๐บ๐ธ
dot.mg
2026-10-02 12:38:02
(25 minutes ago)
Bad behaviour
Web Spam
๐บ๐ธ
TPI-Abuse
2026-10-02 12:34:08
(29 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.198.150.241 (241.150.198.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.198.150.241 (241.150.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:34:01.841448 2026] [security2:error] [pid 10890:tid 10890] [client 35.198.150.241:58688] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.aeomis.com|F|2"] [data ".aeomis.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.aeomis.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.aeomis.com"] [unique_id "ar-kuaWXc-3izax-m0lR4QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
WebNiraj
2026-10-02 12:14:19
(49 minutes ago)
(mod_security) mod_security (id:949110) triggered by 35.198.150.241 (DE/Germany/241.150.198.35.bc.go ...
show more
(mod_security) mod_security (id:949110) triggered by 35.198.150.241 (DE/Germany/241.150.198.35.bc.googleusercontent.com): 5 in the last 3600 secs [SIGMA]
show less
Brute-Force
๐ซ๐ท
masterguru
2026-10-02 11:49:27
(1 hour ago)
BAD BOT - Detected and Blocked.. Matched phrase "baidu" at REQUEST_HEADERS:User-Agent. (1100000-196)
Bad Web Bot
Anonymous
2026-10-02 11:48:31
(1 hour ago)
[Fri Oct 02 13:48:27.487874 2026] [proxy_fcgi:error] [pid 46466:tid 46525] [client 35.198.150.241:39 ...
show more
[Fri Oct 02 13:48:27.487874 2026] [proxy_fcgi:error] [pid 46466:tid 46525] [client 35.198.150.241:39950] AH01071: Got error 'Primary script unknown'
[Fri Oct 02 13:48:27.558674 2026] [proxy_fcgi:error] [pid 35125:tid 35261] [client 35.198.150.241:39978] AH01071: Got error 'Primary script unknown'
[Fri Oct 02 13:48:28.603420 2026] [proxy_fcgi:error] [pid 35127:tid 35202] [client 35.198.150.241:40014] AH01071: Got error 'Primary script unknown'
[Fri Oct 02 13:48:30.277665 2026] [proxy_fcgi:error] [pid 35145:tid 35325] [client 35.198.150.241:40054] AH01071: Got error 'Primary script unknown'
[Fri Oct 02 13:48:30.291971 2026] [proxy_fcgi:error] [pid 35127:tid 35223] [client 35.198.150.241:40014] AH01071: Got error 'Primary script unknown'
...
show less
Brute-Force
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-02 11:17:30
(1 hour ago)
[ti-14al] Excessive 404 errors (web scanning): 27 suspicious requests detected by fail2ban jail <nam ...
show more
[ti-14al] Excessive 404 errors (web scanning): 27 suspicious requests detected by fail2ban jail <name>. Example: 35.198.150.241 - - \[02/Oct/2026:13:17:23 +0200\] "GET /static/manifest.json HTTP/1.1" 404 518 "-" "Mozilla/5.0 \(X11\; Linux x86_64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/153.0.0.0 Safari/537.36"
35.198.150.241 - - \[02/Oct/2026:13:17:23 +0200\] "GET /asset-manifest.json HTTP/1.1" 404 518 "-" "Mozilla/5.0 \(X11\; Linux x86_64\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/153.0.0.0 Safari/537.36"
35.198.150.241 - - \[02/Oct/2026:13:17:23 +0200\] "GET /t12h658jubotcjxvu0sd HTTP/1.1" 404 518 "-" "Mozilla/5.0 \(compatible\; MistralAI-User/1.0\; +https://mistral.ai/\)"
35.198.150.241 - - \[02/Oct/2026:13:17:23 +0200\] "GET /z9x8c7v6b5-debug-trigger-erp.agro-ecolum-nederland.com HTTP/1.1" 404 518 "-" "Mozilla
...
show less
Bad Web Bot
Web App Attack
๐ณ๐ฑ
middelkoopcc
2026-10-02 11:12:00
(1 hour ago)
2026-10-02 13:10:01 GET /config/env/aws_credentials.env [404] && 2026-10-02 13:10:02 GET /_nuxt/../. ...
show more
2026-10-02 13:10:01 GET /config/env/aws_credentials.env [404] && 2026-10-02 13:10:02 GET /_nuxt/../.env [404] && 2026-10-02 13:10:02 GET /wp-config.php.old [404] && 252 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 11:01:37
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.198.150.241 (241.150.198.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.198.150.241 (241.150.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 07:01:31.464322 2026] [security2:error] [pid 1051:tid 1051] [client 35.198.150.241:42386] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.bigredgraphicdesign.com|F|2"] [data ".bigredgraphicdesign.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.bigredgraphicdesign.com"] [uri "/z9x8c7v6b5-debug-trigger-mail.bigredgraphicdesign.com"] [unique_id "ar-PCwm48hv15LTmaIw9mwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-02 10:59:01
(2 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
bazter.pro
2026-10-02 10:52:48
(2 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 10:40:51
(2 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.198.150.241 (241.150.198.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.198.150.241 (241.150.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 06:40:45.351370 2026] [security2:error] [pid 23309:tid 23309] [client 35.198.150.241:40514] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.armrms.com"] [uri "/web.config"] [unique_id "ar-KLZV_b7YzdT3a6iFQFAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 09:59:17
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.198.150.241 (241.150.198.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.198.150.241 (241.150.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 05:59:09.855869 2026] [security2:error] [pid 9126:tid 9126] [client 35.198.150.241:38664] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.blockadegc.com|F|2"] [data ".blockadegc.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.blockadegc.com"] [uri "/z9x8c7v6b5-debug-trigger-www.blockadegc.com"] [unique_id "ar-AbbaQK0NSMqgw1q95DQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 09:41:01
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.198.150.241 (241.150.198.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.198.150.241 (241.150.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 05:40:54.824985 2026] [security2:error] [pid 28895:tid 28895] [client 35.198.150.241:35118] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||braddonengineering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "braddonengineering.com"] [uri "/z9x8c7v6b5-debug-trigger-braddonengineering.com"] [unique_id "ar98Jon9ZzAzSjyi_tjLwwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Blinker73
2026-10-02 09:17:17
(3 hours ago)
2026-10-01T23:42 kernel: OUT= SRC=35.198.150.241 LEN=60 TOS=0x00 PREC=0x00 TTL=46 ID=19674 DF ...
show more
2026-10-01T23:42 kernel: OUT= SRC=35.198.150.241 LEN=60 TOS=0x00 PREC=0x00 TTL=46 ID=19674 DF PROTO=TCP SPT=36406 DPT=8443 WINDOW=65320 RES=0x00 SYN URGP=0
2026-10-01T23:42 kernel: OUT= SRC=35.198.150.241 LEN=60 TOS=0x00 PREC=0x00 TTL=47 ID=34923 DF PROTO=TCP SPT=57302 DPT=8080 WINDOW=65320 RES=0x00 SYN URGP=0
2026-10-02T05:17 kernel: OUT= SRC=35.198.150.241 LEN=60 TOS=0x00 PREC=0x00 TTL=47 ID=34275 DF PROTO=TCP SPT=39788 DPT=8080 WINDOW=65320 RES=0x00 SYN URGP=
show less
Port Scan
๐ฌ๐ง
consul.to
2026-10-02 09:04:11
(3 hours ago)
Web attack/malicious scanning detected
Web App Attack