๐ฉ๐ช
bazter.pro
2026-10-04 22:06:33
(3 days ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 22:03:48
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.203.66.226 (226.66.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.203.66.226 (226.66.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 18:03:43.410746 2026] [security2:error] [pid 22256:tid 22256] [client 35.203.66.226:41734] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gabosoftware.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gabosoftware.com"] [uri "/z9x8c7v6b5-debug-trigger-gabosoftware.com"] [unique_id "asLNP38EqPMddJnYWkcbZAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 21:27:00
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.203.66.226 (226.66.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.203.66.226 (226.66.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 17:26:56.789125 2026] [security2:error] [pid 15033:tid 15033] [client 35.203.66.226:46888] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||davidquiroa.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "davidquiroa.com"] [uri "/z9x8c7v6b5-debug-trigger-davidquiroa.com"] [unique_id "asLEoLBIBsh4BJgMnPyUmAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ญ
dalslab ltd
2026-10-04 21:25:36
(3 days ago)
35.203.66.226 - - [04/Oct/2026:23:25:35 +0200] "POST /graphql HTTP/1.1" 405 556 "http://dalslab.com" ...
show more
35.203.66.226 - - [04/Oct/2026:23:25:35 +0200] "POST /graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.203.66.226 - - [04/Oct/2026:23:25:35 +0200] "POST / HTTP/1.1" 405 154 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)"
35.203.66.226 - - [04/Oct/2026:23:25:35 +0200] "POST /api/graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.203.66.226 - - [04/Oct/2026:23:25:35 +0200] "POST /v1/graphql HTTP/1.1" 405 556 "http://dalslab.com" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36"
35.203.66.226 - - [04/Oct/2026:23:25:35 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/1.1" 400 154 "-" "-"
...
show less
Web Spam
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
david.houstin
2026-10-04 21:11:07
(3 days ago)
35.203.66.226 - - [04/Oct/2026:23:10:58 +0200] "GET /api/data/..%2f..%2f.env HTTP/2.0" 404 264 "-" " ...
show more
35.203.66.226 - - [04/Oct/2026:23:10:58 +0200] "GET /api/data/..%2f..%2f.env HTTP/2.0" 404 264 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
35.203.66.226 - - [04/Oct/2026:23:10:58 +0200] "GET /api/orders/..%2f..%2f.env HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)"
35.203.66.226 - - [04/Oct/2026:23:10:58 +0200] "GET /api/orders/..%2fadmin/config.json HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; Bravebot/1.0; +https://brave.com/search/)"
35.203.66.226 - - [04/Oct/2026:23:10:59 +0200] "GET /api/orders/..%2f..%2fproc/self/environ HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)"
35.203.66.226 - - [04/Oct/2026:23:11:03 +0200] "GET /admin%2F.env HTTP/2.0" 404 264 "-" "Mozilla/5.0 (compatible; xAI-Grok/1.0; +https://x.ai/)"
35.203.66.226 - - [04/Oct/2026:23:11:03 +0200] "GET /..%2f.env HTTP/2.0" 404 264 "-" "Mozilla/5.0 (co
...
show less
Web App Attack
Bad Web Bot
๐ฉ๐ช
LRob
2026-10-04 21:04:46
(3 days ago)
Crawler ignoring refusals | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, ...
show more
Crawler ignoring refusals | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36, Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html), Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot) (+4 more) | path: /build/manifest.json, /ag27dwyadndszuyhqyz2, /lib/terminal-xhr.php (+7 more)
show less
Bad Web Bot
๐ซ๐ท
dynamix
2026-10-04 21:04:09
(3 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 21:03:04
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.203.66.226 (226.66.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.203.66.226 (226.66.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 17:02:59.076876 2026] [security2:error] [pid 7119:tid 7119] [client 35.203.66.226:56256] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cajunfriedturkey.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cajunfriedturkey.com"] [uri "/z9x8c7v6b5-debug-trigger-cajunfriedturkey.com"] [unique_id "asK_A2X7v-D18dNHyLFGGgAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
TheDjRider
2026-10-04 20:57:59
(3 days ago)
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban tri ...
show more
CrowdSec detected Web application reconnaissance. Scenario: local/framework-recon. Automatic ban triggered. Detection time (UTC): 2026-10-04T20:57:58.64054528Z. Context: http_status=200
show less
Web App Attack
Anonymous
2026-10-04 20:57:12
(3 days ago)
Web application attack detected.
Web App Attack
๐ช๐ธ
robotstxt
2026-10-04 20:55:05
(3 days ago)
35.203.66.226 - - [04/Oct/2026:20:54:30 +0000] "GET /wp-content/cache/autoptimize/js/autoptimize_ef9 ...
show more
35.203.66.226 - - [04/Oct/2026:20:54:30 +0000] "GET /wp-content/cache/autoptimize/js/autoptimize_ef9e7d371c10cd56929782c27cd5ffaa.js HTTP/2.0" 403 165 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.203.66.226"
35.203.66.226 - - [04/Oct/2026:20:54:30 +0000] "GET /manifest.json HTTP/2.0" 403 7740 "https://blockchainqualifications.com/manifest.json" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Safari/537.36" "-" edge="35.203.66.226"
35.203.66.226 - - [04/Oct/2026:20:54:30 +0000] "GET /z9x8c7v6b5-debug-trigger-blockchainqualifications.com HTTP/2.0" 403 8420 "https://blockchainqualifications.com/z9x8c7v6b5-debug-trigger-blockchainqualifications.com" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" "-" edge="35.203.66.226"
35.203.66.226 - - [04/Oct/2026:20:54:30 +0000] "GET /webpack-stats.json HTTP/2.0" 403 7740 "https://blockchainqualifications.
...
show less
Web App Attack
๐บ๐ธ
TVolk
2026-10-04 20:37:00
(3 days ago)
sensitive login probing
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-04 20:26:27
(3 days ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-10-04 20:06:04
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.203.66.226 (226.66.203.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.203.66.226 (226.66.203.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 16:06:00.867982 2026] [security2:error] [pid 31562:tid 31573] [client 35.203.66.226:47952] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||104ventures.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "104ventures.com"] [uri "/z9x8c7v6b5-debug-trigger-104ventures.com"] [unique_id "asKxqFBsvSMW8gY7r2HRyAAAAMk"]
show less
Brute-Force
Bad Web Bot
Web App Attack