๐ฉ๐ช
klaus_ph
2026-09-27 07:28:19
(5 days ago)
2026-09-26 03:01:45,468 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 35.194.41.210
.. ...
show more
2026-09-26 03:01:45,468 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 35.194.41.210
...
show less
Bad Web Bot
๐ฎ๐ณ
evicky2002
2026-09-23 06:00:01
(1 week ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐ซ๐ท
Tilellit.PRO
2026-09-23 01:37:09
(1 week ago)
Web application probing for unlinked paths and hidden files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-23 00:54:35
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.194.41.210 (210.41.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.41.210 (210.41.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 20:54:30.112692 2026] [security2:error] [pid 12613:tid 12613] [client 35.194.41.210:60536] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.mp3tracks.com|F|2"] [data ".mp3tracks.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.mp3tracks.com"] [uri "/z9x8c7v6b5-debug-trigger-www.mp3tracks.com"] [unique_id "arMjRoAmGj8xc0jlp4jUoAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 00:24:54
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.194.41.210 (210.41.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.41.210 (210.41.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 20:24:41.235258 2026] [security2:error] [pid 11036:tid 11083] [client 35.194.41.210:52506] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.mouserart.com|F|2"] [data ".mouserart.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.mouserart.com"] [uri "/z9x8c7v6b5-debug-trigger-www.mouserart.com"] [unique_id "arMcScRj6x4IfnXlIW3DswAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 22:54:14
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.194.41.210 (210.41.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.41.210 (210.41.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:54:11.848457 2026] [security2:error] [pid 4896:tid 4896] [client 35.194.41.210:36486] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.banis-associates.com|F|2"] [data ".banis-associates.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.banis-associates.com"] [uri "/z9x8c7v6b5-debug-trigger-www.banis-associates.com"] [unique_id "arMHE15sv2sLmxw5gVoPjQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
lufi
2026-09-22 22:38:55
(1 week ago)
2026-09-23T00:38:55+02:00 lufischer04 ids442 2026-09-23 00:38:55 35.194.41.210: blacklistedPath: /.s ...
show more
2026-09-23T00:38:55+02:00 lufischer04 ids442 2026-09-23 00:38:55 35.194.41.210: blacklistedPath: /.ssh/id_rsa
...
show less
Web Spam
Brute-Force
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 22:33:02
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.194.41.210 (210.41.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.41.210 (210.41.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:32:58.156253 2026] [security2:error] [pid 10444:tid 10444] [client 35.194.41.210:47230] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aguasolar.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aguasolar.com"] [uri "/z9x8c7v6b5-debug-trigger-aguasolar.com"] [unique_id "arMCGlLQ095kvmut2GrbWgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 21:57:37
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.194.41.210 (210.41.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.41.210 (210.41.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:57:29.936273 2026] [security2:error] [pid 14402:tid 14402] [client 35.194.41.210:33060] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||danged.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "danged.com"] [uri "/z9x8c7v6b5-debug-trigger-danged.com"] [unique_id "arL5yfkaVK_pIcR4j5Ys8gAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
GabrielJST
2026-09-22 21:54:59
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 35.194.41.210 (US/United States/210.41. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.194.41.210 (US/United States/210.41.194.35.bc.googleusercontent.com): (CF_ENABLE)
show less
SQL Injection
Anonymous
2026-09-22 21:45:44
(1 week ago)
Aggressive web scan
Web App Attack
๐ฉ๐ช
bazter.pro
2026-09-22 21:33:34
(1 week ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 21:16:42
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.194.41.210 (210.41.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.194.41.210 (210.41.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:16:38.711265 2026] [security2:error] [pid 8153:tid 8153] [client 35.194.41.210:35940] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ink2wear.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ink2wear.com"] [uri "/z9x8c7v6b5-debug-trigger-ink2wear.com"] [unique_id "arLwNgWcku35vbU3f9ovoQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
[email protected]
2026-09-22 20:48:32
(1 week ago)
CrowdSec ban: crowdsecurity/http-admin-interface-probing (duration: 71h59m57s)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 20:25:18
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 35.194.41.210 (210.41.194.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.194.41.210 (210.41.194.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:25:14.275069 2026] [security2:error] [pid 16241:tid 16249] [client 35.194.41.210:34556] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mouawadarchitects.com"] [uri "/.env.js"] [unique_id "arLkKr5E2sKr39MO73d1bQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack