๐ณ๐ฑ
Mangelot Hosting
2026-09-22 09:08:36
(12 minutes ago)
(modsecurity) srv104 ModSecurity 35.241.222.172 (BE/Belgium/172.222.241.35.bc.googleusercontent.com) ...
show more
(modsecurity) srv104 ModSecurity 35.241.222.172 (BE/Belgium/172.222.241.35.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
IndigoRidge
2026-09-22 09:04:10
(17 minutes ago)
35.241.222.172 - - [22/Sep/2026:05:04:05 -0400] "GET /.git/config HTTP/1.1" 403 5497 "-" "Mozilla/5. ...
show more
35.241.222.172 - - [22/Sep/2026:05:04:05 -0400] "GET /.git/config HTTP/1.1" 403 5497 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)"
35.241.222.172 - - [22/Sep/2026:05:04:05 -0400] "GET /.aws/credentials HTTP/1.1" 404 51392 "-" "Mozilla/5.0 (compatible; ChatGLM-Spider/1.0; +https://zhipuai.cn/)"
35.241.222.172 - - [22/Sep/2026:05:04:09 -0400] "GET /.env HTTP/1.1" 403 5497 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:57:10
(24 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.241.222.172 (172.222.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.241.222.172 (172.222.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:57:06.400592 2026] [security2:error] [pid 23156:tid 23156] [client 35.241.222.172:45378] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thekingtones.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thekingtones.com"] [uri "/z9x8c7v6b5-debug-trigger-thekingtones.com"] [unique_id "arJC4t2XIKkVBhXBHs7itwAAADs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:10:10
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.241.222.172 (172.222.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.241.222.172 (172.222.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:10:04.198461 2026] [security2:error] [pid 25824:tid 25824] [client 35.241.222.172:52066] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||thelowensteinfamily.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thelowensteinfamily.com"] [uri "/z9x8c7v6b5-debug-trigger-thelowensteinfamily.com"] [unique_id "arI33F1Qy-mFsQdwS3BALwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 07:53:32
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.241.222.172 (172.222.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.241.222.172 (172.222.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 03:53:27.267551 2026] [security2:error] [pid 10816:tid 10839] [client 35.241.222.172:48826] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "themarketplacelb.com"] [uri "/apps/.env"] [unique_id "arIz94qPBhPpa7d3o1CzkQAAAZI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-22 07:50:27
(1 hour ago)
Web attack/malicious scanning detected
Web App Attack
๐ฎ๐น
VHosting
2026-09-22 07:40:04
(1 hour ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 07:32:11
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.241.222.172 (172.222.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.241.222.172 (172.222.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 03:32:06.812452 2026] [security2:error] [pid 32319:tid 32319] [client 35.241.222.172:51734] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||twilighthackers.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "twilighthackers.com"] [uri "/z9x8c7v6b5-debug-trigger-twilighthackers.com"] [unique_id "arIu9mr0hXGBn3v3gGrdrgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 07:30:10
(1 hour ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ณ๐ฑ
Site.eu
2026-09-22 07:28:40
(1 hour ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-09-22 07:28:06
(1 hour ago)
Web App Attack
Brute-Force
Exploited Host
Web App Attack
๐น๐ท
ycoskun41
2026-09-22 07:27:34
(1 hour ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 07:14:13
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.241.222.172 (172.222.241.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.241.222.172 (172.222.241.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 03:14:07.865421 2026] [security2:error] [pid 814:tid 814] [client 35.241.222.172:44426] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||zeta-me.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "zeta-me.com"] [uri "/z9x8c7v6b5-debug-trigger-zeta-me.com"] [unique_id "arIqv7IU01r_SpmYNH7XzwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
polycoda
2026-09-22 06:29:00
(2 hours ago)
AutoBlock: ๐ก Port Scan (Non Decay-Based)
Port Scan