๐บ๐ธ
TPI-Abuse
2026-10-09 18:50:17
(35 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.241.186.88 (88.186.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.241.186.88 (88.186.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 14:50:11.337585 2026] [security2:error] [pid 19871:tid 19871] [client 35.241.186.88:40728] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||bestnebraskadetective.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bestnebraskadetective.com"] [uri "/z9x8c7v6b5-debug-trigger-bestnebraskadetective.com"] [unique_id "ask3Y193jeUiJbCwrw8IiQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Stara
2026-10-09 18:36:40
(48 minutes ago)
ModSecurity detected web attack - .env/config probing or SQLi/Code injection (Rule 949110)
Brute-Force
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 17:57:40
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.241.186.88 (88.186.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.241.186.88 (88.186.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 13:57:32.733402 2026] [security2:error] [pid 7246:tid 7276] [client 35.241.186.88:39422] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||besfixedwireless.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "besfixedwireless.com"] [uri "/z9x8c7v6b5-debug-trigger-besfixedwireless.com"] [unique_id "askrDAeI3X4OoYtYjae8DAAAAcA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
KTSTechnology
2026-10-09 17:36:24
(1 hour ago)
Web vulnerability scanning detected by our ISP firewall
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-09 17:30:11
(1 hour ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
konseptit
2026-10-09 17:27:52
(1 hour ago)
(mod_security) mod_security triggered on hostname [redacted] 35.241.186.88 (BE/Belgium/88.186.241.35 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.241.186.88 (BE/Belgium/88.186.241.35.bc.googleusercontent.com)
show less
SQL Injection
๐ง๐ช
cmbplf
2026-10-09 17:23:37
(2 hours ago)
2.720 requests with url.path *.env
1.521 requests with url.path */@fs/*
419 requests with url.pat ...
show more
2.720 requests with url.path *.env
1.521 requests with url.path */@fs/*
419 requests with url.path */proc/*
274 requests with url.path *.aws/*
258 requests with url.path *config.json
182 requests with url.path *.ssh/*
show less
Brute-Force
Bad Web Bot
๐ฌ๐ง
bensmithurst
2026-10-09 17:07:50
(2 hours ago)
35.241.186.88 - - [09/Oct/2026:17:07:49 +0000] "GET /public/plugins/text/../../../../../../../../pro ...
show more
35.241.186.88 - - [09/Oct/2026:17:07:49 +0000] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 150 "-" "-"
35.241.186.88 - - [09/Oct/2026:17:07:49 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2fproc/self/environ HTTP/1.1" 400 150 "-" "-"
35.241.186.88 - - [09/Oct/2026:17:07:49 +0000] "GET /@fs/..%2f..%2f..%2f..%2f..%2froot/.env HTTP/1.1" 400 150 "-" "-"
35.241.186.88 - - [09/Oct/2026:17:07:50 +0000] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env HTTP/1.1" 400 150 "-" "-"
35.241.186.88 - - [09/Oct/2026:17:07:50 +0000] "GET /%2e%2e/%2e%2e/%2e%2e/%2e%2e/proc/self/environ HTTP/1.1" 400 150 "-" "-"
... [host=LAN***]
show less
Web App Attack
๐บ๐ธ
IndigoRidge
2026-10-09 17:01:47
(2 hours ago)
[Fri Oct 09 13:01:43.609243 2026] [authz_core:error] [pid 1986252:tid 139705605478144] [client 35.24 ...
show more
[Fri Oct 09 13:01:43.609243 2026] [authz_core:error] [pid 1986252:tid 139705605478144] [client 35.241.186.88:0] AH01630: client denied by server configuration: /var/www/vhosts/bennettpaving.com/error_docs/forbidden.html, referer: https://bennettpaving.com/z9x8c7v6b5-debug-trigger-bennettpaving.com
[Fri Oct 09 13:01:43.618345 2026] [authz_core:error] [pid 2249808:tid 139705068803840] [client 35.241.186.88:0] AH01630: client denied by server configuration: /var/www/vhosts/bennettpaving.com/httpdocs/m2x8ryjakesq6mmwbh2l, referer: https://bennettpaving.com/m2x8ryjakesq6mmwbh2l
[Fri Oct 09 13:01:43.618415 2026] [authz_core:error] [pid 2249808:tid 139705068803840] [client 35.241.186.88:0] AH01630: client denied by server configuration: /var/www/vhosts/bennettpaving.com/error_docs/forbidden.html, referer: https://bennettpaving.com/m2x8ryjakesq6mmwbh2l
[Fri Oct 09 13:01:47.078644 2026] [authz_core:error] [pid 2000243:tid 139705571907328] [client 35.241.186.88:0] AH01630: client denied by serve
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 16:57:49
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.241.186.88 (88.186.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.241.186.88 (88.186.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 12:57:42.382421 2026] [security2:error] [pid 29699:tid 29699] [client 35.241.186.88:57446] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||benlbrown.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "benlbrown.com"] [uri "/z9x8c7v6b5-debug-trigger-benlbrown.com"] [unique_id "askdBodR-96aTMPA8DV8lAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-09 16:33:13
(2 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-09 16:32:44
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.241.186.88 (88.186.241.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.241.186.88 (88.186.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 12:32:39.229334 2026] [security2:error] [pid 21860:tid 21860] [client 35.241.186.88:41986] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bendersite.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bendersite.com"] [uri "/z9x8c7v6b5-debug-trigger-bendersite.com"] [unique_id "askXJzN2VvHKwbpmJUKILQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-10-09 16:23:09
(3 hours ago)
(mod_security) mod_security (id:930130) triggered by 35.241.186.88 (BE/Belgium/88.186.241.35.bc.goog ...
show more
(mod_security) mod_security (id:930130) triggered by 35.241.186.88 (BE/Belgium/88.186.241.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐บ๐ธ
Mundo Bueno
2026-10-09 16:11:05
(3 hours ago)
[ISILIA Protection v2.3] Tentative d'accรจs: /.env.old [RATE LIMITED - 1800s quarantine] | Pays: BE | ...
show more
[ISILIA Protection v2.3] Tentative d'accรจs: /.env.old [RATE LIMITED - 1800s quarantine] | Pays: BE | UA: Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)
show less
Hacking
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-09 16:06:47
(3 hours ago)
[ti-05al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-05al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 35.241.186.88 - - [09/Oct/2026:18:06:28 +0200] "GET /jetwf2z8zfb96uhxmjkf HTTP/2.0" 404 1878 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
35.241.186.88 - - [09/Oct/2026:18:06:28 +0200] "GET /6p1w6ubya9dgz8ld38k6 HTTP/2.0" 404 1920 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
35.241.186.88 - - [09/Oct/2026:18:06:28 +0200] "GET /z9x8c7v6b5-debug-trigger-bellspalsycare.com HTTP/2.0" 404 1920 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
35.241.186.88 - - [09/Oct/2026:18:06:28 +0200] "GET /wp-json HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605
...
show less
Bad Web Bot
Web App Attack