π«π·
dynamix
2026-09-22 16:10:00
(5 days ago)
Automated web vulnerability and path enumeration scan with excessive 404 requests
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 15:43:05
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.230.105.228 (228.105.230.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.230.105.228 (228.105.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:43:00.666309 2026] [security2:error] [pid 5973:tid 5973] [client 35.230.105.228:41074] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||anthearodgers.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "anthearodgers.com"] [uri "/z9x8c7v6b5-debug-trigger-anthearodgers.com"] [unique_id "arKiBOFwWt1dWVDkcJqTRAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 15:20:05
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.230.105.228 (228.105.230.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.230.105.228 (228.105.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:19:54.580188 2026] [security2:error] [pid 32263:tid 32263] [client 35.230.105.228:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||antitribu.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "antitribu.com"] [uri "/z9x8c7v6b5-debug-trigger-antitribu.com"] [unique_id "arKcmr_bKUSb6U--YcReZAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Site.eu
2026-09-22 15:16:34
(5 days ago)
Excessive multi-domain requests
Brute-Force
π³π±
Alt255
2026-09-22 15:16:12
(5 days ago)
[ti-29al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-29al] Web exploit scanning: 2 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.230.105.228 - - [22/Sep/2026:17:16:05 +0200] "GET /%2e%2e/.env HTTP/2.0" 301 526 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
35.230.105.228 - - [22/Sep/2026:17:16:05 +0200] "GET /@fs/app/.env?raw?? HTTP/2.0" 301 534 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Bad Web Bot
Web App Attack
πΊπΈ
mnsf
2026-09-22 15:05:59
(5 days ago)
Scanning/Probing (17)
Request Overload (114)
Brute-Force
Web App Attack
πΊπΈ
IndigoRidge
2026-09-22 14:40:48
(5 days ago)
[22/Sep/2026:10:40:43.556671 --0400] arKTa6gDMXMJc6MmXyPc9QAAAAk 35.230.105.228 41006 205.233.18.17 ...
show more
[22/Sep/2026:10:40:43.556671 --0400] arKTa6gDMXMJc6MmXyPc9QAAAAk 35.230.105.228 41006 205.233.18.17 7081
[22/Sep/2026:10:40:48.038008 --0400] arKTcDyU3MP@KjLCLeJOsAAAAQ4 35.230.105.228 32902 205.233.18.17 7081
[22/Sep/2026:10:40:48.169072 --0400] arKTcDyU3MP@KjLCLeJOswAAARU 35.230.105.228 32940 205.233.18.17 7081
[22/Sep/2026:10:40:48.172421 --0400] arKTcDyU3MP@KjLCLeJOtAAAAQ0 35.230.105.228 32934 205.233.18.17 7081
[22/Sep/2026:10:40:48.307345 --0400] arKTcDyU3MP@KjLCLeJOtQAAARY 35.230.105.228 32962 205.233.18.17 7081
...
show less
Hacking
πΊπΈ
TPI-Abuse
2026-09-22 14:38:56
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.230.105.228 (228.105.230.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.230.105.228 (228.105.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:38:49.569271 2026] [security2:error] [pid 6832:tid 6832] [client 35.230.105.228:59672] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||anxietyquest.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "anxietyquest.com"] [uri "/z9x8c7v6b5-debug-trigger-anxietyquest.com"] [unique_id "arKS-UASAKwoz0X0_ht6qwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 13:43:07
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.230.105.228 (228.105.230.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.230.105.228 (228.105.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:43:00.537474 2026] [security2:error] [pid 29719:tid 29719] [client 35.230.105.228:48008] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aperturecontrols.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aperturecontrols.com"] [uri "/z9x8c7v6b5-debug-trigger-aperturecontrols.com"] [unique_id "arKF5Efd7ZvJ09uwaDWgNwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π«π·
COMAITE
2026-09-22 13:22:38
(5 days ago)
Suspicious URL access.
Web App Attack
πΊπΈ
TAY
2026-09-22 13:00:41
(5 days ago)
35.230.105.228 - - [22/Sep/2026:21:00:40 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 404 2050 "-" "Mozi ...
show more
35.230.105.228 - - [22/Sep/2026:21:00:40 +0800] "GET /@fs/../.env?raw?? HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)"
35.230.105.228 - - [22/Sep/2026:21:00:40 +0800] "GET /_nuxt/../.env HTTP/1.1" 404 2050 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; ChatGPT-User/1.0; +https://openai.com/bot"
35.230.105.228 - - [22/Sep/2026:21:00:40 +0800] "GET /static../.env HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
35.230.105.228 - - [22/Sep/2026:21:00:40 +0800] "GET /img../.env HTTP/1.1" 404 2050 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
35.230.105.228 - - [22/Sep/2026:21:00:40 +0800] "GET /media../.env HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)"
35.230.105.228 - - [22/Sep/2026:21:00:40 +0800] "GET /files../.env HTTP/1.1" 404 2050 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0;
...
show less
Brute-Force
π«π·
dynamix
2026-09-22 12:54:52
(5 days ago)
Multiple WAF Violations
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 12:40:49
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.230.105.228 (228.105.230.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.230.105.228 (228.105.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:40:45.580389 2026] [security2:error] [pid 27856:tid 27856] [client 35.230.105.228:55938] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||appalachianfolkmagician.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "appalachianfolkmagician.com"] [uri "/z9x8c7v6b5-debug-trigger-appalachianfolkmagician.com"] [unique_id "arJ3TdphCpesFKWpkflRAQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-09-22 12:23:51
(5 days ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 12:08:42
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 35.230.105.228 (228.105.230.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.230.105.228 (228.105.230.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 08:08:34.483896 2026] [security2:error] [pid 618:tid 649] [client 35.230.105.228:51278] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||arotger.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arotger.com"] [uri "/z9x8c7v6b5-debug-trigger-arotger.com"] [unique_id "arJvwosR8AwdqEFzoJU-rQAAAME"]
show less
Brute-Force
Bad Web Bot
Web App Attack