๐ซ๐ท
Batz
2026-10-01 21:09:22
(6 days ago)
[35.198.30.103] Multiple FTP BruteForce Attack
FTP Brute-Force
Hacking
Brute-Force
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-01 17:03:58
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.198.30.103 (103.30.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.198.30.103 (103.30.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:03:50.696061 2026] [security2:error] [pid 19296:tid 19356] [client 35.198.30.103:37532] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||shaneblair.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "shaneblair.com"] [uri "/z9x8c7v6b5-debug-trigger-shaneblair.com"] [unique_id "ar6SduTzfvpZgdZE2bXcOgAAAM4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
cg-design.co.uk
2026-10-01 16:26:24
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted] 35.198.30.103 (BR/Brazil/103.30.198.35. ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.198.30.103 (BR/Brazil/103.30.198.35.bc.googleusercontent.com)
show less
SQL Injection
๐ณ๐ฑ
middelkoopcc
2026-10-01 16:10:01
(1 week ago)
2026-10-01 18:08:16 GET /phpinfo.php [301] && 2026-10-01 18:08:18 AH10244: invalid URI path (/%2e%2e ...
show more
2026-10-01 18:08:16 GET /phpinfo.php [301] && 2026-10-01 18:08:18 AH10244: invalid URI path (/%2e%2e/.env) && 2026-10-01 18:08:16 GET /ngsw.json [301] && 191 more within 20 minutes
show less
Web App Attack
๐บ๐ธ
kosada.com
2026-10-01 13:36:31
(1 week ago)
Repeated requests for suspicious nonexistent URLs, for example: /assets/manifest.json (HTTP/2.0 port ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /assets/manifest.json (HTTP/2.0 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36")
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 13:16:35
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.198.30.103 (103.30.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.198.30.103 (103.30.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 09:16:28.525951 2026] [security2:error] [pid 487:tid 487] [client 35.198.30.103:36874] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||noshsf.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "noshsf.com"] [uri "/z9x8c7v6b5-debug-trigger-noshsf.com"] [unique_id "ar5dLMdZhswaudhPncJo9wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 12:25:17
(1 week ago)
Aggressive web scan
Web App Attack
Anonymous
2026-10-01 12:24:42
(1 week ago)
IP matched detection query more than 2 hosts and only bad rq long ban.
Brute-Force
Web App Attack
Hacking
๐ฉ๐ช
updown.io
2026-10-01 12:22:46
(1 week ago)
{"level":"info","ts":1790857359.1393826,"logger":"http.log.access.log1","msg":"handled request","req ...
show more
{"level":"info","ts":1790857359.1393826,"logger":"http.log.access.log1","msg":"handled request","request":{"remote_ip":"35.198.30.103","remote_port":"55480","client_ip":"35.198.30.103","proto":"HTTP/2.0","method":"GET","host":"status.villagemaps.in","uri":"/assets/manifest.json","headers":{"User-Agent":["Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36"],"Accept":["*/*"],"X-Nextjs-Data":["1"],"Sec-Fetch-Site":["same-origin"],"Priority":["u=1"],"Sec-Ch-Ua-Platform":["\"Android\""],"X-Middleware-Subrequest":["src/middleware:nowaf:src/middleware:src/middleware:src/middleware:src/middleware:middleware:middleware:nowaf:middleware:middleware:middleware:pages/_middleware"],"Accept-Language":["en-US,en;q=0.9"],"Sec-Fetch-Mode":["no-cors"],"Sec-Ch-Ua":["\"Chromium\";v=\"153\", \"Google Chrome\";v=\"153\", \"Not_A Brand\";v=\"8\""],"Sec-Ch-Ua-Mobile":["?1"],"Sec-Fetch-Dest":["script"],"Accept-Encoding":["gzip, deflate, br, zstd"]},"t
...
show less
DDoS Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 11:38:27
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 35.198.30.103 (103.30.198.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.198.30.103 (103.30.198.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:38:23.526075 2026] [security2:error] [pid 26711:tid 26711] [client 35.198.30.103:54110] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||staff.getitenglish.com|F|2"] [data ".getitenglish.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "staff.getitenglish.com"] [uri "/z9x8c7v6b5-debug-trigger-staff.getitenglish.com"] [unique_id "ar5GL26clX5f_5QOQGxhRwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Hazzard
2026-10-01 11:22:15
(1 week ago)
(mod_security) mod_security triggered on hostname [redacted]): (CF_ENABLE)
SQL Injection
๐บ๐ธ
MakoWish
2026-10-01 11:12:15
(1 week ago)
Fuzzing for misconfigured web servers.
Hacking
Web App Attack
๐ฉ๐ช
MBombeck
2026-10-01 10:41:19
(1 week ago)
Fail2Ban/traefik-botsearch on apps-01: banned after 5 failures
Web App Attack
Anonymous
2026-10-01 10:00:12
(1 week ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
๐ฌ๐ง
noise.agency
2026-10-01 09:04:04
(1 week ago)
35.198.30.103 (BR/Brazil/103.30.198.35.bc.googleusercontent.com), more than 10 Apache 403 hits
Hacking