z9x8c7v6b5-debug-trigger-templeantiques.com"] [unique_id "arwtYhxETezhnmlRXFgsMgAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-09-29 20:55:20
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
π§πͺ
cmbplf
2026-09-29 20:10:17
(2 days ago)
27.006 requests from untrusted country (1w1d18h)
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-29 19:33:36
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.240.237.177 (177.237.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.237.177 (177.237.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 15:33:30.119845 2026] [security2:error] [pid 19713:tid 19713] [client 35.240.237.177:37574] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||thecrimsonpirate.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thecrimsonpirate.com"] [uri "/z9x8c7v6b5-debug-trigger-thecrimsonpirate.com"] [unique_id "arwSitisuGE-TiMhmDRA0QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 19:32:12
(2 days ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack