πΊπΈ
TPI-Abuse
2026-10-09 01:45:51
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.199.198.253 (253.198.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 104.199.198.253 (253.198.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 21:45:43.718533 2026] [security2:error] [pid 20137:tid 20137] [client 104.199.198.253:59096] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||virginiabeachlovebird.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "virginiabeachlovebird.com"] [uri "/z9x8c7v6b5-debug-trigger-virginiabeachlovebird.com"] [unique_id "ashHR7FipjrvZvKWfS29wQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
maxpower
2026-10-09 00:31:05
(3 hours ago)
(PERMBLOCK) 104.199.198.253 (TW/Taiwan/253.198.199.104.bc.googleusercontent.com) has had more than 4 ...
show more
(PERMBLOCK) 104.199.198.253 (TW/Taiwan/253.198.199.104.bc.googleusercontent.com) has had more than 4 temp blocks in the last 86400 secs; Ports: *; Direction: inout; Trigger: LF_PERMBLOCK_COUNT; Logs:
show less
Port Scan
πΈπͺ
vaia.cloud
2026-10-08 22:55:01
(5 hours ago)
crowdsecurity/http-admin-interface-probing
Brute-Force
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 22:43:45
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.199.198.253 (253.198.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 104.199.198.253 (253.198.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 18:43:37.659441 2026] [security2:error] [pid 16321:tid 16321] [client 104.199.198.253:52728] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||title26.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "title26.com"] [uri "/z9x8c7v6b5-debug-trigger-title26.com"] [unique_id "asgcmdX7iGzwKrazsglrnwAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
maxpower
2026-10-08 22:31:34
(5 hours ago)
(junkbot) REGOLA 8 - Junk Bot Blocked 104.199.198.253 (TW/Taiwan/253.198.199.104.bc.googleuserconten ...
show more
(junkbot) REGOLA 8 - Junk Bot Blocked 104.199.198.253 (TW/Taiwan/253.198.199.104.bc.googleusercontent.com): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 104.199.198.253 - - [09/Oct/2026:00:31:31 +0200] "POST / HTTP/2.0" 200 11968 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; PerplexityBot/1.0; +https://perplexity.ai/perplexitybot)" "-" host=spacehosting.ovh
show less
Port Scan
π§π·
radardatelecom
2026-10-08 22:27:13
(5 hours ago)
Blocked by Radar da Telecom firewall β abuseipdb
Bad Web Bot
Web App Attack
π§πͺ
voormedia
2026-10-08 21:59:55
(6 hours ago)
Accessed trap at '/.env'
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-08 21:31:35
(6 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.199.198.253 (253.198.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 104.199.198.253 (253.198.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 17:31:30.599258 2026] [security2:error] [pid 31571:tid 31571] [client 104.199.198.253:41826] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||virantenn.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "virantenn.com"] [uri "/z9x8c7v6b5-debug-trigger-virantenn.com"] [unique_id "asgLslB6g3gBTz4v3wRWowAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
rh24
2026-10-08 20:07:33
(8 hours ago)
(badbots) Bad bot user-agent [redacted] from 104.199.198.253 (TW/Taiwan/253.198.199.104.bc.googleuse ...
show more
(badbots) Bad bot user-agent [redacted] from 104.199.198.253 (TW/Taiwan/253.198.199.104.bc.googleusercontent.com)
show less
Hacking
πΊπΈ
TPI-Abuse
2026-10-08 20:03:18
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 104.199.198.253 (253.198.199.104.bc.googleuserc ...
show more
(mod_security) mod_security (id:210730) triggered by 104.199.198.253 (253.198.199.104.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 16:03:14.795713 2026] [security2:error] [pid 5880:tid 5880] [client 104.199.198.253:43622] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||puoci.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "puoci.com"] [uri "/z9x8c7v6b5-debug-trigger-puoci.com"] [unique_id "asf3AiT9xPRmwJKz0tElrQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
kkw
2026-10-08 20:02:36
(8 hours ago)
[REDACTED] 104.199.198.253 - - [08/Oct/2026:22:02:35 +0200] "GET /.ssh/id_ed25519 HTTP/2.0" 404 343 ...
show more
[REDACTED] 104.199.198.253 - - [08/Oct/2026:22:02:35 +0200] "GET /.ssh/id_ed25519 HTTP/2.0" 404 343 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
... (mode: searching http-sensitive-files)
show less
Bad Web Bot
Web App Attack
Anonymous
2026-10-08 19:56:49
(8 hours ago)
Portscan: TCP/443, TCP/8080 (5x), TCP/80, TCP/8443 (4x)
Port Scan
πΈπͺ
nekopavel
2026-10-08 19:55:08
(8 hours ago)
104.199.198.253 - - [08/Oct/2026:21:55:05 +0200]"GET /wp-json HTTP/2.0" 200 1482"-" pavel.gg "Mozill ...
show more
104.199.198.253 - - [08/Oct/2026:21:55:05 +0200]"GET /wp-json HTTP/2.0" 200 1482"-" pavel.gg "Mozilla/5.0 (compatible; Amazonbot/0.1; +https://developer.amazon.com/support/amazonbot)""0.000" "-""Taipei" "TW"
104.199.198.253 - - [08/Oct/2026:21:55:06 +0200]"GET /@fs/app/.env?raw?? HTTP/2.0" 444 0"-" pavel.gg "Mozilla/5.0 (compatible; Baiduspider/2.0; +http://www.baidu.com/search/spider.html)""0.000" "-""Taipei" "TW"
104.199.198.253 - - [08/Oct/2026:21:55:06 +0200]"GET /@fs/src/.env?raw?? HTTP/2.0" 200 1482"-" pavel.gg "Mozilla/5.0 (compatible; MistralAI-User/1.0; +https://mistral.ai/)""0.000" "-""Taipei" "TW"
...
show less
Hacking
Bad Web Bot
Web App Attack
π§πͺ
voormedia
2026-10-08 19:50:49
(8 hours ago)
Accessed trap at '/.npmrc'
Web App Attack
Anonymous
2026-10-08 19:30:11
(8 hours ago)
CrowdSec decision: crowdsecurity/http-crawl-non_statics (origin: crowdsec)
Port Scan