๐บ๐ธ
lavnet.net
2026-10-06 13:14:50
(6 hours ago)
35.240.143.7 - - [06/Oct/2026:13:14:49 +0000] "GET /signin HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Linu ...
show more
35.240.143.7 - - [06/Oct/2026:13:14:49 +0000] "GET /signin HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
35.240.143.7 - - [06/Oct/2026:13:14:49 +0000] "GET /users/login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
35.240.143.7 - - [06/Oct/2026:13:14:49 +0000] "GET /auth/login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
35.240.143.7 - - [06/Oct/2026:13:14:49 +0000] "GET /account/login HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Mobile Safari/537.36 EdgA/152.0.0.0"
35.240.143.7 - - [06/Oct/2026:13:14:49 +0000] "GET /sb70xawwtk80ffsv5gh8 HTTP/2.0" 404 1855 "-" "Mozilla/5.0 (compatible; cohere-ai; +https:
...
show less
Brute-Force
๐บ๐ธ
IndigoRidge
2026-10-06 11:47:42
(8 hours ago)
35.240.143.7 - - [06/Oct/2026:07:47:40 -0400] "GET /.ssh/id_rsa HTTP/1.1" 503 5725 "-" "Mozilla/5.0 ...
show more
35.240.143.7 - - [06/Oct/2026:07:47:40 -0400] "GET /.ssh/id_rsa HTTP/1.1" 503 5725 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.4; +https://openai.com/gptbot"
35.240.143.7 - - [06/Oct/2026:07:47:41 -0400] "GET /@fs/app/.env?raw?? HTTP/1.1" 503 5725 "-" "Mozilla/5.0 (compatible; Google-Extended; +http://www.google.com/bot.html)"
35.240.143.7 - - [06/Oct/2026:07:47:41 -0400] "GET /@fs/src/.env?raw?? HTTP/1.1" 503 5725 "-" "CCBot/2.0 (https://commoncrawl.org/faq/)"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 11:18:36
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.143.7 (7.143.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.143.7 (7.143.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 07:18:32.363569 2026] [security2:error] [pid 32248:tid 32248] [client 35.240.143.7:48072] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thegamblefamily.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thegamblefamily.com"] [uri "/z9x8c7v6b5-debug-trigger-thegamblefamily.com"] [unique_id "asTZCLSopvBEGusqXJ7h4AAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
cg-design.co.uk
2026-10-06 11:14:31
(8 hours ago)
(mod_security) mod_security triggered on hostname [redacted] 35.240.143.7 (SG/Singapore/7.143.240.35 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.240.143.7 (SG/Singapore/7.143.240.35.bc.googleusercontent.com)
show less
SQL Injection
๐ซ๐ท
masterguru
2026-10-06 10:45:11
(9 hours ago)
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encod ...
show more
HTTP header is restricted by policy (/x-middleware-subrequest/). String match within "/content-encoding/ /proxy/ /lock-token/ /content-range/ /if/ /x-http-method-override/ /x-http-method/ /x-method-override/ /x-middleware-subrequest/ /expect/" at TX:header_name_920450_x-middleware-subrequest. (920450-197)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-06 10:04:42
(9 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.143.7 (7.143.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.143.7 (7.143.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 06:04:37.810323 2026] [security2:error] [pid 10945:tid 10945] [client 35.240.143.7:57894] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thediscounttoolbox.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thediscounttoolbox.com"] [uri "/z9x8c7v6b5-debug-trigger-thediscounttoolbox.com"] [unique_id "asTHtQsyDfAY_KoP20CkUwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
EGP Abuse Dept
2026-10-06 09:59:53
(9 hours ago)
Scanning for web/db/file exploits on thedfcd.com
SQL Injection
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 09:36:32
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.143.7 (7.143.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.143.7 (7.143.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 05:36:26.907571 2026] [security2:error] [pid 17870:tid 17870] [client 35.240.143.7:59166] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thecrossing1.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thecrossing1.com"] [uri "/z9x8c7v6b5-debug-trigger-thecrossing1.com"] [unique_id "asTBGvAc50L3DGieajaz0QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
sc user
2026-10-06 09:29:45
(10 hours ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan
๐บ๐ธ
MatCat
2026-10-06 09:05:07
(10 hours ago)
Banned by fail2ban: apache-webprobe
Port Scan
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-06 08:59:44
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.143.7 (7.143.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.143.7 (7.143.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 04:59:39.828159 2026] [security2:error] [pid 5015:tid 5015] [client 35.240.143.7:37152] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thechoiceint.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thechoiceint.com"] [uri "/z9x8c7v6b5-debug-trigger-thechoiceint.com"] [unique_id "asS4e5zhzFXBJbZ9bRPBUwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-10-06 08:33:01
(11 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 08:27:59
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.143.7 (7.143.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.143.7 (7.143.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 04:27:53.755941 2026] [security2:error] [pid 26108:tid 26108] [client 35.240.143.7:34562] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thebronsons.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thebronsons.com"] [uri "/z9x8c7v6b5-debug-trigger-thebronsons.com"] [unique_id "asSxCQTwOmy07GUvZuV1kwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WizardsToolkit
2026-10-06 08:23:58
(11 hours ago)
tried to access server backup files
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 07:30:30
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.143.7 (7.143.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.143.7 (7.143.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 03:30:25.989361 2026] [security2:error] [pid 5632:tid 5632] [client 35.240.143.7:53058] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||jbcllcnet.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jbcllcnet.com"] [uri "/z9x8c7v6b5-debug-trigger-jbcllcnet.com"] [unique_id "asSjkePEmHiHmscPLmVclQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack