๐ณ๐ฑ
homeshowdomain.nl
2026-10-01 21:59:36
(3 hours ago)
Auto-ban: >3000 req/min op 2026-10-01
Web App Attack
SSH
Hacking
๐ซ๐ท
COMAITE
2026-10-01 17:08:22
(8 hours ago)
Common web attack from 35.199.98.183.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 16:50:54
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.199.98.183 (183.98.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.98.183 (183.98.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 12:50:49.101087 2026] [security2:error] [pid 4316:tid 4316] [client 35.199.98.183:34212] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||danged.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "danged.com"] [uri "/z9x8c7v6b5-debug-trigger-danged.com"] [unique_id "ar6PaURhh9-EeAixcg3cygAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Manuel Braeuer
2026-10-01 16:49:58
(9 hours ago)
35.199.98.183 - - [01/Oct/2026:18:49:56 +0200] "GET /mi9zjvzp4zeimy5nwxke HTTP/1.1" 403 5677 "-" "Mo ...
show more
35.199.98.183 - - [01/Oct/2026:18:49:56 +0200] "GET /mi9zjvzp4zeimy5nwxke HTTP/1.1" 403 5677 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
35.199.98.183 - - [01/Oct/2026:18:49:56 +0200] "GET /hb9lq76mz1olcj9pnbe3 HTTP/1.1" 403 5677 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
35.199.98.183 - - [01/Oct/2026:18:49:57 +0200] "GET /config.js HTTP/1.1" 403 5677 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)"
35.199.98.183 - - [01/Oct/2026:18:49:57 +0200] "GET /model/info HTTP/1.1" 403 5677 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] ) AppleWebKit/537.36"
35.199.98.183 - - [01/Oct/2026:18:49:57 +0200] "GET /environment.js HTTP/1.1" 403 5677 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
...
show less
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-01 14:54:50
(10 hours ago)
[ti-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apac ...
show more
[ti-04al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail apache-404. Example: 35.199.98.183 - - [01/Oct/2026:16:54:48 +0200] "GET /z9x8c7v6b5-debug-trigger-profile.depakjesboot.nl HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
35.199.98.183 - - [01/Oct/2026:16:54:48 +0200] "GET /model/info HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
35.199.98.183 - - [01/Oct/2026:16:54:48 +0200] "GET /q2k0ves8vzfcbtj1a6ta HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
35.199.98.183 - - [01/Oct/2026:16:54:48 +0200] "POST /login HTTP/2.0" 404 1855 "-" "DuckAssistBot/1.1 (https://duckduckgo.com/duckassistbot)"
04ti.a
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 12:25:32
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.199.98.183 (183.98.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.98.183 (183.98.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:25:29.222172 2026] [security2:error] [pid 23891:tid 23891] [client 35.199.98.183:38170] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.deathofaspy.banis-associates.com|F|2"] [data ".deathofaspy.banis-associates.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.deathofaspy.banis-associates.com"] [uri "/z9x8c7v6b5-debug-trigger-www.deathofaspy.banis-associates.com"] [unique_id "ar5ROfQK-Uw7sUxcpZQHdwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 12:22:25
(13 hours ago)
Portscan: TCP/8080 (7x), TCP/8443 (7x), TCP/443, TCP/80
Port Scan
๐ฉ๐ช
Savvii
2026-10-01 12:11:48
(13 hours ago)
20 attempts against mh-misbehave-ban on rose
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-10-01 12:05:19
(13 hours ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-01 12:00:48
(13 hours ago)
Excessive multi-domain requests
Brute-Force
๐ณ๐ฑ
Savvii
2026-10-01 11:52:29
(13 hours ago)
20 attempts against mh-misbehave-ban on redirect
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-10-01 11:09:13
(14 hours ago)
[ti-30al] Web exploit scanning: 3 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-30al] Web exploit scanning: 3 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.199.98.183 - - [01/Oct/2026:13:09:03 +0200] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env HTTP/2.0" 400 1990 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
35.199.98.183 - - [01/Oct/2026:13:09:03 +0200] "GET /appearance/../../.env HTTP/2.0" 400 1990 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
35.199.98.183 - - [01/Oct/2026:13:09:03 +0200] "GET /%2e%2e/.env HTTP/2.0" 400 1990 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
noise.agency
2026-10-01 10:57:05
(14 hours ago)
35.199.98.183 (BR/Brazil/183.98.199.35.bc.googleusercontent.com), more than 10 Apache 403 hits
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-01 10:46:41
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.199.98.183 (183.98.199.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.199.98.183 (183.98.199.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:46:34.571580 2026] [security2:error] [pid 9310:tid 9310] [client 35.199.98.183:55042] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.delunas.thelowensteinfamily.com|F|2"] [data ".delunas.thelowensteinfamily.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.delunas.thelowensteinfamily.com"] [uri "/z9x8c7v6b5-debug-trigger-www.delunas.thelowensteinfamily.com"] [unique_id "ar46CnazE4xDFI28byrs6wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-10-01 10:35:28
(15 hours ago)
IP matched detection query 50 and more bad rqs apache.
Hacking
Bad Web Bot
Brute-Force
Web App Attack