🇳🇱
Alt255
2026-09-14 10:38:56
(41 minutes ago)
[ti-14al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail <nam ...
show more
[ti-14al] Excessive 404 errors (web scanning): 25 suspicious requests detected by fail2ban jail <name>. Example: 35.253.196.22 - - \[14/Sep/2026:01:14:15 +0200\] "GET /manifest.json HTTP/1.1" 404 518 "-" "Mozilla/5.0 \(Macintosh\; Intel Mac OS X 10_15_7\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/152.0.0.0 Safari/537.36"
35.253.196.22 - - \[14/Sep/2026:01:14:15 +0200\] "GET /asset-manifest.json HTTP/1.1" 404 518 "-" "Mozilla/5.0 \(Macintosh\; Intel Mac OS X 10_15_7\) AppleWebKit/537.36 \(KHTML, like Gecko\) Chrome/152.0.0.0 Safari/537.36"
35.253.196.22 - - \[14/Sep/2026:01:14:15 +0200\] "GET /z9x8c7v6b5-debug-trigger-11st.timbular.com HTTP/1.1" 404 518 "-" "Mozilla/5.0 \(compatible\; MistralAI-User/1.0\; +https://mistral.ai/\)"
35.253.196.22 - - \[14/Sep/2026:01:14:15 +0200\] "GET /static/manifest.json HTTP/1.1" 404 5817 "-
...
show less
Bad Web Bot
Web App Attack
🇳🇱
CaduVet
2026-09-14 06:24:57
(4 hours ago)
2026-09-14 01:15:14,859 fail2ban.actions [939]: NOTICE [apache-fakegooglebot] Ban 35.253.196 ...
show more
2026-09-14 01:15:14,859 fail2ban.actions [939]: NOTICE [apache-fakegooglebot] Ban 35.253.196.22
2026-09-14 08:24:54,328 fail2ban.actions [939]: NOTICE [apache-fakegooglebot] Ban 35.253.196.22
2026-09-14 08:24:54,338 fail2ban.actions [939]: NOTICE [apache-noscript] Ban 35.253.196.22
...
show less
Brute-Force
🇲🇽
octageeks.com
2026-09-14 04:12:43
(7 hours ago)
Wordpress malicious attack:[octamissingdomain]
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 22:30:59
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.253.196.22 (22.196.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.253.196.22 (22.196.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 18:30:54.332551 2026] [security2:error] [pid 21329:tid 21329] [client 35.253.196.22:59166] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||verdadesreales.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "verdadesreales.com"] [uri "/z9x8c7v6b5-debug-trigger-verdadesreales.com"] [unique_id "aqckHuN8WjtOwoYsWVZtuQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
PlexLads
2026-09-13 21:07:22
(14 hours ago)
35.253.196.22 - - [13/Sep/2026:14:07:21 -0700] "GET /z9x8c7v6b5-debug-trigger-tidafoods.com HTTP/1.1 ...
show more
35.253.196.22 - - [13/Sep/2026:14:07:21 -0700] "GET /z9x8c7v6b5-debug-trigger-tidafoods.com HTTP/1.1" 404 12562 "-" "Mozilla/5.0 (compatible; GrokBot/1.0; +https://x.ai/)" 35.253.196.22 - - [13/Sep/2026:14:07:21 -0700] "GET /%2eenv HTTP/1.1" 403 12563 "-" "Mozilla/5.0 (compatible; KimiBot/1.0; +https://kimi.ai/)" 35.253.196.22 - - [13/Sep/2026:14:07:21 -0700] "GET /wp-json HTTP/1.1" 404 12561 "-" "Mozilla/5.0 (compatible; YouBot/1.0; +https://you.com/bot)" 35.253.196.22 - - [13/Sep/2026:14:07:21 -0700] "GET /auth/login HTTP/1.1" 404 12562 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36" 35.253.196.22 - - [13/Sep/2026:14:07:21 -0700] "GET /sign-in HTTP/1.1" 404 12563 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/150.0.0.0 Safari/537.36" 35.253.196.22 - - [13/Sep/2026:14:07:21 -0700] "GET /signin HTTP/1.1" 404 12563 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit
...
show less
Hacking
Web App Attack
🇬🇧
consul.to
2026-09-13 20:59:55
(14 hours ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-13 20:11:18
(15 hours ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: Word ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: US, Attack patterns: WordPress scanning, Backup file probing, Cloud secrets probing
show less
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 19:32:53
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.253.196.22 (22.196.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.253.196.22 (22.196.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 15:32:48.691412 2026] [security2:error] [pid 20499:tid 20499] [client 35.253.196.22:36006] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||thongtracker.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thongtracker.com"] [uri "/z9x8c7v6b5-debug-trigger-thongtracker.com"] [unique_id "aqb6YBFwbPfHQj23eAGD6AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-13 19:18:58
(16 hours ago)
cloudlinux2 fail2ban: 2026-09-13 21:13:51,620 fail2ban.filter [1591]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-13 21:13:51,620 fail2ban.filter [1591]: INFO [plesk-modsecurity] Found 35.253.196.22 - 2026-09-13 21:13:51cloudlinux2 fail2ban: 2026-09-13 21:13:51,592 fail2ban.filter [1591]: INFO [plesk-modsecurity] Found 35.253.196.22 - 2026-09-13 21:13:51cloudlinux2 fail2ban: 2026-09-13 21:13:50,713 fail2ban.filter [1591]: INFO [plesk-modsecurity] Found 35.253.196.22 - 2026-09-13 21:13:50cloudlinux2 fail2ban: 2026-09-13 21:13:51,581 fail2ban.filter [1591]: INFO [plesk-modsecurity] Found 35.253.196.22 - 2026-09-13 21:13:51cloudlinux2 fail2ban: 2026-09-13 21:13:51,606 fail2ban.filter [1591]: INFO [plesk-modsecurity] Found 35.253.196.22 - 2026-09-13 21:13:51cloudlinux2 fail2ban: 2026-09-13 21:13:50,702 fail2ban.filter [1591]: INFO [plesk-modsecurity] Found 35.253.196.22 - 2026-09-13 21:13:50cloudlinux2 fail2ban: 2026-09-13 21:13:51,695 fail2ban.actions [1591]: NOTICE [plesk-modsecurity] Ban 35.253.196.22cloudlinux2 fail2ba
show less
Brute-Force
🇧🇪
madeit
2026-09-13 18:49:05
(16 hours ago)
Web App Attack
Anonymous
2026-09-13 18:37:51
(16 hours ago)
Blocked by ModSec and CSF
Port Scan
🇺🇸
TPI-Abuse
2026-09-13 17:33:08
(17 hours ago)
(mod_security) mod_security (id:210492) triggered by 35.253.196.22 (22.196.253.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210492) triggered by 35.253.196.22 (22.196.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 13:33:04.032391 2026] [security2:error] [pid 10447:tid 10447] [client 35.253.196.22:59526] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thewarmachineguns.com"] [uri "/@fs/src/.env"] [unique_id "aqbeUKjBbGUXGaYVzx7xMQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
Mediashaker
2026-09-13 17:13:27
(18 hours ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.253.196.22 (US/Un ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 35.253.196.22 (US/United States/22.196.253.35.bc.googleusercontent.com)
show less
Bad Web Bot
🇳🇱
e.fierstra
2026-09-13 17:03:27
(18 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
🇬🇧
sc user
2026-09-13 15:21:07
(19 hours ago)
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad ...
show more
Fail2Ban nginx: repeated suspicious HTTP requests consistent with automated probing, scanning or bad bot behaviour. Technical log details and local server identifiers intentionally omitted for privacy.
show less
Bad Web Bot
Web App Attack
Port Scan