🇺🇸
TPI-Abuse
2026-09-09 16:59:10
(3 hours ago)
(mod_security) mod_security (id:210831) triggered by 35.192.61.189 (189.61.192.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210831) triggered by 35.192.61.189 (189.61.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 12:59:02.937326 2026] [security2:error] [pid 6579:tid 6579] [client 35.192.61.189:36596] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:user-agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||salernospizza.com|F|4"] [data "ContactBot/"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "salernospizza.com"] [uri "/"] [unique_id "aqGQVlhjrjdc-4unwWHTPgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 16:42:18
(4 hours ago)
(mod_security) mod_security (id:210831) triggered by 35.192.61.189 (189.61.192.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210831) triggered by 35.192.61.189 (189.61.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 12:42:13.084735 2026] [security2:error] [pid 29847:tid 29847] [client 35.192.61.189:39056] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:user-agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||meierstavern.com|F|4"] [data "ContactBot/"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "meierstavern.com"] [uri "/"] [unique_id "aqGMZUCvKGei-qKmnLmczQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 12:57:06
(7 hours ago)
(mod_security) mod_security (id:210831) triggered by 35.192.61.189 (189.61.192.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210831) triggered by 35.192.61.189 (189.61.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:57:03.812906 2026] [security2:error] [pid 27752:tid 27752] [client 35.192.61.189:36884] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:user-agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.drbbenefits.com|F|4"] [data "ContactBot/"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.drbbenefits.com"] [uri "/"] [unique_id "aqFXn25uVyGzQT8K9raEfAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-09 12:16:24
(8 hours ago)
(mod_security) mod_security (id:210831) triggered by 35.192.61.189 (189.61.192.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210831) triggered by 35.192.61.189 (189.61.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 08:16:19.393577 2026] [security2:error] [pid 13353:tid 13353] [client 35.192.61.189:42258] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:user-agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.readyremotely.com|F|4"] [data "ContactBot/"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.readyremotely.com"] [uri "/"] [unique_id "aqFOE4POW71wjuYQhNTWywAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2025-06-14 16:06:00
(1 year ago)
IPBlock protected site ID [2815-wdn][s=02].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2025-06-13 06:50:00
(1 year ago)
IPBlock protected site ID [2815-wdn][s=02].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2025-06-10 21:47:00
(1 year ago)
IPBlock protected site ID [2815-wdn][s=02].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2025-06-10 03:49:00
(1 year ago)
IPBlock protected site ID [2815-wdn][s=02].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2025-06-09 04:33:00
(1 year ago)
IPBlock protected site ID [2815-wdn][s=02].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
🇨🇭
backslash
2025-06-08 16:05:07
(1 year ago)
block ruleset 3D3AFA921A373ECE19B6BA285C2D722163304638
Bad Web Bot
🇺🇸
ipblock.com
2025-06-08 14:20:00
(1 year ago)
IPBlock protected site ID [2815-wdn][s=02].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2025-06-07 18:33:46
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 35.192.61.189 (189.61.192.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.192.61.189 (189.61.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 07 14:33:43.373949 2025] [security2:error] [pid 1836432:tid 1836432] [client 35.192.61.189:43948] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.informativearticles.com|F|2"] [data ".inc"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.informativearticles.com"] [uri "/spyware/inc/ads-top.inc"] [unique_id "aESGB7RF89nJcxfR2ZSHzQAAAAw"], referer: http://www.informativearticles.com/spyware/inc/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2025-06-06 22:09:00
(1 year ago)
IPBlock protected site ID [955-wdo][s=11].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
🇵🇹
PT
2025-06-06 12:25:00
(1 year ago)
Scrapy/2.11.2
Brute-Force
🇺🇸
TPI-Abuse
2025-06-03 03:04:24
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 35.192.61.189 (189.61.192.35.bc.googleuserconte ...
show more
(mod_security) mod_security (id:210730) triggered by 35.192.61.189 (189.61.192.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 02 23:04:17.987344 2025] [security2:error] [pid 3711557:tid 3711557] [client 35.192.61.189:58558] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||john-bell-associates.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "john-bell-associates.com"] [uri "/reddit.com"] [unique_id "aD5mMYw24bExl_wU4Pat1gAAAAE"], referer: http://john-bell-associates.com
show less
Brute-Force
Bad Web Bot
Web App Attack