๐บ๐ธ
TPI-Abuse
2026-10-09 06:19:26
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.252.238.210 (210.238.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.238.210 (210.238.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 02:19:19.411291 2026] [security2:error] [pid 32602:tid 32602] [client 35.252.238.210:52154] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||amazingerection.amazingwelding.com|F|2"] [data ".amazingwelding.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "amazingerection.amazingwelding.com"] [uri "/z9x8c7v6b5-debug-trigger-amazingerection.amazingwelding.com"] [unique_id "asiHZ6sXreEfWog5lHoGaQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Operator873
2026-10-09 06:03:57
(4 hours ago)
2026/10/09 01:03:55 [error] 2359781#0: *1114680 access forbidden by rule, client: 35.252.238.210, se ...
show more
2026/10/09 01:03:55 [error] 2359781#0: *1114680 access forbidden by rule, client: 35.252.238.210, server: [OBFUSCATED], request: "GET / HTTP/1.1", host: "[OBFUSCATED]"
2026/10/09 01:03:55 [error] 2359781#0: *1114680 access forbidden by rule, client: 35.252.238.210, server: [OBFUSCATED], request: "GET / HTTP/1.1", host: "[OBFUSCATED]"
2026/10/09 01:03:55 [error] 2359781#0: *1114680 access forbidden by rule, client: 35.252.238.210, server: [OBFUSCATED], request: "GET /signin HTTP/1.1", host: "[OBFUSCATED]"
2026/10/09 01:03:55 [error] 2359781#0: *1114680 access forbidden by rule, client: 35.252.238.210, server: [OBFUSCATED], request: "GET /signin HTTP/1.1", host: "[OBFUSCATED]"
2026/10/09 01:03:55 [error] 2359781#0: *1114687 access forbidden by rule, client: 35.252.238.210, server: [OBFUSCATED], request: "POST / HTTP/1.1", host: "[OBFUSCATED]"
...
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 05:23:40
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.252.238.210 (210.238.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.238.210 (210.238.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 01:23:34.241664 2026] [security2:error] [pid 13248:tid 13248] [client 35.252.238.210:36944] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||altitudeprothemeclean.fernfieldbrooks.com|F|2"] [data ".fernfieldbrooks.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "altitudeprothemeclean.fernfieldbrooks.com"] [uri "/z9x8c7v6b5-debug-trigger-altitudeprothemeclean.fernfieldbrooks.com"] [unique_id "ash6VsqbyE5Fl7O9OrpRjgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 05:01:41
(6 hours ago)
Web App Attack
๐ฉ๐ช
raph
2026-10-09 04:27:21
(6 hours ago)
[DOT FILES] crawler *.env*, .git*, .config*, etc.
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-09 03:13:03
(7 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
antlac1
2026-10-09 02:51:31
(8 hours ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-10-09 02:48:47
(8 hours ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 02:39:25
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.252.238.210 (210.238.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.238.210 (210.238.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 22:39:19.186774 2026] [security2:error] [pid 25495:tid 25495] [client 35.252.238.210:45318] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tortoisehosting.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tortoisehosting.com"] [uri "/z9x8c7v6b5-debug-trigger-tortoisehosting.com"] [unique_id "ashT1_hgkBlHcs4mDG52yAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 02:07:19
(8 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.238.210 (210.238.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.238.210 (210.238.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 22:07:11.716989 2026] [security2:error] [pid 18043:tid 18043] [client 35.252.238.210:59542] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "providencesilverco.com"] [uri "/.htpasswd"] [unique_id "ashMT27V-XpUanx0DbOuXwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
zXero
2026-10-09 01:57:12
(9 hours ago)
Fail2Ban automatic report - jail: web-exploit
Brute-Force
SSH
DDoS Attack
๐บ๐ธ
MaxSmartCode
2026-10-09 01:43:51
(9 hours ago)
Credential brute-force attacks on webpage.
Brute-Force
SSH
Anonymous
2026-10-09 01:40:07
(9 hours ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-10-09 01:37:50
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.238.210 (210.238.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.238.210 (210.238.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:37:42.509118 2026] [security2:error] [pid 30319:tid 30319] [client 35.252.238.210:52198] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htpasswd" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "littlehorndesign.com"] [uri "/.htpasswd"] [unique_id "ashFZkrP_OD40nf8Md7ZPAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 01:22:23
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.252.238.210 (210.238.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.252.238.210 (210.238.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:22:19.830384 2026] [security2:error] [pid 23182:tid 23182] [client 35.252.238.210:55326] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "indie100.com"] [uri "/%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env"] [unique_id "ashByzG4l9hyN43dItLIwwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack