๐ฟ๐ฆ
conure.sh
2026-10-09 19:07:22
(3 minutes ago)
csagent: score 24.5: 404 noise floor x18, secrets grab x2; 1 domain(s) in 2s
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 19:01:23
(9 minutes ago)
(mod_security) mod_security (id:210580) triggered by 8.229.66.185 (185.66.229.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210580) triggered by 8.229.66.185 (185.66.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:01:17.890877 2026] [security2:error] [pid 6556:tid 6606] [client 8.229.66.185:52664] ModSecurity: Access denied with code 403 (phase 2). Matched phrase "proc/self/environ" at ARGS:path. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/08_Global_Other.conf"] [line "57"] [id "210580"] [rev "2"] [msg "COMODO WAF: OS File Access Attempt||hdtv55.com|F|2"] [data "Matched Data: proc/self/environ found within ARGS:path: /proc/self/environ"] [severity "CRITICAL"] [tag "CWAF"] [tag "Other"] [hostname "hdtv55.com"] [uri "/api/fs/read"] [unique_id "ask5_dj3Uf9BVU_qD99h0QAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 18:40:14
(31 minutes ago)
(mod_security) mod_security (id:210730) triggered by 8.229.66.185 (185.66.229.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 8.229.66.185 (185.66.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 14:40:10.842641 2026] [security2:error] [pid 1069:tid 1069] [client 8.229.66.185:40624] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||handmrenovationsllc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "handmrenovationsllc.com"] [uri "/z9x8c7v6b5-debug-trigger-handmrenovationsllc.com"] [unique_id "ask1CmbxTFS9Obnr00BKIwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-09 18:25:43
(45 minutes ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-09 18:16:21
(54 minutes ago)
(mod_security) mod_security (id:210730) triggered by 8.229.66.185 (185.66.229.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 8.229.66.185 (185.66.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 14:16:17.725047 2026] [security2:error] [pid 30861:tid 30861] [client 8.229.66.185:51866] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gslandservices.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gslandservices.com"] [uri "/z9x8c7v6b5-debug-trigger-gslandservices.com"] [unique_id "askvcZKlnpMb78zCUZQOpQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-10-09 18:08:40
(1 hour ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
mnsf
2026-10-09 18:05:45
(1 hour ago)
Too many Status 40X (16)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 17:57:32
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 8.229.66.185 (185.66.229.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 8.229.66.185 (185.66.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 13:57:27.285488 2026] [security2:error] [pid 1391:tid 1391] [client 8.229.66.185:37220] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||greatnorthernstrategies.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "greatnorthernstrategies.com"] [uri "/z9x8c7v6b5-debug-trigger-greatnorthernstrategies.com"] [unique_id "askrB9zDcY29pl-HtbjE2QAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 17:39:26
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 8.229.66.185 (185.66.229.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 8.229.66.185 (185.66.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 13:39:19.558940 2026] [security2:error] [pid 10392:tid 10392] [client 8.229.66.185:60426] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||goodpage.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "goodpage.com"] [uri "/z9x8c7v6b5-debug-trigger-goodpage.com"] [unique_id "askmx4qpJte3VtZn_Cm1uQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 17:22:22
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 8.229.66.185 (185.66.229.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210492) triggered by 8.229.66.185 (185.66.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 13:22:15.192295 2026] [security2:error] [pid 27527:tid 27527] [client 8.229.66.185:0] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "globetechsecurities.com"] [uri "/@fs/app/.env"] [unique_id "askix0dhIMB_8u4eYjf9twAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-10-09 16:53:57
(2 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐น๐ท
ycoskun41
2026-10-09 16:50:04
(2 hours ago)
fail2ban: plesk-modsecurity jail on genckocaeli.com
Web App Attack
๐ฉ๐ช
svr
2026-10-09 16:44:04
(2 hours ago)
Abusive Automated Web Scanner
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 16:43:21
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 8.229.66.185 (185.66.229.8.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 8.229.66.185 (185.66.229.8.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 12:43:16.305205 2026] [security2:error] [pid 20806:tid 20806] [client 8.229.66.185:51562] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gazelleplanner.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gazelleplanner.com"] [uri "/z9x8c7v6b5-debug-trigger-gazelleplanner.com"] [unique_id "askZpLSr_i1vkuWtMqHOqAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-09 16:33:56
(2 hours ago)
Web application attack detected.
Web App Attack