๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(5 hours ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
Anonymous
2026-09-23 00:55:03
(10 hours ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 23:59:35
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.247.153.244 (244.153.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.247.153.244 (244.153.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 19:59:30.038099 2026] [security2:error] [pid 21960:tid 21960] [client 35.247.153.244:46548] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ultrakid.com|F|2"] [data ".ultrakid.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ultrakid.com"] [uri "/z9x8c7v6b5-debug-trigger-www.ultrakid.com"] [unique_id "arMWYnOkOq6TM2D865-GGgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 23:55:19
(11 hours ago)
sensitive path probe detected by fail2ban
...
Port Scan
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-22 21:43:40
(13 hours ago)
20 attempts against mh-misbehave-ban on burne
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
magnetosphere-tarpit
2026-09-22 19:45:24
(15 hours ago)
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not ...
show more
Automated web scanner: repeatedly probed for .env, .git, wp-admin and PHP webshell paths that do not exist on this host. Tarpitted, then banned: 10 requests within 24h0m0s
show less
Port Scan
Bad Web Bot
Web App Attack
๐ฉ๐ช
Bedios GmbH
2026-09-22 19:15:00
(16 hours ago)
Login credentials theft attempt
Hacking
๐ฉ๐ช
IVski.com
2026-09-22 19:08:56
(16 hours ago)
IVski WAF | Next.js Server Action probe
Hacking
Brute-Force
Web App Attack
๐ฉ๐ช
rh24
2026-09-22 18:31:27
(16 hours ago)
(badbots) Bad bot user-agent [redacted] from 35.247.153.244 (SG/Singapore/244.153.247.35.bc.googleus ...
show more
(badbots) Bad bot user-agent [redacted] from 35.247.153.244 (SG/Singapore/244.153.247.35.bc.googleusercontent.com)
show less
Hacking
๐ฉ๐ช
sternwart
2026-09-22 16:29:04
(18 hours ago)
Automatisch erkannt: Zugriff auf /config/.env (ukraine-top-travel.com)
Web App Attack
Bad Web Bot
๐บ๐ธ
NXTwoThou
2026-09-22 15:34:06
(19 hours ago)
/..%2f.env
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:29:41
(19 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.247.153.244 (244.153.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.247.153.244 (244.153.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:29:33.971725 2026] [security2:error] [pid 1292:tid 1292] [client 35.247.153.244:50988] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "undergroundh2o.com"] [uri "/.env"] [unique_id "arKe3bM_IkzvEFauM66hxQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:59:17
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.247.153.244 (244.153.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.247.153.244 (244.153.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:59:13.459481 2026] [security2:error] [pid 839538:tid 839538] [client 35.247.153.244:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||uni-plan.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "uni-plan.com"] [uri "/z9x8c7v6b5-debug-trigger-uni-plan.com"] [unique_id "arKXwUQ7n563V8kJpXdZfgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:37:35
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.247.153.244 (244.153.247.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.247.153.244 (244.153.247.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:37:29.298048 2026] [security2:error] [pid 6763:tid 6763] [client 35.247.153.244:52824] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||unified-dispatch.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "unified-dispatch.com"] [uri "/z9x8c7v6b5-debug-trigger-unified-dispatch.com"] [unique_id "arKSqQ5F83LgWbm6tlpXLQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 14:25:00
(20 hours ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack