๐ฆ๐บ
artful
2026-05-30 06:37:00
(1 week ago)
Excessive errors ~1k in recent hours
Web App Attack
๐ฌ๐ง
CrystalMaker
2026-05-30 05:20:43
(1 week ago)
Vulnerability scan - GET /.htaccess; GET /.htpasswd
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-30 04:51:58
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.252.186.10 (10.186.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.186.10 (10.186.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 00:51:50.603100 2026] [security2:error] [pid 21095:tid 21095] [client 35.252.186.10:52834] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||192.64.150.235|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "192.64.150.235"] [uri "/.config/gcloud/credentials.db"] [unique_id "ahps5pCbYDZZ3tQmjcxR0wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฟ
Antinson
2026-05-30 04:15:42
(1 week ago)
Scraping with a high error ratio and request rate
Bad Web Bot
๐ฆ๐บ
2000cn.com.au
2026-05-30 04:00:53
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-05-30 02:54:16
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.252.186.10 (10.186.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.186.10 (10.186.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 22:54:09.521182 2026] [security2:error] [pid 21023:tid 21023] [client 35.252.186.10:53290] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||192.64.151.28|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "192.64.151.28"] [uri "/.config/gcloud/credentials.db"] [unique_id "ahpRUfGa3mjquMvW7k8hXAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-05-30 00:16:57
(1 week ago)
74 attempts against mh-misbehave-ban on runners01-perf
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Mediashaker
2026-05-29 22:55:33
(1 week ago)
(CT) IP 35.252.186.10 (US/United States/10.186.252.35.bc.googleusercontent.com) found to have 765 co ...
show more
(CT) IP 35.252.186.10 (US/United States/10.186.252.35.bc.googleusercontent.com) found to have 765 connections
show less
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-05-29 04:17:30
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.252.186.10 (10.186.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.186.10 (10.186.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 00:17:23.571786 2026] [security2:error] [pid 31101:tid 31101] [client 35.252.186.10:55438] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||192.64.150.166|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "192.64.150.166"] [uri "/.config/gcloud/credentials.db"] [unique_id "ahkTU5j1P8VFSFT6FZ8yGgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-05-29 01:58:06
(1 week ago)
[Fri May 29 03:58:04.700725 2026] [authz_core:error] [pid 877190:tid 877190] [client 35.252.186.10:3 ...
show more
[Fri May 29 03:58:04.700725 2026] [authz_core:error] [pid 877190:tid 877190] [client 35.252.186.10:35566] AH01630: client denied by server configuration: /var/www/html/wordpress/.htpasswd
[Fri May 29 03:58:04.744677 2026] [authz_core:error] [pid 877201:tid 877201] [client 35.252.186.10:35582] AH01630: client denied by server configuration: /var/www/html/wordpress/.htaccess
...
show less
Hacking
Brute-Force