๐ฉ๐ช
klaus_ph
2026-09-27 14:15:17
(1 day ago)
2026-09-26 07:00:38,357 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 35.232.233.59
.. ...
show more
2026-09-26 07:00:38,357 fail2ban.actions [594716]: NOTICE [ipblocklist] Ban 35.232.233.59
...
show less
Bad Web Bot
Anonymous
2026-09-23 09:58:10
(6 days ago)
35.232.233.59 - - [22/Sep/2026:07:05:03 -0500] "GET /.env.staging HTTP/1.1" 403 199 "-" "Mozilla/5.0 ...
show more
35.232.233.59 - - [22/Sep/2026:07:05:03 -0500] "GET /.env.staging HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" 35.232.233.59
35.232.233.59 - - [22/Sep/2026:07:05:03 -0500] "GET /.env.test HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; Meta-ExternalAgent/1.0; +https://developers.facebook.com/docs/sharing/webmasters/crawler)" 35.232.233.59
35.232.233.59 - - [22/Sep/2026:07:05:03 -0500] "GET /.env.development HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" 35.232.233.59
35.232.233.59 - - [22/Sep/2026:07:05:03 -0500] "GET /.env.docker HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; DeepSeekBot/1.0; +https://www.deepseek.com/)" 35.232.233.59
35.232.233.59 - - [22/Sep/2026:07:05:03 -0500] "GET /.env.production.bak HTTP/1.1" 403 199 "-" "Mozilla/5.0 (compatible; cohere-ai; +https://cohere.com/crawler)" 35.232.233.59
35.232.233.59 - - [22/Sep/2026:07:05:03 -0500] "GET /.env.prod.bak HTTP/1.1" 403 199 "-" "Mozilla/5.
...
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ฝ
octageeks.com
2026-09-23 04:14:00
(6 days ago)
Wordpress malicious attack:[octablocked]
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-23 02:34:16
(6 days ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-23 02:31:35
(6 days ago)
[cb-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[cb-06al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.232.233.59 - - [23/Sep/2026:04:31:17 +0200] "GET /api/console/api_server?sense_version=%40%40SENSE_VERSION&apis=../../../../../../.env HTTP/2.0" 403 6628 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Claude-User/1.0; [email protected] )"
...
show less
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-09-23 02:13:43
(6 days ago)
(mod_security) mod_security (id:920420) triggered by 35.232.233.59 (US/United States/59.233.232.35.b ...
show more
(mod_security) mod_security (id:920420) triggered by 35.232.233.59 (US/United States/59.233.232.35.bc.googleusercontent.com): 5 in the last 300 secs (CF_ENABLE)
show less
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 02:07:59
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.232.233.59 (59.233.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.232.233.59 (59.233.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 22:07:55.305508 2026] [security2:error] [pid 24078:tid 24078] [client 35.232.233.59:37554] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dwipapuri-abadi.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dwipapuri-abadi.com"] [uri "/z9x8c7v6b5-debug-trigger-dwipapuri-abadi.com"] [unique_id "arM0e7DBXe3vKzb0Bz11dAAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-22 22:24:23
(6 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 21:52:24
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.232.233.59 (59.233.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.232.233.59 (59.233.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 17:52:19.627315 2026] [security2:error] [pid 29754:tid 29754] [client 35.232.233.59:38676] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||easylandcash.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "easylandcash.com"] [uri "/z9x8c7v6b5-debug-trigger-easylandcash.com"] [unique_id "arL4kwGEpuwzTJVHxXG9RwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 20:55:31
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.232.233.59 (59.233.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.232.233.59 (59.233.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 16:55:26.475520 2026] [security2:error] [pid 24274:tid 24274] [client 35.232.233.59:50160] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ebizplayers.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ebizplayers.com"] [uri "/z9x8c7v6b5-debug-trigger-ebizplayers.com"] [unique_id "arLrPtNrjqp_QVjNmZtoVQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
robotstxt
2026-09-22 19:28:10
(6 days ago)
35.232.233.59 - - [22/Sep/2026:19:27:34 +0000] "-" 400 193 "-" "-" "-"
35.232.233.59 - - [22/Sep/202 ...
show more
35.232.233.59 - - [22/Sep/2026:19:27:34 +0000] "-" 400 193 "-" "-" "-"
35.232.233.59 - - [22/Sep/2026:19:27:35 +0000] "-" 400 193 "-" "-" "-"
35.232.233.59 - - [22/Sep/2026:19:27:35 +0000] "-" 400 193 "-" "-" "-"
35.232.233.59 - - [22/Sep/2026:19:27:36 +0000] "-" 400 193 "-" "-" "-"
35.232.233.59 - - [22/Sep/2026:19:27:36 +0000] "-" 400 193 "-" "-" "-"
...
show less
Web Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:40:49
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.232.233.59 (59.233.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.232.233.59 (59.233.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:40:41.969168 2026] [security2:error] [pid 16152:tid 16152] [client 35.232.233.59:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||eddysgroup.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "eddysgroup.com"] [uri "/z9x8c7v6b5-debug-trigger-eddysgroup.com"] [unique_id "arLLqTFwFDgb8Mt62fHF8wAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Savvii
2026-09-22 18:38:14
(6 days ago)
20 attempts against mh-misbehave-ban on ozone
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:20:57
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.232.233.59 (59.233.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.232.233.59 (59.233.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:20:52.706472 2026] [security2:error] [pid 11552:tid 11552] [client 35.232.233.59:53674] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||edgeimprov.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "edgeimprov.com"] [uri "/z9x8c7v6b5-debug-trigger-edgeimprov.com"] [unique_id "arLHBEa4_gTZSlCAB8-bCwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 17:48:28
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 35.232.233.59 (59.233.232.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.232.233.59 (59.233.232.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 13:48:24.573446 2026] [security2:error] [pid 1097518:tid 1097518] [client 35.232.233.59:57106] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||edmestonfd.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "edmestonfd.com"] [uri "/z9x8c7v6b5-debug-trigger-edmestonfd.com"] [unique_id "arK_aI_a65mWxLVpqjJizAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack