๐บ๐ธ
TPI-Abuse
2026-10-09 21:27:59
(3 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.238.158.211 (211.158.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.238.158.211 (211.158.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 17:27:53.276694 2026] [security2:error] [pid 5983:tid 5992] [client 35.238.158.211:33794] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thebiglies.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thebiglies.com"] [uri "/z9x8c7v6b5-debug-trigger-thebiglies.com"] [unique_id "aslcWRGIKz_foqyDL7DcUgAAAUc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 21:05:15
(25 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.238.158.211 (211.158.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.238.158.211 (211.158.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 17:05:08.295099 2026] [security2:error] [pid 14618:tid 14618] [client 35.238.158.211:45086] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tenmenband.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tenmenband.com"] [uri "/z9x8c7v6b5-debug-trigger-tenmenband.com"] [unique_id "aslXBM6FvcTI-6m78Y-WlAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 20:45:25
(45 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.238.158.211 (211.158.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.238.158.211 (211.158.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 16:45:20.699512 2026] [security2:error] [pid 31816:tid 31816] [client 35.238.158.211:39622] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||teakprop.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "teakprop.com"] [uri "/z9x8c7v6b5-debug-trigger-teakprop.com"] [unique_id "aslSYN9jsq1vzMa_pQw3XAAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 20:25:57
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.238.158.211 (211.158.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.238.158.211 (211.158.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 16:25:54.266817 2026] [security2:error] [pid 3436:tid 3436] [client 35.238.158.211:40964] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tallahasseepartybuses.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tallahasseepartybuses.com"] [uri "/z9x8c7v6b5-debug-trigger-tallahasseepartybuses.com"] [unique_id "aslN0n7eoLWF6JRYZd_DDQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-10-09 20:25:31
(1 hour ago)
460 requests with url.path */@fs/*
139 requests with url.path */proc/*
101 requests with url.path ...
show more
460 requests with url.path */@fs/*
139 requests with url.path */proc/*
101 requests with url.path *config.json
show less
Brute-Force
Bad Web Bot
Anonymous
2026-10-09 20:20:26
(1 hour ago)
Malicious scan detected (score: 5 >= 4): Path Matches Pattern (/credentials, weight 5) on path: /cre ...
show more
Malicious scan detected (score: 5 >= 4): Path Matches Pattern (/credentials, weight 5) on path: /credentials.json
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 20:09:47
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.238.158.211 (211.158.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.238.158.211 (211.158.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 16:09:41.527677 2026] [security2:error] [pid 15149:tid 15149] [client 35.238.158.211:49694] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||syconline.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "syconline.com"] [uri "/z9x8c7v6b5-debug-trigger-syconline.com"] [unique_id "aslKBbnrRj4dqAtR_ukYyQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 19:50:14
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.238.158.211 (211.158.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.238.158.211 (211.158.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:50:10.199686 2026] [security2:error] [pid 5074:tid 5074] [client 35.238.158.211:40520] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||supportconvalelementary.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "supportconvalelementary.com"] [uri "/z9x8c7v6b5-debug-trigger-supportconvalelementary.com"] [unique_id "aslFcvoB_xKANwsvDpTa4QAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 19:28:39
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.238.158.211 (211.158.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.238.158.211 (211.158.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:28:31.827374 2026] [security2:error] [pid 22611:tid 22611] [client 35.238.158.211:52950] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||styxwetworld.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "styxwetworld.com"] [uri "/z9x8c7v6b5-debug-trigger-styxwetworld.com"] [unique_id "aslAXzxktBc58-kSa_8rxAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 19:07:06
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.238.158.211 (211.158.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.238.158.211 (211.158.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:07:00.615535 2026] [security2:error] [pid 2350:tid 2350] [client 35.238.158.211:60746] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stevenkloepfer.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stevenkloepfer.com"] [uri "/z9x8c7v6b5-debug-trigger-stevenkloepfer.com"] [unique_id "ask7VDEijlGslUA_SY8nhwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 18:48:44
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.238.158.211 (211.158.238.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.238.158.211 (211.158.238.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 14:48:41.118104 2026] [security2:error] [pid 12322:tid 12322] [client 35.238.158.211:42252] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stablechase.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stablechase.com"] [uri "/z9x8c7v6b5-debug-trigger-stablechase.com"] [unique_id "ask3CYr9CKm4XdqdVD6SfQAAADM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-09 18:39:25
(2 hours ago)
Excessive multi-domain requests
Brute-Force
๐ฉ๐ช
ghostwarriors
2026-10-09 18:20:11
(3 hours ago)
Webpage scraping
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
lnklnx
2026-10-09 18:15:12
(3 hours ago)
www.lnklnx.com:443 35.238.158.211 - - [09/Oct/2026:13:15:11 -0500] "GET /public/plugins/text/../../. ...
show more
www.lnklnx.com:443 35.238.158.211 - - [09/Oct/2026:13:15:11 -0500] "GET /public/plugins/text/../../../../../../../../proc/self/environ HTTP/1.1" 400 515 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Safari/605.1.15 (Applebot/0.1)"
...
show less
Web App Attack
๐ฉ๐ช
itsolon
2026-10-09 18:08:30
(3 hours ago)
[09/Oct/2026:20:08:29 +0200] 179156930946.165034 35.238.158.211 0 217.154.7.177 443
[09/Oct/2026:20: ...
show more
[09/Oct/2026:20:08:29 +0200] 179156930946.165034 35.238.158.211 0 217.154.7.177 443
[09/Oct/2026:20:08:29 +0200] 179156930994.115633 35.238.158.211 0 217.154.7.177 443
[09/Oct/2026:20:08:29 +0200] 17915693098.881784 35.238.158.211 0 217.154.7.177 443
[09/Oct/2026:20:08:29 +0200] 179156930943.297755 35.238.158.211 0 217.154.7.177 443
[09/Oct/2026:20:08:29 +0200] 179156930999.921823 35.238.158.211 0 217.154.7.177 443
...
show less
Port Scan
Hacking
Brute-Force
Web App Attack