๐ณ๐ฑ
homeshowdomain.nl
2026-09-20 22:01:31
(19 hours ago)
Auto-ban: >3000 req/min op 2026-09-20
Web App Attack
SSH
Hacking
Anonymous
2026-09-20 15:29:33
(1 day ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-20 15:18:45
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.252.156.81 (81.156.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.156.81 (81.156.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 11:18:38.796033 2026] [security2:error] [pid 29174:tid 29174] [client 35.252.156.81:56902] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||veneerdent.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "veneerdent.com"] [uri "/z9x8c7v6b5-debug-trigger-veneerdent.com"] [unique_id "aq_5TtB8PfnhN-CkS_I62AAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
venar
2026-09-20 15:12:09
(1 day ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
Anonymous
2026-09-20 14:57:53
(1 day ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐ฉ๐ช
XICTRON
2026-09-20 14:55:07
(1 day ago)
ModSecurity rule violation detected by Fail2Ban
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:23:41
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.252.156.81 (81.156.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.156.81 (81.156.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:23:34.211875 2026] [security2:error] [pid 4894:tid 4894] [client 35.252.156.81:60138] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ronnycarrera.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ronnycarrera.com"] [uri "/z9x8c7v6b5-debug-trigger-ronnycarrera.com"] [unique_id "aq_sZl7k-a3LUWs1rXHP-AAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 14:01:10
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.252.156.81 (81.156.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.156.81 (81.156.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 10:01:05.176220 2026] [security2:error] [pid 24956:tid 24956] [client 35.252.156.81:59026] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mhext.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mhext.com"] [uri "/z9x8c7v6b5-debug-trigger-mhext.com"] [unique_id "aq_nIRz_FaIMUxc7ANXjHAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:43:24
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.252.156.81 (81.156.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.156.81 (81.156.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:43:16.554215 2026] [security2:error] [pid 20379:tid 20379] [client 35.252.156.81:44598] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ink2wear.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ink2wear.com"] [uri "/rclone.conf"] [unique_id "aq_i9Ac8pLKJsve8y8gsWAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
svr
2026-09-20 13:31:15
(1 day ago)
Abusive Automated Web Scanner
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 13:25:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 35.252.156.81 (81.156.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.156.81 (81.156.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:25:08.195993 2026] [security2:error] [pid 10095:tid 10117] [client 35.252.156.81:43280] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "exede-sales.com"] [uri "/docker/.env"] [unique_id "aq_etHFmCuI-OtmwC46BlwAAAFM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2026-09-20 13:15:03
(1 day ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐ซ๐ท
demomodule
2026-09-20 13:14:42
(1 day ago)
PrestaShop Security Module: suspicious probe path detected (/.env)
Web App Attack
๐ฉ๐ช
LRob
2026-09-20 13:10:21
(1 day ago)
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 (Macintosh; Inte ...
show more
Declared crawler ignoring robots.txt and the refusals it is given | ua: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatibl (+2 more) | path: /.htpasswd (+8 more) | 2026-09-20 13:10 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-20 13:09:57
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.252.156.81 (81.156.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.156.81 (81.156.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 09:09:50.238333 2026] [security2:error] [pid 29705:tid 29705] [client 35.252.156.81:54940] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||coconut-homes.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "coconut-homes.com"] [uri "/z9x8c7v6b5-debug-trigger-coconut-homes.com"] [unique_id "aq_bHirHabnswzNt-Mks0wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack