๐บ๐ธ
TPI-Abuse
2026-10-04 21:49:01
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.252.240.39 (39.240.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.240.39 (39.240.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 17:48:57.074927 2026] [security2:error] [pid 29468:tid 29468] [client 35.252.240.39:53664] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thebrotherhoodlounge.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thebrotherhoodlounge.com"] [uri "/z9x8c7v6b5-debug-trigger-thebrotherhoodlounge.com"] [unique_id "asLJyaR6nAn7feSWl6dBogAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WizardsToolkit
2026-10-04 21:42:28
(2 days ago)
tried to access server backup files
Web App Attack
๐ณ๐ฑ
Savvii
2026-10-04 21:41:04
(2 days ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 21:13:20
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.252.240.39 (39.240.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.240.39 (39.240.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 17:13:17.211065 2026] [security2:error] [pid 15086:tid 15086] [client 35.252.240.39:56830] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||theblindmantylertx.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "theblindmantylertx.com"] [uri "/z9x8c7v6b5-debug-trigger-theblindmantylertx.com"] [unique_id "asLBbbqDtvl46_28iplZFAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
stinpriza
2026-10-04 21:12:03
(2 days ago)
Web App Attack
Web App Attack
๐ฌ๐ง
consul.to
2026-10-04 20:59:12
(2 days ago)
Web attack/malicious scanning detected
Web App Attack
๐ฎ๐น
VHosting
2026-10-04 20:45:03
(2 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 20:39:38
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.252.240.39 (39.240.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.240.39 (39.240.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 16:39:34.273040 2026] [security2:error] [pid 16422:tid 16422] [client 35.252.240.39:53958] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||portlunchgroup.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "portlunchgroup.com"] [uri "/z9x8c7v6b5-debug-trigger-portlunchgroup.com"] [unique_id "asK5hux_Z8FLmcPk_AvB9gAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 20:18:58
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.252.240.39 (39.240.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.240.39 (39.240.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 16:18:52.017306 2026] [security2:error] [pid 27346:tid 27346] [client 35.252.240.39:39272] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||halotoys.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "halotoys.com"] [uri "/z9x8c7v6b5-debug-trigger-halotoys.com"] [unique_id "asK0rEkOjpUlpWjtFKMYYQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
TheDjRider
2026-10-04 20:13:28
(2 days ago)
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ba ...
show more
CrowdSec detected Web application reconnaissance. Scenario: crowdsecurity/http-probing. Automatic ban triggered. Detection time (UTC): 2026-10-04T20:13:19.431925281Z. Context: http_status=403, http_status=404
show less
Web App Attack
Anonymous
2026-10-04 20:01:50
(2 days ago)
git/env leak probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 19:59:14
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.252.240.39 (39.240.252.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.240.39 (39.240.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 15:59:07.052997 2026] [security2:error] [pid 10879:tid 10879] [client 35.252.240.39:44686] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||banis-associates.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "banis-associates.com"] [uri "/z9x8c7v6b5-debug-trigger-banis-associates.com"] [unique_id "asKwC321-G_bZpBmtFO3UQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack