๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(1 day ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฒ๐ฝ
octageeks.com
2026-09-23 04:13:02
(1 day ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐บ๐ธ
mnsf
2026-09-23 01:05:16
(1 day ago)
Abuse Detected (9)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 00:40:53
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.252.129.55 (55.129.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.129.55 (55.129.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 20:40:47.018391 2026] [security2:error] [pid 26027:tid 26027] [client 35.252.129.55:50550] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ww-bbs.com|F|2"] [data ".ww-bbs.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ww-bbs.com"] [uri "/z9x8c7v6b5-debug-trigger-www.ww-bbs.com"] [unique_id "arMgDysKl2Drg135kiZLeAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 23:30:06
(2 days ago)
suspicious request in access.log
Web App Attack
๐ช๐ธ
robotstxt
2026-09-22 23:16:32
(2 days ago)
35.252.129.55 - - [22/Sep/2026:23:15:30 +0000] "POST / HTTP/2.0" 403 31911 "-" "Mozilla/5.0 (compati ...
show more
35.252.129.55 - - [22/Sep/2026:23:15:30 +0000] "POST / HTTP/2.0" 403 31911 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" "-" edge="35.252.129.55"
35.252.129.55 - - [22/Sep/2026:23:15:30 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 10506 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.252.129.55"
35.252.129.55 - - [22/Sep/2026:23:15:30 +0000] "GET /z9x8c7v6b5-debug-trigger-www.wpnoticias.com HTTP/2.0" 403 10980 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" "-" edge="35.252.129.55"
35.252.129.55 - - [22/Sep/2026:23:15:30 +0000] "GET /dist/.vite/manifest.json HTTP/2.0" 403 10485 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.252.129.55"
35.252.129.55 - - [22/Sep/2026:23:15:30 +0000] "GET /build/manifest.json HTTP/2.0" 403 10485 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKi
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 23:14:46
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.252.129.55 (55.129.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.129.55 (55.129.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 19:14:39.870290 2026] [security2:error] [pid 15644:tid 15644] [client 35.252.129.55:50652] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.wplusw.com|F|2"] [data ".wplusw.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.wplusw.com"] [uri "/z9x8c7v6b5-debug-trigger-www.wplusw.com"] [unique_id "arML35M99z5J_qNIGe0_yAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 22:44:19
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.252.129.55 (55.129.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.129.55 (55.129.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:44:11.208089 2026] [security2:error] [pid 27342:tid 27342] [client 35.252.129.55:56250] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.worshipconcert.com|F|2"] [data ".worshipconcert.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.worshipconcert.com"] [uri "/z9x8c7v6b5-debug-trigger-www.worshipconcert.com"] [unique_id "arMEu030B3xY3juoTmMCqQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 22:02:28
(2 days ago)
[ti-26al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-26al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.252.129.55 - - [23/Sep/2026:00:02:27 +0200] "GET /.env.production HTTP/1.1" 301 590 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
35.252.129.55 - - [23/Sep/2026:00:02:27 +0200] "GET /.env HTTP/1.1" 301 568 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
IVski.com
2026-09-22 18:45:16
(2 days ago)
IVski WAF | Next.js Server Action probe
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:41:39
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.252.129.55 (55.129.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.129.55 (55.129.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:41:33.659603 2026] [security2:error] [pid 25495:tid 25495] [client 35.252.129.55:48380] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.worldcalendar.com.amybeam.com|F|2"] [data ".worldcalendar.com.amybeam.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.worldcalendar.com.amybeam.com"] [uri "/z9x8c7v6b5-debug-trigger-www.worldcalendar.com.amybeam.com"] [unique_id "arKvvS-qTt924apxLxUk3wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:37:20
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.252.129.55 (55.129.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.129.55 (55.129.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:37:14.240426 2026] [security2:error] [pid 9633:tid 9633] [client 35.252.129.55:41592] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bamedica.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bamedica.com"] [uri "/z9x8c7v6b5-debug-trigger-bamedica.com"] [unique_id "arKgqvdguQskJTRF8SLrYQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
robotstxt
2026-09-22 15:29:18
(2 days ago)
35.252.129.55 - - [22/Sep/2026:15:28:56 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 36225 "-" "Mo ...
show more
35.252.129.55 - - [22/Sep/2026:15:28:56 +0000] "GET /.vite/manifest.json HTTP/2.0" 403 36225 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "35.252.129.55" edge="162.159.106.182"
35.252.129.55 - - [22/Sep/2026:15:28:59 +0000] "GET /.env.example HTTP/2.0" 403 2 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)" "35.252.129.55" edge="172.71.151.27"
35.252.129.55 - - [22/Sep/2026:15:28:59 +0000] "GET /.env.production HTTP/2.0" 403 2 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)" "35.252.129.55" edge="172.71.151.27"
35.252.129.55 - - [22/Sep/2026:15:28:59 +0000] "GET /.env.local HTTP/2.0" 403 2 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)" "35.252.129.55" edge="172.71.151.27"
35.252.129.55 - - [22/Sep/2026:15:28:59 +0000] "GET /.env.backup HTTP/2.0" 403 2 "-" "Mozilla/5.0 (compatible; Qwenbot/
...
show less
Web App Attack
๐ซ๐ท
demomodule
2026-09-22 15:00:11
(2 days ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:56:14
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.252.129.55 (55.129.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.129.55 (55.129.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:56:05.856972 2026] [security2:error] [pid 20729:tid 20729] [client 35.252.129.55:41006] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dockrockukiah.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dockrockukiah.com"] [uri "/z9x8c7v6b5-debug-trigger-dockrockukiah.com"] [unique_id "arKXBWk9Pc9nP4aanNS1FgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack