๐ฎ๐ณ
evicky2002
2026-08-09 06:00:00
(2 weeks ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ฒ๐ฝ
octageeks.com
2026-08-09 04:17:23
(2 weeks ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ฌ๐ง
WebNiraj
2026-08-08 22:41:31
(2 weeks ago)
(mod_security) mod_security (id:949110) triggered by 35.189.118.52 (GB/United Kingdom/52.118.189.35. ...
show more
(mod_security) mod_security (id:949110) triggered by 35.189.118.52 (GB/United Kingdom/52.118.189.35.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
๐บ๐ธ
legionMCCXV
2026-08-08 22:19:16
(2 weeks ago)
PHP/WordPress shell scanner on non-PHP site โ repeated requests to .php paths returning 404.
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-08 22:18:06
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 35.189.118.52 (52.118.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.189.118.52 (52.118.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 18:17:57.866538 2026] [security2:error] [pid 926249:tid 926269] [client 35.189.118.52:57060] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bestofthis.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bestofthis.com"] [uri "/z9x8c7v6b5-debug-trigger-bestofthis.com"] [unique_id "anerFRsLdeM2UDhKCl-RqgAAAVI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 20:44:42
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.189.118.52 (52.118.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.118.52 (52.118.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 16:44:39.275509 2026] [security2:error] [pid 3958870:tid 3958870] [client 35.189.118.52:55902] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "wmodradio.com"] [uri "/.git/HEAD"] [unique_id "aneVNxFSK9jzIkUdeqPYUwAAAGI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-08 20:31:03
(2 weeks ago)
[Sat Aug 08 10:15:25.865100 2026] [authz_core:error] [pid 16738] [client 35.189.118.52:40086] AH0163 ...
show more
[Sat Aug 08 10:15:25.865100 2026] [authz_core:error] [pid 16738] [client 35.189.118.52:40086] AH01630: client denied by server configuration: /var/www/api/.htpasswd
[Sat Aug 08 10:15:29.412191 2026] [authz_core:error] [pid 17137] [client 35.189.118.52:40102] AH01630: client denied by server configuration: /var/www/api/server-status
[Sat Aug 08 15:50:28.271071 2026] [authz_core:error] [pid 7236] [client 35.189.118.52:47880] AH01630: client denied by server configuration: /var/www/api/.htpasswd
[Sat Aug 08 15:50:32.885120 2026] [authz_core:error] [pid 6957] [client 35.189.118.52:47816] AH01630: client denied by server configuration: /var/www/api/server-status
[Sat Aug 08 16:30:59.349926 2026] [authz_core:error] [pid 12566] [client 35.189.118.52:45338] AH01630: client denied by server configuration: /var/www/api/.htpasswd
[Sat Aug 08 16:31:03.035477 2026] [authz_core:error] [pid 13671] [client 35.189.118.52:45422] AH01630: client denied by server configuration: /var/www/api/server-status
show less
Bad Web Bot
Web App Attack
๐ต๐ฑ
strefapi_com
2026-08-08 20:14:26
(2 weeks ago)
Brute-force, web
...
Hacking
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-08 20:04:34
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 35.189.118.52 (52.118.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.189.118.52 (52.118.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 16:04:29.277740 2026] [security2:error] [pid 965228:tid 965228] [client 35.189.118.52:51412] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||willowcreekretreathouse.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "willowcreekretreathouse.com"] [uri "/z9x8c7v6b5-debug-trigger-willowcreekretreathouse.com"] [unique_id "aneLzRTfjmHjqwWer1s_xgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-08 20:00:52
(2 weeks ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-08-08 19:56:37
(2 weeks ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐บ๐ธ
masterguru
2026-08-08 19:54:35
(2 weeks ago)
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" ...
show more
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. (210730-169)
show less
Hacking
๐ฉ๐ช
grassau.com
2026-08-08 18:54:08
(2 weeks ago)
(mod_security) mod_security triggered on hostname [redacted] 35.189.118.52 (GB/United Kingdom/Englan ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.189.118.52 (GB/United Kingdom/England/City of London/52.118.189.35.bc.googleusercontent.com)
show less
SQL Injection
๐บ๐ธ
TPI-Abuse
2026-08-08 18:45:16
(2 weeks ago)
(mod_security) mod_security (id:210492) triggered by 35.189.118.52 (52.118.189.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.189.118.52 (52.118.189.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 14:45:09.549548 2026] [security2:error] [pid 1531868:tid 1531868] [client 35.189.118.52:42926] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "clients.pghsea.com"] [uri "/.git/config"] [unique_id "and5NUb5tLoDtYpG790xTgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
poundawebsiteltd
2026-08-08 18:10:09
(2 weeks ago)
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.189.118 ...
show more
Malicious activity in general-malicious. Evidence: (apache_probe) Failed Access (403/404) 35.189.118.52 (GB/United Kingdom/[REDACTED_DOMAIN]): 20 in the last 3600 secs | UA: (apache_probe) Failed Access (403/404) 35.189.118.52 (GB/United Kingdom/52.118.189.35.bc.googleusercontent.com): 20 in the last 3600 secs
show less
Brute-Force
Web App Attack