Anonymous
2026-09-23 10:20:20
(3 hours ago)
35.240.198.1 - - [22/Sep/2026:08:25:14 -0500] "GET /.env HTTP/1.1" 301 265 "-" "Mozilla/5.0 (compati ...
show more
35.240.198.1 - - [22/Sep/2026:08:25:14 -0500] "GET /.env HTTP/1.1" 301 265 "-" "Mozilla/5.0 (compatible; MoonshotBot/1.0; +https://kimi.ai/)" 172.71.81.81
35.240.198.1 - - [22/Sep/2026:08:25:14 -0500] "GET /.env.production HTTP/1.1" 301 276 "-" "Mozilla/5.0 (compatible; Hunyuan/1.0; +https://hunyuan.tencent.com/)" 162.158.162.46
35.240.198.1 - - [22/Sep/2026:08:25:14 -0500] "GET /.env.local HTTP/1.1" 301 271 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" 172.70.188.51
35.240.198.1 - - [22/Sep/2026:08:25:14 -0500] "GET /.env.save HTTP/1.1" 301 270 "-" "Mozilla/5.0 (compatible; Kimi-SearchBot/1.0; +https://kimi.ai/)" 162.158.189.64
35.240.198.1 - - [22/Sep/2026:08:25:15 -0500] "GET /.env.prod HTTP/1.1" 301 270 "-" "Mozilla/5.0 (compatible; YiBot/1.0; +https://01.ai/)" 172.70.188.51
35.240.198.1 - - [22/Sep/2026:08:25:17 -0500] "GET /.env.php.bak HTTP/1.1" 301 273 "-" "Mozilla/5.0 (compatible; Qwenbot/1.0; +https://qwen.alibaba.com/)" 162.158.88.153
35.240.198.1 -
...
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 03:26:11
(10 hours ago)
Bot / seems abusive / Apache connections: 26
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
๐ณ๐ฑ
ConsulHosting
2026-09-23 01:50:47
(11 hours ago)
Excessive failed CAPTCHA attempts (CAPTCHA DoS)
Web App Attack
๐บ๐ธ
rdpguard.com
2026-09-23 00:01:22
(13 hours ago)
RdpGuard detected brute-force attempt on HTTP
Brute-Force
Anonymous
2026-09-22 23:22:05
(14 hours ago)
35.240.198.1 - - [23/Sep/2026:01:22:03 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Andr ...
show more
35.240.198.1 - - [23/Sep/2026:01:22:03 +0200] "GET / HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36 EdgA/153.0.0.0"
35.240.198.1 - - [23/Sep/2026:01:22:03 +0200] "GET /users/login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36 EdgA/153.0.0.0"
35.240.198.1 - - [23/Sep/2026:01:22:03 +0200] "GET /auth/login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36 EdgA/153.0.0.0"
35.240.198.1 - - [23/Sep/2026:01:22:04 +0200] "GET /auth HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/153.0.0.0 Mobile Safari/537.36 EdgA/153.0.0.0"
35.240.198.1 - - [23/Sep/2026:01:22:04 +0200] "GET /user/login HTTP/1.1" 403 183 "-" "Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko)
...
show less
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 23:13:13
(14 hours ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
oralunal
2026-09-22 16:30:08
(21 hours ago)
IP banned by Fail2Ban in jail ah-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 16:15:39
(21 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.198.1 (1.198.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.198.1 (1.198.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 12:15:33.049576 2026] [security2:error] [pid 17222:tid 17222] [client 35.240.198.1:39830] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cajunfriedturkey.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cajunfriedturkey.com"] [uri "/z9x8c7v6b5-debug-trigger-cajunfriedturkey.com"] [unique_id "arKppWUMpJoWc-AM3CqX5AAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
ELYAZ
2026-09-22 15:53:44
(21 hours ago)
(y3) Failed access -byebye- from 35.240.198.1 (SG/Singapore/1.198.240.35.bc.googleusercontent.com): ...
show more
(y3) Failed access -byebye- from 35.240.198.1 (SG/Singapore/1.198.240.35.bc.googleusercontent.com): (CF_ENABLE)
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-22 14:44:52
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.198.1 (1.198.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.198.1 (1.198.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:44:47.011600 2026] [security2:error] [pid 7933:tid 7967] [client 35.240.198.1:40162] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||philacentric.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "philacentric.com"] [uri "/z9x8c7v6b5-debug-trigger-philacentric.com"] [unique_id "arKUX6YtTkFWwP-GXBfS4gAAAQM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-22 14:33:50
(23 hours ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 14:26:43
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.198.1 (1.198.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.198.1 (1.198.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 10:26:37.887325 2026] [security2:error] [pid 22496:tid 22496] [client 35.240.198.1:42182] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rassehundeverein.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rassehundeverein.com"] [uri "/z9x8c7v6b5-debug-trigger-rassehundeverein.com"] [unique_id "arKQHTkcnFXbgzlqhyOenwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:33:44
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.240.198.1 (1.198.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.198.1 (1.198.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:33:36.767792 2026] [security2:error] [pid 742261:tid 742261] [client 35.240.198.1:55980] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||raystransmission.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "raystransmission.com"] [uri "/z9x8c7v6b5-debug-trigger-raystransmission.com"] [unique_id "arKDsPydFU0eY0JA3-XzmQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 13:18:20
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 35.240.198.1 (1.198.240.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.198.1 (1.198.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 09:18:17.556071 2026] [security2:error] [pid 13720:tid 13865] [client 35.240.198.1:47944] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rbarw.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rbarw.com"] [uri "/z9x8c7v6b5-debug-trigger-rbarw.com"] [unique_id "arKAGSrMyVdROKIIOGLPDgAAApg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 13:11:46
(1 day ago)
35.240.198.1 - - [22/Sep/2026:15:11:26 +0200] "GET /.next/.env HTTP/2.0" 403 272 "-" "Mozilla/5.0 (M ...
show more
35.240.198.1 - - [22/Sep/2026:15:11:26 +0200] "GET /.next/.env HTTP/2.0" 403 272 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/131.0.0.0 Safari/537.36; compatible; OAI-SearchBot/1.4; +https://opena
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack