๐บ๐ธ
TPI-Abuse
2026-10-09 21:59:53
(15 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 17:59:45.092362 2026] [security2:error] [pid 31753:tid 31753] [client 35.253.198.204:58436] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||berksoft.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "berksoft.com"] [uri "/z9x8c7v6b5-debug-trigger-berksoft.com"] [unique_id "aslj0cP4-4fOAbJT30OnkQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 21:35:02
(40 minutes ago)
(mod_security) mod_security (id:210730) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 17:34:57.489830 2026] [security2:error] [pid 31564:tid 31564] [client 35.253.198.204:60836] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||be4ventures.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "be4ventures.com"] [uri "/z9x8c7v6b5-debug-trigger-be4ventures.com"] [unique_id "asleAUWvJOyf9IQJ1f27HwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 20:56:32
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 16:56:25.294983 2026] [security2:error] [pid 9459:tid 9459] [client 35.253.198.204:36838] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||backyardtossers.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "backyardtossers.com"] [uri "/z9x8c7v6b5-debug-trigger-backyardtossers.com"] [unique_id "aslU-QEOM-J9fw3Moili2QAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 19:36:41
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 15:36:36.700033 2026] [security2:error] [pid 14510:tid 14510] [client 35.253.198.204:60636] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||armrms.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "armrms.com"] [uri "/z9x8c7v6b5-debug-trigger-armrms.com"] [unique_id "aslCRIm9_SSjf2NG3E7G9wAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-10-09 19:33:02
(2 hours ago)
Excessive multi-domain requests
Brute-Force
๐บ๐ธ
oralunal
2026-10-09 18:38:55
(3 hours ago)
IP banned by Fail2Ban in jail ah-suss access.log mvfnds
...
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 18:36:24
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 14:36:17.710249 2026] [security2:error] [pid 24417:tid 24417] [client 35.253.198.204:60132] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||amybeam.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "amybeam.com"] [uri "/z9x8c7v6b5-debug-trigger-amybeam.com"] [unique_id "ask0IQo5b2IBsZsntoIvJgAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
bazter.pro
2026-10-09 18:18:47
(3 hours ago)
Fail2Ban: plesk-bot-aggressive - 15 failures
Port Scan
Bad Web Bot
Web App Attack
๐บ๐ธ
Lee Daniel
2026-10-09 18:14:33
(4 hours ago)
35.253.198.204 - - [09/Oct/2026:14:14:32 -0400] "GET /.htpasswd HTTP/1.1" 403 377 "https://altmanbar ...
show more
35.253.198.204 - - [09/Oct/2026:14:14:32 -0400] "GET /.htpasswd HTTP/1.1" 403 377 "https://altmanbarbados.com/.htpasswd" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko; compatible; Perplexity-User/1.0; +https://perplexity.ai/perplexitybot)"
...
show less
DDoS Attack
Web Spam
Email Spam
Port Scan
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 18:04:53
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 14:04:47.862394 2026] [security2:error] [pid 13250:tid 13250] [client 35.253.198.204:58944] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||almudenastrust.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "almudenastrust.com"] [uri "/z9x8c7v6b5-debug-trigger-almudenastrust.com"] [unique_id "asksv0ZjZyGtDAqLOGB-SQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 17:49:13
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 13:49:08.604739 2026] [security2:error] [pid 16793:tid 16793] [client 35.253.198.204:46572] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||alianzafreight.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "alianzafreight.com"] [uri "/z9x8c7v6b5-debug-trigger-alianzafreight.com"] [unique_id "askpFPpQQ1AYiE0tH4dsrAAAACY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 17:26:33
(4 hours ago)
(mod_security) mod_security (id:949110) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:949110) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 13:26:28.130100 2026] [security2:error] [pid 19811:tid 19811] [client 35.253.198.204:55584] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "akistech.com"] [uri "/z9x8c7v6b5-debug-trigger-akistech.com"] [unique_id "askjxCBYRhQdtd1Ire4T1AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 17:10:18
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 13:10:14.419696 2026] [security2:error] [pid 7246:tid 7284] [client 35.253.198.204:40486] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ahrgroup.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ahrgroup.com"] [uri "/z9x8c7v6b5-debug-trigger-ahrgroup.com"] [unique_id "askf9geI3X4OoYtYjae3SAAAAcg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 16:49:47
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 12:49:43.497660 2026] [security2:error] [pid 31739:tid 31739] [client 35.253.198.204:46160] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||afdfurniture.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "afdfurniture.com"] [uri "/z9x8c7v6b5-debug-trigger-afdfurniture.com"] [unique_id "askbJ0Okgov0Jl6KMzYuIwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-09 16:31:56
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercon ...
show more
(mod_security) mod_security (id:210730) triggered by 35.253.198.204 (204.198.253.35.bc.googleusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 09 12:31:50.164789 2026] [security2:error] [pid 20097:tid 20110] [client 35.253.198.204:42858] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||adprosfla.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "adprosfla.com"] [uri "/z9x8c7v6b5-debug-trigger-adprosfla.com"] [unique_id "askW9jstw9vSSdByD8lVfAAAAUY"]
show less
Brute-Force
Bad Web Bot
Web App Attack