๐ซ๐ท
Catalin Negru
2026-09-17 12:07:35
(4 days ago)
2026-09-15 14:18:04,240 fail2ban.actions [736]: NOTICE [apache-404] Ban 35.222.206.245
2026- ...
show more
2026-09-15 14:18:04,240 fail2ban.actions [736]: NOTICE [apache-404] Ban 35.222.206.245
2026-09-15 14:18:04,296 fail2ban.actions [736]: NOTICE [apache-scan] Ban 35.222.206.245
2026-09-15 14:18:04,351 fail2ban.actions [736]: NOTICE [apache-security] Ban 35.222.206.245
2026-09-15 14:18:04,362 fail2ban.actions [736]: NOTICE [laravel-auth] Ban 35.222.206.245
2026-09-15 14:18:04,644 fail2ban.actions [736]: NOTICE [web-scanner] Ban 35.222.206.245
...
show less
Brute-Force
Web App Attack
๐ซ๐ฎ
tjs
2026-09-16 12:35:00
(5 days ago)
web attack
Hacking
Web App Attack
๐ซ๐ท
dynamix
2026-09-16 05:26:46
(5 days ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
andypiper
2026-09-16 01:01:18
(6 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 00:21:20
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 35.222.206.245 (245.206.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.222.206.245 (245.206.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:21:15.188314 2026] [security2:error] [pid 10965:tid 10965] [client 35.222.206.245:33874] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "vrevgaming.net"] [uri "/.env.example"] [unique_id "aqng-0Y31Mh43BRLRxGIFAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 00:14:12
(6 days ago)
Bot / seems abusive / Apache connections: 25
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 23:27:04
(6 days ago)
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.222.206.245 (US/United States/245.206.222 ...
show more
(config_exploit_scan) Configuratie Scanner / Nep GPTBot 35.222.206.245 (US/United States/245.206.222.35.bc.googleusercontent.com): 3 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.222.206.245 - - [16/Sep/2026:01:27:01 +0200] "GET /%2E%2E/%2E%2E/%2E%2E/%2E%2E/.env HTTP/2.0" 406 317 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot)"
35.222.206.245 - - [16/Sep/2026:01:27:01 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f%2e%2e%2f.env HTTP/2.0" 406 317 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-SearchBot/1.0; [email protected] )"
35.222.206.245 - - [16/Sep/2026:01:27:01 +0200] "GET /api/uploads/%2e%2e%2f%2e%2e%2f.env HTTP/2.0" 406 317 "-" "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)"
show less
Port Scan
Anonymous
2026-09-15 23:25:05
(6 days ago)
suspicious request in access.log
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:32:44
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.222.206.245 (245.206.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.222.206.245 (245.206.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:32:37.165840 2026] [security2:error] [pid 14627:tid 14627] [client 35.222.206.245:38176] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||thongtracker.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thongtracker.com"] [uri "/ssl/localhost.key"] [unique_id "aqm5df_1qLob7z4hJcvbYgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:05:30
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.222.206.245 (245.206.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.222.206.245 (245.206.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:05:26.140996 2026] [security2:error] [pid 18527:tid 18527] [client 35.222.206.245:57060] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thomasanthonyquinn.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thomasanthonyquinn.com"] [uri "/z9x8c7v6b5-debug-trigger-thomasanthonyquinn.com"] [unique_id "aqmzFpXOfkoj68HQ3haDOAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
gadix
2026-09-15 20:46:56
(6 days ago)
[15/Sep/2026:22:46:53.611524 +0200] aqmuvfKATHHXUPtnA79BLQAAAAk 35.222.206.245 54560 127.0.0.1 7081
...
show more
[15/Sep/2026:22:46:53.611524 +0200] aqmuvfKATHHXUPtnA79BLQAAAAk 35.222.206.245 54560 127.0.0.1 7081
[15/Sep/2026:22:46:53.620607 +0200] aqmuvT2XOb22lXhRdijpHAAAAAA 35.222.206.245 54590 127.0.0.1 7081
[15/Sep/2026:22:46:53.624071 +0200] aqmuvVZvft4GtLl1eVoe9QAAAAQ 35.222.206.245 54606 127.0.0.1 7081
...
show less
Web App Attack
Anonymous
2026-09-15 20:17:09
(6 days ago)
[Tue Sep 15 22:16:58.165976 2026] [php:error] [pid 1128268] [client 35.222.206.245:34330] script '/v ...
show more
[Tue Sep 15 22:16:58.165976 2026] [php:error] [pid 1128268] [client 35.222.206.245:34330] script '/var/www/thisisdochdetroit.com/public_html/document.php' not found or unable to stat
[Tue Sep 15 22:17:08.788333 2026] [php:error] [pid 1128268] [client 35.222.206.245:34330] script '/var/www/thisisdochdetroit.com/public_html/phpinfo.php' not found or unable to stat
[Tue Sep 15 22:17:08.866035 2026] [php:error] [pid 1029191] [client 35.222.206.245:34350] script '/var/www/thisisdochdetroit.com/public_html/test.php' not found or unable to stat
[Tue Sep 15 22:17:08.868848 2026] [php:error] [pid 1099588] [client 35.222.206.245:34372] script '/var/www/thisisdochdetroit.com/public_html/i.php' not found or unable to stat
[Tue Sep 15 22:17:08.884496 2026] [php:error] [pid 1036878] [client 35.222.206.245:34366] script '/var/www/thisisdochdetroit.com/public_html/pi.php' not found or unable to stat
...
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-15 19:39:35
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.222.206.245 (245.206.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.222.206.245 (245.206.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:39:31.372011 2026] [security2:error] [pid 7909:tid 7909] [client 35.222.206.245:42900] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thinksite.net|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thinksite.net"] [uri "/rclone.conf"] [unique_id "aqme81IjB1i2er8wjI3twAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 18:02:34
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.222.206.245 (245.206.222.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.222.206.245 (245.206.222.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 14:02:26.842042 2026] [security2:error] [pid 25559:tid 25559] [client 35.222.206.245:58468] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thewritekellys.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thewritekellys.com"] [uri "/z9x8c7v6b5-debug-trigger-thewritekellys.com"] [unique_id "aqmIMmw26ruExBuJKjKbsgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-15 17:42:40
(6 days ago)
Web attack/malicious scanning detected
Web App Attack