πΊπΈ
TPI-Abuse
2026-09-23 02:39:05
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.239.2.113 (113.2.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.239.2.113 (113.2.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 22:38:59.993147 2026] [security2:error] [pid 31728:tid 31728] [client 35.239.2.113:42956] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||msbasile.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "msbasile.com"] [uri "/z9x8c7v6b5-debug-trigger-msbasile.com"] [unique_id "arM7w2fLA1ix5ljppcwsnwAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-23 02:14:51
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.239.2.113 (113.2.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.239.2.113 (113.2.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 22:14:44.802774 2026] [security2:error] [pid 4163:tid 4163] [client 35.239.2.113:45204] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mspish2.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mspish2.com"] [uri "/z9x8c7v6b5-debug-trigger-mspish2.com"] [unique_id "arM2FJY2DGbEYvRpuv8JSQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
EGP Abuse Dept
2026-09-23 01:56:08
(3 days ago)
Scanning for web/db/file exploits on www.mtc-forklifts.com
SQL Injection
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 01:45:12
(3 days ago)
Bot / seems abusive / Apache connections: 24
DDoS Attack
Web Spam
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-23 01:44:24
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.239.2.113 (113.2.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.239.2.113 (113.2.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 21:44:19.966644 2026] [security2:error] [pid 11035:tid 11064] [client 35.239.2.113:37070] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mtiminis.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mtiminis.com"] [uri "/z9x8c7v6b5-debug-trigger-mtiminis.com"] [unique_id "arMu82uNTwIQehXVsPcSmgAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
hero2026
2026-09-23 01:06:23
(3 days ago)
Blocked by Fail2ban
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-23 01:01:59
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.239.2.113 (113.2.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.239.2.113 (113.2.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 21:01:52.884776 2026] [security2:error] [pid 7955:tid 7955] [client 35.239.2.113:48280] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||muddybuddypals.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "muddybuddypals.com"] [uri "/z9x8c7v6b5-debug-trigger-muddybuddypals.com"] [unique_id "arMlALOG4pHBthriHoautwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-23 01:00:06
(3 days ago)
| Multiple common web attacks from same source ip. (multiple servers)
Web App Attack
Hacking
SQL Injection
π©πͺ
palzer.IT
2026-09-23 00:55:58
(3 days ago)
Fail2ban automatic report for plesk-apache-badbot: 35.239.2.113 - - [23/Sep/2026:02:55:34 +0200] GET ...
show more
Fail2ban automatic report for plesk-apache-badbot: 35.239.2.113 - - [23/Sep/2026:02:55:34 +0200] GET / [DOMAIN_REMOVED] 200 15152 [DOMAIN_REMOVED] Mozilla/5.0 (compatible; Amazonbot/0.1; +[DOMAIN_REMOVED]
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-23 00:40:29
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.239.2.113 (113.2.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.239.2.113 (113.2.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 20:40:23.559889 2026] [security2:error] [pid 28758:tid 28758] [client 35.239.2.113:33974] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mukau.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mukau.com"] [uri "/z9x8c7v6b5-debug-trigger-mukau.com"] [unique_id "arMf96R4aILwEBpPr86X1AAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π¦
Dunham Support
2026-09-22 23:16:25
(3 days ago)
(mod_security) mod_security triggered on hostname [redacted] 35.239.2.113 (US/United States/113.2.23 ...
show more
(mod_security) mod_security triggered on hostname [redacted] 35.239.2.113 (US/United States/113.2.239.35.bc.googleusercontent.com)
show less
SQL Injection
πΊπΈ
TPI-Abuse
2026-09-22 22:51:58
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.239.2.113 (113.2.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.239.2.113 (113.2.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:51:53.206336 2026] [security2:error] [pid 21786:tid 21786] [client 35.239.2.113:53016] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||muskogeecleaning.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "muskogeecleaning.com"] [uri "/z9x8c7v6b5-debug-trigger-muskogeecleaning.com"] [unique_id "arMGicjwfv9FJbOFAmezNQAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 22:36:11
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.239.2.113 (113.2.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.239.2.113 (113.2.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 18:36:06.741437 2026] [security2:error] [pid 25522:tid 25522] [client 35.239.2.113:59878] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mutiful.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mutiful.com"] [uri "/z9x8c7v6b5-debug-trigger-mutiful.com"] [unique_id "arMC1it62tOfs8SCW-HLsQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π·π΄
clauss
2026-09-22 22:24:17
(3 days ago)
35.239.2.113 - - [23/Sep/2026:01:24:16 +0300] "GET /firebase-adminsdk.json HTTP/2.0" 301 0 "-" "Mozi ...
show more
35.239.2.113 - - [23/Sep/2026:01:24:16 +0300] "GET /firebase-adminsdk.json HTTP/2.0" 301 0 "-" "Mozilla/5.0 (compatible; PanguBot/1.0; +https://www.huaweicloud.com/)"
35.239.2.113 - - [23/Sep/2026:01:24:16 +0300] "GET /secrets.yml HTTP/2.0" 301 0 "-" "Mozilla/5.0 (compatible; Googlebot/2.1; +http://www.google.com/bot.html)"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-22 19:50:32
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 35.239.2.113 (113.2.239.35.bc.googleusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 35.239.2.113 (113.2.239.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 15:50:26.238422 2026] [security2:error] [pid 29910:tid 29910] [client 35.239.2.113:40308] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mydarklady.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mydarklady.com"] [uri "/z9x8c7v6b5-debug-trigger-mydarklady.com"] [unique_id "arLcAroc4Awd8fLL9I4fUgAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack