Anonymous
2026-09-22 14:20:07
(4 minutes ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
Anonymous
2026-09-22 13:55:02
(29 minutes ago)
suspicious request in access.log
Web App Attack
๐ฌ๐ง
consul.to
2026-09-22 13:45:28
(38 minutes ago)
Web attack/malicious scanning detected
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-09-22 13:39:27
(44 minutes ago)
(modsecurity) srv201 ModSecurity 35.252.187.249 (US/United States/249.187.252.35.bc.googleuserconten ...
show more
(modsecurity) srv201 ModSecurity 35.252.187.249 (US/United States/249.187.252.35.bc.googleusercontent.com): 30 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:16:32
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.252.187.249 (249.187.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.187.249 (249.187.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:16:27.066391 2026] [security2:error] [pid 6732:tid 6732] [client 35.252.187.249:55784] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||zazuza.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "zazuza.com"] [uri "/z9x8c7v6b5-debug-trigger-zazuza.com"] [unique_id "arJ_q6dmMTGs3wm8ncnpJwAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:56:23
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 35.252.187.249 (249.187.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.187.249 (249.187.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:56:15.882660 2026] [security2:error] [pid 5236:tid 5236] [client 35.252.187.249:60606] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "zebax.com"] [uri "/.env.example"] [unique_id "arJ674a-95J-yuK10aGAcgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 12:31:53
(1 hour ago)
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-05al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.252.187.249 - - [22/Sep/2026:14:31:44 +0200] "GET /.env.prod HTTP/2.0" 200 3454 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 12:24:07
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.252.187.249 (249.187.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.187.249 (249.187.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:23:59.775896 2026] [security2:error] [pid 4631:tid 4631] [client 35.252.187.249:40728] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||zenmonkeyproject.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "zenmonkeyproject.com"] [uri "/z9x8c7v6b5-debug-trigger-zenmonkeyproject.com"] [unique_id "arJzX58NaGMQxJZXIHhyhAAAADU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-22 12:10:32
(2 hours ago)
cloudlinux2 fail2ban: 2026-09-22 13:49:03,410 fail2ban.filter [1598]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-22 13:49:03,410 fail2ban.filter [1598]: INFO [plesk-wordpress] Found 138.75.7.100 - 2026-09-22 13:49:03cloudlinux2 fail2ban: 2026-09-22 13:49:28,679 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 91.75.85.203 - 2026-09-22 13:49:28cloudlinux2 fail2ban: 2026-09-22 13:50:35,041 fail2ban.actions [1598]: NOTICE [plesk-modsecurity] Unban 106.222.235.156cloudlinux2 fail2ban: 2026-09-22 13:50:54,572 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 91.75.85.203 - 2026-09-22 13:50:54cloudlinux2 fail2ban: 2026-09-22 13:51:26,213 fail2ban.filter [1598]: INFO [plesk-modsecurity] Found 91.75.85.203 - 2026-09-22 13:51:26cloudlinux2 fail2ban: 2026-09-22 13:51:26,318 fail2ban.actions [1598]: NOTICE [plesk-modsecurity] Ban 91.75.85.203cloudlinux2 fail2ban: 2026-09-22 13:51:26,325 fail2ban.filter [1598]: INFO [recidive] Found 91.75.85.203 - 2026-09-22 13:51:26cloudlinux2 fail2ban: 2026-09-22 13:51:40,349 fail2ban.a
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 11:52:11
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.252.187.249 (249.187.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.187.249 (249.187.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 07:52:04.201550 2026] [security2:error] [pid 21736:tid 21736] [client 35.252.187.249:47448] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||zeta-me.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "zeta-me.com"] [uri "/z9x8c7v6b5-debug-trigger-zeta-me.com"] [unique_id "arJr5CKZoLWHY4mJnNjwDAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 10:51:18
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.252.187.249 (249.187.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.187.249 (249.187.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 06:51:09.232176 2026] [security2:error] [pid 11034:tid 11034] [client 35.252.187.249:52270] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||zheundu.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "zheundu.com"] [uri "/z9x8c7v6b5-debug-trigger-zheundu.com"] [unique_id "arJdnRQJPIjoMRZmY9jfEAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-22 09:44:38
(4 hours ago)
575 requests with url.path */@fs/*
252 requests with url.path */proc/*
Brute-Force
Bad Web Bot
๐ซ๐ท
dynamix
2026-09-22 09:43:57
(4 hours ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 08:53:57
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.252.187.249 (249.187.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.187.249 (249.187.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 04:53:51.634806 2026] [security2:error] [pid 2691:tid 2691] [client 35.252.187.249:56562] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||zoesaadeh.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "zoesaadeh.com"] [uri "/z9x8c7v6b5-debug-trigger-zoesaadeh.com"] [unique_id "arJCHwsz_qeadgBbuopjFgAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Gwyneth Llewelyn
2026-09-22 08:45:23
(5 hours ago)
2026/09/22 09:45:21 [error] 325888#325888: *1264299 access forbidden by rule, client: 35.252.187.249 ...
show more
2026/09/22 09:45:21 [error] 325888#325888: *1264299 access forbidden by rule, client: 35.252.187.249, server: zonadetestes.com, request: "GET /_nuxt/../.env HTTP/2.0", host: "zonadetestes.com"
2026/09/22 09:45:21 [error] 325888#325888: *1264291 access forbidden by rule, client: 35.252.187.249, server: zonadetestes.com, request: "GET /static../.env HTTP/2.0", host: "zonadetestes.com"
2026/09/22 09:45:21 [error] 325888#325888: *1264291 access forbidden by rule, client: 35.252.187.249, server: zonadetestes.com, request: "GET /media../.env HTTP/2.0", host: "zonadetestes.com"
show less
Brute-Force
Web App Attack