Anonymous
2026-10-01 15:53:58
(13 hours ago)
IP matched detection query 50 and more bad rqs apache.
Hacking
Bad Web Bot
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 15:23:13
(14 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.246.134.151 (151.134.246.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.246.134.151 (151.134.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:23:07.735587 2026] [security2:error] [pid 10407:tid 10407] [client 35.246.134.151:36572] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||topografiazgs.com.disenowebprofesional.com|F|2"] [data ".com.disenowebprofesional.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "topografiazgs.com.disenowebprofesional.com"] [uri "/z9x8c7v6b5-debug-trigger-topografiazgs.com.disenowebprofesional.com"] [unique_id "ar5627RQZpegtvw6iQahxAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
masterguru
2026-10-01 15:22:44
(14 hours ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
๐ธ๐ช
vaia.cloud
2026-10-01 14:55:01
(14 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
๐บ๐ธ
interbiznw.com
2026-10-01 14:28:35
(15 hours ago)
sql-malicious-activity
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 14:16:30
(15 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.246.134.151 (151.134.246.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.246.134.151 (151.134.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 10:16:23.193754 2026] [security2:error] [pid 11256:tid 11256] [client 35.246.134.151:37608] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "dashboard.wholesalelivelobsters.com"] [uri "/@fs/app/.env"] [unique_id "ar5rN1jRKob5waP_36XqFwAAAC4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
dalslab ltd
2026-10-01 13:48:52
(15 hours ago)
[01/Oct/2026:15:48:52 +0200] - 404 404 - GET https auth.dalslab.com "/qf5uc1i85n00h5h1e7t9" [Client ...
show more
[01/Oct/2026:15:48:52 +0200] - 404 404 - GET https auth.dalslab.com "/qf5uc1i85n00h5h1e7t9" [Client 35.246.134.151] [Length 1599] [Gzip -] [Sent-to 10.1.1.240] "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" "-"
[01/Oct/2026:15:48:52 +0200] - 404 404 - GET https auth.dalslab.com "/.vite/manifest.json" [Client 35.246.134.151] [Length 1598] [Gzip -] [Sent-to 10.1.1.240] "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-"
[01/Oct/2026:15:48:52 +0200] - 403 403 - POST https auth.dalslab.com "/" [Client 35.246.134.151] [Length 959] [Gzip -] [Sent-to 10.1.1.240] "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "-"
[01/Oct/2026:15:48:52 +0200] - 404 404 - GET https auth.dalslab.com "/model/info" [Client 35.246.134.151] [Length 1600] [Gzip -] [Sent-to 10.1.1.240] "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" "-"
[01/Oct/2026:15:48:52 +0200] - 404 404 - GET https auth.dalslab.com "/dist/manifest.
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
๐น๐ญ
thaizone.com
2026-10-01 13:38:15
(16 hours ago)
Brute Force Attack on a Web Resources (repeated 404) #1
DDoS Attack
Web Spam
Brute-Force
Web App Attack
Anonymous
2026-10-01 13:35:08
(16 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
Anonymous
2026-10-01 13:30:42
(16 hours ago)
2026/10/01 13:30:40 [error] 2479711#2479711: *506222 [client 35.246.134.151] ModSecurity: Access den ...
show more
2026/10/01 13:30:40 [error] 2479711#2479711: *506222 [client 35.246.134.151] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `40' ) [file "/usr/local/owasp-modsecurity-crs-4.11.0/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "222"] [id "949110"] [rev ""] [msg "Inbound Anomaly Score Exceeded (Total Score: 40)"] [data ""] [severity "0"] [ver "OWASP_CRS/4.29.0"] [maturity "0"] [accuracy "0"] [tag "anomaly-evaluation"] [tag "OWASP_CRS"] [hostname "logiciensoft.com"] [uri "/"] [unique_id "179086144068.415324"] [ref ""], client: 35.246.134.151, server: logiciensoft.com, request: "POST / HTTP/2.0", host: "logiciensoft.com"
2026/10/01 13:30:40 [error] 2479711#2479711: *506222 [client 35.246.134.151] ModSecurity: Access denied with code 403 (phase 2). Matched "Operator `Ge' with parameter `5' against variable `TX:BLOCKING_INBOUND_ANOMALY_SCORE' (Value: `40' ) [file "/usr/local/owasp-modsecu
...
show less
Brute-Force
Anonymous
2026-10-01 13:14:57
(16 hours ago)
Aggressive web scan
Web App Attack
๐ฉ๐ช
updown.io
2026-10-01 13:13:44
(16 hours ago)
{"level":"info","ts":1790860423.6065047,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790860423.6065047,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.246.134.151","remote_port":"58426","client_ip":"35.246.134.151","proto":"HTTP/2.0","method":"GET","host":"status.myerpserver.com","uri":"/dist/manifest.json","headers":{"Priority":["u=0, i"],"User-Agent":["Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36"],"Accept":["text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,*/*;q=0.8"],"X-Nextjs-Data":["1"],"Upgrade-Insecure-Requests":["1"],"Sec-Fetch-Mode":["navigate"],"Sec-Fetch-Dest":["document"],"Sec-Ch-Ua-Platform":["\"Android\""],"Accept-Encoding":["gzip, deflate, br, zstd"],"Sec-Ch-Ua":["\"Chromium\";v=\"152\", \"Not?A_Brand\";v=\"24\", \"Google Chrome\";v=\"152\""],"Sec-Ch-Ua-Mobile":["?1"],"Sec-Fetch-User":["?1"],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middle
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:03:26
(16 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.246.134.151 (151.134.246.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 35.246.134.151 (151.134.246.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:03:20.718900 2026] [security2:error] [pid 10632:tid 10632] [client 35.246.134.151:59094] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "toxicnation.com"] [uri "/z9x8c7v6b5-debug-trigger-toxicnation.com"] [unique_id "ar5aGPJtWhIpFc5Z7Txd5gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-10-01 12:55:09
(16 hours ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ฌ๐ง
noise.agency
2026-10-01 12:46:07
(17 hours ago)
35.246.134.151 (DE/Germany/151.134.246.35.bc.googleusercontent.com), more than 10 Apache 403 hits
Hacking