๐บ๐ธ
micropedro
2026-09-24 14:15:31
(1 day ago)
4 incidents: malicious activity. First: 2026-09-22 20:16, Last: 2026-09-24 10:15 UTC. Triggers: unkn ...
show more
4 incidents: malicious activity. First: 2026-09-22 20:16, Last: 2026-09-24 10:15 UTC. Triggers: unknown.
show less
Port Scan
๐ฉ๐ช
klaus_ph
2026-09-23 20:54:13
(2 days ago)
2026-09-23 04:04:59,763 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 35.240.149.224
. ...
show more
2026-09-23 04:04:59,763 fail2ban.actions [535885]: NOTICE [ipblocklist] Ban 35.240.149.224
...
show less
Bad Web Bot
๐จ๐ฆ
polycoda
2026-09-22 11:59:33
(3 days ago)
๐ฅ VERY AGGRESSIVE SCANNER probed over 200 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack
๐ฎ๐ณ
evicky2002
2026-09-22 06:00:01
(3 days ago)
Confirmed malicious by STILWaters CTI platform (score=100, sources=1)
Hacking
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-09-22 01:04:28
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.240.149.224 (224.149.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.149.224 (224.149.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 21:04:24.447886 2026] [security2:error] [pid 19681:tid 19691] [client 35.240.149.224:42826] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.peapageprod.pwrcoupling.com|F|2"] [data ".peapageprod.pwrcoupling.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.peapageprod.pwrcoupling.com"] [uri "/z9x8c7v6b5-debug-trigger-www.peapageprod.pwrcoupling.com"] [unique_id "arHUGMB2oIlJfrJRsQuEHQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
andypiper
2026-09-22 01:00:40
(3 days ago)
CrowdSec ban for AbuseIPDB Top List
Brute-Force
Web App Attack
๐ฉ๐ช
maxpower
2026-09-22 00:30:15
(3 days ago)
(junkbot) REGOLA 8 - Junk Bot Blocked 35.240.149.224 (SG/Singapore/224.149.240.35.bc.googleuserconte ...
show more
(junkbot) REGOLA 8 - Junk Bot Blocked 35.240.149.224 (SG/Singapore/224.149.240.35.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 35.240.149.224 - - [22/Sep/2026:02:30:12 +0200] "GET /.bash_profile HTTP/2.0" 200 12147 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; ClaudeBot/1.0; [email protected] )" "-" host=mediaqualitylab.com
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-09-22 00:15:44
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.240.149.224 (224.149.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.149.224 (224.149.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 20:15:37.525634 2026] [security2:error] [pid 4125:tid 4125] [client 35.240.149.224:36202] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||book-arts.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "book-arts.com"] [uri "/z9x8c7v6b5-debug-trigger-book-arts.com"] [unique_id "arHIqR7eABTeAQmmyiqu3AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-21 23:55:58
(3 days ago)
222 requests with url.path */@fs/*
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-21 23:54:03
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.149.224 (224.149.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.149.224 (224.149.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 19:53:57.119770 2026] [security2:error] [pid 25688:tid 25688] [client 35.240.149.224:58942] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.pipperonline.gulftelecom.com"] [uri "/%2e%2e/%2e%2e/%2e%2e/%2e%2e/.env"] [unique_id "arHDlfl0BJkNWhvk5_5DhgAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
23p02732
2026-09-21 23:06:35
(4 days ago)
Automated web scanning and malicious probing
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-21 21:39:08
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 35.240.149.224 (224.149.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210492) triggered by 35.240.149.224 (224.149.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 17:39:02.492335 2026] [security2:error] [pid 770:tid 770] [client 35.240.149.224:47126] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.brucerohr.com"] [uri "/@fs/app/.env"] [unique_id "arGj9oy2vSqBl6ZluqQn7gAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 21:02:47
(4 days ago)
35.240.149.224 - - [21/Sep/2026:21:02:47 +0000] "GET /frontend/.env HTTP/2.0" 404 16596 "-" "Mozilla ...
show more
35.240.149.224 - - [21/Sep/2026:21:02:47 +0000] "GET /frontend/.env HTTP/2.0" 404 16596 "-" "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)"
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 20:02:47
(4 days ago)
Portscan: TCP/8443 (3x), TCP/8080 (3x), TCP/80, TCP/443 (2x)
Port Scan
๐ฒ๐พ
Rizzy
2026-09-21 19:48:57
(4 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack