๐บ๐ธ
TPI-Abuse
2026-09-23 02:52:04
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.252.255.198 (198.255.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.255.198 (198.255.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 22:51:56.946395 2026] [security2:error] [pid 11367:tid 11367] [client 35.252.255.198:53322] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.vanemby.com|F|2"] [data ".vanemby.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.vanemby.com"] [uri "/z9x8c7v6b5-debug-trigger-www.vanemby.com"] [unique_id "arM-zD6XfymuiapaS_pjBwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 02:02:06
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.252.255.198 (198.255.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.255.198 (198.255.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 22:01:58.564826 2026] [security2:error] [pid 20966:tid 20966] [client 35.252.255.198:50854] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.gevieworld.com|F|2"] [data ".gevieworld.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.gevieworld.com"] [uri "/z9x8c7v6b5-debug-trigger-www.gevieworld.com"] [unique_id "arMzFrNlhkfkgsEECeX7fwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Philister11
2026-09-23 01:04:26
(1 day ago)
CrowdSec: crowdsecurity/http-bad-user-agent (US/AS396982)
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 00:23:14
(1 day ago)
malicious scanning tool activity
Web App Attack
๐ฉ๐ช
Philister11
2026-09-23 00:20:37
(1 day ago)
CrowdSec: crowdsecurity/http-crawl-non_statics (US/AS396982)
Bad Web Bot
Web App Attack
๐ฏ๐ต
beon
2026-09-22 19:20:15
(1 day ago)
[DateTime=>2026-09-22T19:20:15Z to 2026-09-22T19:20:30Z (UTC)] , [HoneyPot_Hits=>182 times] , [Honey ...
show more
[DateTime=>2026-09-22T19:20:15Z to 2026-09-22T19:20:30Z (UTC)] , [HoneyPot_Hits=>182 times] , [HoneyPots=>/config/application.properties, /config/env/aws_credentials.env, /actuator/env, /config/secrets.yml, /actuator/configprops, /actuator/threaddump and others] , [irregular_query_Hits=>54 times] , [404targets=>/x8nhbgp5q69715w9cx5n, /k10t6u5yzou3by708nlb, /z9x8c7v6b5-debug-trigger-[mydomain], /application.yml, /bootstrap.yml, /application.properties and others] , [total_Hits=>358 times] , [hit_per_second=>23.86] , [Keyword=>WordPress, Laravel, PHP web shells, irregular query]
show less
Bad Web Bot
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 19:10:19
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.252.255.198 (198.255.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.255.198 (198.255.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:10:12.746338 2026] [security2:error] [pid 996:tid 996] [client 35.252.255.198:55148] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||321q.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "321q.com"] [uri "/z9x8c7v6b5-debug-trigger-321q.com"] [unique_id "arLSlFGutvTp2TdjCfixSgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-22 19:09:32
(1 day ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.252.255.198 (US/United States/198 ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 35.252.255.198 (US/United States/198.255.252.35.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
Anonymous
2026-09-22 18:47:29
(1 day ago)
git/env leak probe
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:17:29
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.252.255.198 (198.255.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.255.198 (198.255.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:17:21.177496 2026] [security2:error] [pid 13103:tid 13103] [client 35.252.255.198:41282] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||floorswedo.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "floorswedo.com"] [uri "/z9x8c7v6b5-debug-trigger-floorswedo.com"] [unique_id "arLGMUFO9GurFeZkEbNKsQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-22 18:13:52
(1 day ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ณ๐ด
Bots.go.to.hell
2026-09-22 17:41:32
(1 day ago)
This IP was detected by CrowdSec triggering custom/http-bad-crawler-ban
Web App Attack
Bad Web Bot
Anonymous
2026-09-22 17:40:18
(1 day ago)
SIEM ALERT AUTO REPORT
Email Spam
๐บ๐ธ
TPI-Abuse
2026-09-22 17:37:33
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.252.255.198 (198.255.252.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.252.255.198 (198.255.252.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:37:29.012362 2026] [security2:error] [pid 8763:tid 8763] [client 35.252.255.198:57216] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kronrod.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kronrod.com"] [uri "/z9x8c7v6b5-debug-trigger-kronrod.com"] [unique_id "arK82dSz7GoGTsAYhbx_hAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 17:07:05
(1 day ago)
Automated web scanner. Requested suspicious paths: /dist/.vite/manifest.json | /build/manifest.json ...
show more
Automated web scanner. Requested suspicious paths: /dist/.vite/manifest.json | /build/manifest.json | /dist/manifest.json | /.vite/manifest.json. UTC: 2026-09-22 16:28:37.
show less
Web App Attack