๐บ๐ธ
TPI-Abuse
2026-09-23 01:39:21
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.229.239 (239.229.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.229.239 (239.229.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 21:39:17.270054 2026] [security2:error] [pid 9334:tid 9334] [client 35.240.229.239:54968] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.seebeexee.com|F|2"] [data ".seebeexee.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.seebeexee.com"] [uri "/z9x8c7v6b5-debug-trigger-www.seebeexee.com"] [unique_id "arMtxX25p7O4mDSKkytHiAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-09-23 01:06:16
(12 hours ago)
crowdsecurity/http-probing
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-09-23 00:23:56
(12 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.240.229.239 (SG/Singapore/239.229.240.35.bc. ...
show more
(mod_security) mod_security (id:949110) triggered by 35.240.229.239 (SG/Singapore/239.229.240.35.bc.googleusercontent.com): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 22:13:28
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.229.239 (239.229.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.229.239 (239.229.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:13:25.102337 2026] [security2:error] [pid 26757:tid 26757] [client 35.240.229.239:39190] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.schunagroup.com|F|2"] [data ".schunagroup.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.schunagroup.com"] [uri "/z9x8c7v6b5-debug-trigger-www.schunagroup.com"] [unique_id "arL9hepjCDY5jIlEibKMrgAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
e.fierstra
2026-09-22 22:09:07
(15 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Alt255
2026-09-22 21:52:26
(15 hours ago)
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Exam ...
show more
[ti-24al] Web exploit scanning: 1 suspicious requests detected by fail2ban jail apache-scanner. Example: 35.240.229.239 - - [22/Sep/2026:23:52:26 +0200] "GET /.env.production HTTP/2.0" 403 432 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
...
show less
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-09-22 20:48:55
(16 hours ago)
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 35.240.229.239 (SG/Singapore/239.22 ...
show more
LF_MODSEC: (mod_security) mod_security (id:1000001) triggered by 35.240.229.239 (SG/Singapore/239.229.240.35.bc.googleusercontent.com): 2 in the last 3600 secs
show less
Web App Attack
๐ฉ๐ช
itsolon
2026-09-22 20:12:35
(17 hours ago)
[22/Sep/2026:22:12:34 +0200] 179010795482.261495 35.240.229.239 59520 217.154.7.177 443
[22/Sep/2026 ...
show more
[22/Sep/2026:22:12:34 +0200] 179010795482.261495 35.240.229.239 59520 217.154.7.177 443
[22/Sep/2026:22:12:34 +0200] 179010795411.292998 35.240.229.239 59520 217.154.7.177 443
[22/Sep/2026:22:12:35 +0200] 179010795516.594722 35.240.229.239 59520 217.154.7.177 443
[22/Sep/2026:22:12:35 +0200] 179010795586.092172 35.240.229.239 59520 217.154.7.177 443
[22/Sep/2026:22:12:35 +0200] 179010795519.104230 35.240.229.239 59520 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack
Anonymous
2026-09-22 19:39:17
(17 hours ago)
35.240.229.239 - - [22/Sep/2026:21:39:08 +0200] "GET /dist/.vite/manifest.json HTTP/1.1" 404 30048
3 ...
show more
35.240.229.239 - - [22/Sep/2026:21:39:08 +0200] "GET /dist/.vite/manifest.json HTTP/1.1" 404 30048
35.240.229.239 - - [22/Sep/2026:21:39:08 +0200] "GET /build/manifest.json HTTP/1.1" 404 30048
35.240.229.239 - - [22/Sep/2026:21:39:08 +0200] "GET /pshwk762ywsyjagtogif HTTP/1.1" 404 30048
35.240.229.239 - - [22/Sep/2026:21:39:08 +0200] "GET /dist/manifest.json HTTP/1.1" 404 30048
35.240.229.239 - - [22/Sep/2026:21:39:08 +0200] "GET /apukr3nt2uouk9cy6ybq HTTP/1.1" 404 30048
35.240.229.239 - - [22/Sep/2026:21:39:09 +0200] "GET /api/fs/exec HTTP/1.1" 404 30048
35.240.229.239 - - [22/Sep/2026:21:39:08 +0200] "GET /z9x8c7v6b5-debug-trigger-www.crypcool.com HTTP/1.1" 404 30048
35.240.229.239 - - [22/Sep/2026:21:39:13 +0200] "GET /secrets.yml HTTP/1.1" 404 30048
35.240.229.239 - - [22/Sep/2026:21:39:13 +0200] "GET /secrets.json HTTP/1.1" 404 30048
35.240.229.239 - - [22/Sep/2026:21:39:13 +0200] "GET /service-account.json HTTP/1.1" 404 30048
...
show less
Web Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 18:38:55
(18 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.240.229.239 (239.229.240.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.240.229.239 (239.229.240.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 14:38:51.364762 2026] [security2:error] [pid 919:tid 919] [client 35.240.229.239:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bbproductionsonline.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bbproductionsonline.com"] [uri "/z9x8c7v6b5-debug-trigger-bbproductionsonline.com"] [unique_id "arLLO5m_FSgZvvM8m_9PAAAAACQ"], referer: http://bbproductionsonline.com/z9x8c7v6b5-debug-trigger-bbproductionsonline.com
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-22 18:23:14
(18 hours ago)
35.240.229.239 - - [22/Sep/2026:20:23:05 +0200] "GET /dist/manifest.json HTTP/1.1" 404 30048
35.240. ...
show more
35.240.229.239 - - [22/Sep/2026:20:23:05 +0200] "GET /dist/manifest.json HTTP/1.1" 404 30048
35.240.229.239 - - [22/Sep/2026:20:23:05 +0200] "GET /83ft91abgr9fbtf02zl6 HTTP/1.1" 404 30048
35.240.229.239 - - [22/Sep/2026:20:23:05 +0200] "GET /dist/.vite/manifest.json HTTP/1.1" 404 30048
35.240.229.239 - - [22/Sep/2026:20:23:05 +0200] "GET /2hrmbun6jfd3mwbee73w HTTP/1.1" 404 30048
35.240.229.239 - - [22/Sep/2026:20:23:05 +0200] "GET /build/manifest.json HTTP/1.1" 404 30048
35.240.229.239 - - [22/Sep/2026:20:23:05 +0200] "GET /z9x8c7v6b5-debug-trigger-crypcool.com HTTP/1.1" 404 30048
35.240.229.239 - - [22/Sep/2026:20:23:06 +0200] "POST /api/fs/exec HTTP/1.1" 404 29412
35.240.229.239 - - [22/Sep/2026:20:23:10 +0200] "GET /service-account.json HTTP/1.1" 404 30048
35.240.229.239 - - [22/Sep/2026:20:23:10 +0200] "GET /secrets.yml HTTP/1.1" 404 30048
35.240.229.239 - - [22/Sep/2026:20:23:10 +0200] "GET /secrets.json HTTP/1.1" 404 30048
...
show less
Web Spam
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-22 18:13:29
(19 hours ago)
Excessive 404/403 errors
Brute-Force
๐จ๐ฆ
Mediashaker
2026-09-22 18:08:55
(19 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.240.229.239 (SG/S ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.240.229.239 (SG/Singapore/239.229.240.35.bc.googleusercontent.com)
show less
Bad Web Bot
๐ฉ๐ช
bazter.pro
2026-09-22 18:04:01
(19 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐ฉ๐ช
itsolon
2026-09-22 17:48:37
(19 hours ago)
[22/Sep/2026:19:48:36 +0200] 179009931647.658582 35.240.229.239 54114 217.154.7.177 443
[22/Sep/2026 ...
show more
[22/Sep/2026:19:48:36 +0200] 179009931647.658582 35.240.229.239 54114 217.154.7.177 443
[22/Sep/2026:19:48:37 +0200] 179009931761.101141 35.240.229.239 59000 217.154.7.177 443
[22/Sep/2026:19:48:37 +0200] 17900993170.372645 35.240.229.239 59000 217.154.7.177 443
[22/Sep/2026:19:48:37 +0200] 179009931744.388718 35.240.229.239 59000 217.154.7.177 443
[22/Sep/2026:19:48:37 +0200] 179009931742.260267 35.240.229.239 59000 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack