๐ง๐ช
cmbplf
2026-10-09 22:40:19
(1 day ago)
126 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐ช๐ธ
pipeline.es
2026-10-09 21:14:11
(1 day ago)
Web scanning / probing for vulnerable paths | URL: /.env.prod | Evidence: focus-viagens.com 35.253.2 ...
show more
Web scanning / probing for vulnerable paths | URL: /.env.prod | Evidence: focus-viagens.com 35.253.237.145 - - [09/Oct/2026:23:12:38 +0200] \"GET /.env.prod HTTP/2.0\" 404 22409 \"-\" \"Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)\" GEOIP_COUNTRY_CODE=US 18152 | ASN: GOOGLE-CLOUD-PLATFORM | Country: US
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 20:52:33
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.253.237.145 (145.237.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.253.237.145 (145.237.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 16:52:27.585019 2026] [security2:error] [pid 18871:tid 18871] [client 35.253.237.145:60020] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||five21.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "five21.com"] [uri "/z9x8c7v6b5-debug-trigger-five21.com"] [unique_id "aslUC-092cncbtRZl2gt8AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 20:09:09
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.253.237.145 (145.237.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.253.237.145 (145.237.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 16:09:02.193378 2026] [security2:error] [pid 4498:tid 4498] [client 35.253.237.145:56696] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fancycleaners.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fancycleaners.com"] [uri "/z9x8c7v6b5-debug-trigger-fancycleaners.com"] [unique_id "aslJ3hAkDPzCRDCYu0vcgQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 19:52:23
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.253.237.145 (145.237.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.253.237.145 (145.237.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:52:19.557466 2026] [security2:error] [pid 18212:tid 18212] [client 35.253.237.145:51228] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||exresearch.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "exresearch.com"] [uri "/z9x8c7v6b5-debug-trigger-exresearch.com"] [unique_id "aslF88EE0gsbkDzeO7FFMQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-09 19:40:02
(1 day ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-09 19:35:52
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.253.237.145 (145.237.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.253.237.145 (145.237.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:35:44.831265 2026] [security2:error] [pid 6070:tid 6070] [client 35.253.237.145:53716] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||eventsetcinc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "eventsetcinc.com"] [uri "/z9x8c7v6b5-debug-trigger-eventsetcinc.com"] [unique_id "aslCEO4vpaTXIafns9WWsQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
vanderhost
2026-10-09 19:30:08
(2 days ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/gcp-credentials. ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /config/gcp-credentials.json via rule: /config
show less
Web App Attack
Bad Web Bot
๐บ๐ธ
IndigoRidge
2026-10-09 19:09:39
(2 days ago)
35.253.237.145 - - [09/Oct/2026:15:09:39 -0400] "GET /.ssh/id_rsa HTTP/1.1" 404 4800 "-" "Mozilla/5. ...
show more
35.253.237.145 - - [09/Oct/2026:15:09:39 -0400] "GET /.ssh/id_rsa HTTP/1.1" 404 4800 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
35.253.237.145 - - [09/Oct/2026:15:09:39 -0400] "GET /static../.env HTTP/1.1" 403 4803 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
35.253.237.145 - - [09/Oct/2026:15:09:39 -0400] "GET /@fs/app/.env?raw?? HTTP/1.1" 403 4803 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 18:58:47
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.253.237.145 (145.237.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.253.237.145 (145.237.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 14:58:41.297545 2026] [security2:error] [pid 20268:tid 20268] [client 35.253.237.145:46530] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||entertainmentcapitol.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "entertainmentcapitol.com"] [uri "/z9x8c7v6b5-debug-trigger-entertainmentcapitol.com"] [unique_id "ask5YUQ1tqgqExr37Vp0rgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-10-09 18:57:03
(2 days ago)
[FriOct0920:57:01.3844032026][security2:error][pid27444:tid27610][client35.253.237.145:0]ModSecurity ...
show more
[FriOct0920:57:01.3844032026][security2:error][pid27444:tid27610][client35.253.237.145:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Stringmatchwithin\".asa/.asax/.ascx/.backup/.bak/.bat/.cdx/.cer/.cfg/.cmd/.com/.config/.conf/.cs/.csproj/.csr/.dat/.db/.dbf/.dll/.dos/.htr/.htw/.ida/.idc/.idq/.inc/.ini/.key/.licx/.lnk/.log/.mdb/.old/.pass/.pdb/.pol/.printer/.pwd/.rdb/.resources/.resx/.sql/.swp/.sys/.vb/.vbs/.vbproj/.vsdisco/.webinfo/.xsx/\"atTX:extension.[file\"/etc/apache2/conf.d/modsec_rules/00_asl_zz_strict.conf\"][line\"91\"][id\"390716\"][rev\"2\"][msg\"Atomicorp.comWAFRules:URLfileextensionisrestrictedbypolicy\"][data\".com\"][severity\"ERROR\"][hostname\"enricoalbertini.com\"][uri\"/z9x8c7v6b5-debug-trigger-enricoalbertini.com\"][unique_id\"ask4_UPBvekdYlb63nn3ogAAAU4\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 18:38:23
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.253.237.145 (145.237.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.253.237.145 (145.237.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 14:38:17.844984 2026] [security2:error] [pid 9349:tid 9349] [client 35.253.237.145:37098] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||emelecsrl.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "emelecsrl.com"] [uri "/z9x8c7v6b5-debug-trigger-emelecsrl.com"] [unique_id "ask0maf4pcQ2Xt1LXwPvcwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 18:03:46
(2 days ago)
(mod_security) mod_security triggered on hostname [redacted])
SQL Injection
๐ฉ๐ช
bazter.pro
2026-10-09 18:02:44
(2 days ago)
Fail2Ban: apache-ratelimit - 20 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 17:48:59
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 35.253.237.145 (145.237.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.253.237.145 (145.237.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 13:48:56.362991 2026] [security2:error] [pid 28594:tid 28594] [client 35.253.237.145:36478] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ecodesarrollourbano.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ecodesarrollourbano.com"] [uri "/z9x8c7v6b5-debug-trigger-ecodesarrollourbano.com"] [unique_id "askpCFj8SAT5ofDv2CJvngAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack