๐บ๐ธ
TPI-Abuse
2026-09-30 00:38:25
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 103.96.149.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 103.96.149.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:38:15.126580 2026] [security2:error] [pid 29379:tid 29379] [client 103.96.149.7:51852] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||seanevans.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "seanevans.com"] [uri "/okok.cer"] [unique_id "arxZ9ztIWiBz8i8Ri2SapAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 19:02:04
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 103.96.149.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 103.96.149.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 15:01:50.915387 2026] [security2:error] [pid 936:tid 936] [client 103.96.149.7:57666] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sandpointidaho.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sandpointidaho.com"] [uri "/okok.cer"] [unique_id "arwLHueEjYYgJBtCwXBrSwAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-29 09:37:03
(1 day ago)
Banned by Fail2Ban on server
Web App Attack
๐ฌ๐ง
consul.to
2026-09-29 03:54:32
(1 day ago)
Web attack/malicious scanning detected
Web App Attack
Anonymous
2026-09-28 21:05:05
(2 days ago)
Blocked: Reason='Vulnerability probing โ PHP scan detected (395/60 min)'; Requests=395
Port Scan
๐บ๐ธ
kosada.com
2026-09-28 18:03:57
(2 days ago)
Repeated requests for suspicious nonexistent URLs, for example: /uploads/slide4.php (HTTP/1.1 port 4 ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /uploads/slide4.php (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36")
show less
Web App Attack
๐ฉ๐ช
masterguru
2026-09-27 14:42:18
(3 days ago)
Too much 404 requests in 1 minute. Operator GE matched 10 at IP:block_script. (46020-145)
Hacking
๐ณ๐ฑ
Site.eu
2026-09-27 08:59:09
(3 days ago)
Excessive multi-domain requests
Brute-Force
๐ฌ๐ง
consul.to
2026-09-27 05:17:41
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 19:16:26
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 103.96.149.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 103.96.149.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 15:16:13.006124 2026] [security2:error] [pid 24705:tid 24705] [client 103.96.149.7:58750] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||esneuro.net|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "esneuro.net"] [uri "/okok.cer"] [unique_id "argZ_ZbRcpAJWF-McIhY9QAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-22 06:08:59
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 12:21:04
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 103.96.149.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 103.96.149.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 08:20:54.934511 2026] [security2:error] [pid 30620:tid 30620] [client 103.96.149.7:38222] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||azcrittergetter.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "azcrittergetter.com"] [uri "/okok.cer"] [unique_id "aqvbJj6u9klLeZYPiCB8WAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 03:23:26
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 103.96.149.7 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 103.96.149.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 23:23:17.088490 2026] [security2:error] [pid 2194:tid 2194] [client 103.96.149.7:53078] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.mathewyoung.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.mathewyoung.com"] [uri "/okok.cer"] [unique_id "aqtdJWier_CK363Pi2dMhQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
IRISIO
2026-09-16 22:19:19
(2 weeks ago)
scans/SQL injection/spam posts : 1216 queries
Web App Attack
SQL Injection
๐บ๐ธ
Matthew Ping
2026-09-16 19:00:02
(2 weeks ago)
Excessive connections (DDoS/flood) blocked by CSF CT_LIMIT on dedicated.
DDoS Attack
Brute-Force