πͺπΈ
el-brujo
2026-09-25 18:57:36
(20 hours ago)
25/Sep/2026:20:57:35.881845 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
25/Sep/2026:20:57:35.881845 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 121.24.36.35] ModSecurity: Warning. Match of "rx ^urlgrabber/[0-9\\\\\\\\.]+ yum/[0-9\\\\\\\\.]+$" against "REQUEST_HEADERS:User-Agent" required. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "53"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: user-agent: found within REQUEST_HEADERS:User-Agent: user-agent:mozilla/5.0 (windows nt 6.1; wow64) applewebkit/537.36 (khtml, like gecko) chrome/50.0.2661.102 safari/537.36"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [hostname "hwagm.elhacker.net"] [uri "/el-nuevo-wpa3-es-oficial-un-nuevo-protocolo-para-proteger-tu-wifi/"] [unique_id "arbEHxp36DjMROOvj21
...
show less
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-29 19:12:09
(3 months ago)
(mod_security) mod_security (id:210831) triggered by 121.24.36.35 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210831) triggered by 121.24.36.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 15:11:53.811057 2026] [security2:error] [pid 31085:tid 31085] [client 121.24.36.35:27666] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||robertanders.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "robertanders.com"] [uri "/index.html"] [unique_id "ahnk-Tmtxw8lggnHZRYlcwAAAAI"], referer: http://robertanders.com/index.html
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-24 23:56:23
(4 months ago)
(mod_security) mod_security (id:210831) triggered by 121.24.36.35 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210831) triggered by 121.24.36.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 24 19:56:09.740287 2026] [security2:error] [pid 3793:tid 3793] [client 121.24.36.35:17682] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.purebinary.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.purebinary.com"] [uri "/"] [unique_id "ahOQGbY6CGb-vk0dZYspuwAAAAU"], referer: http://www.purebinary.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-04 22:17:33
(5 months ago)
(mod_security) mod_security (id:210831) triggered by 121.24.36.35 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210831) triggered by 121.24.36.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 18:17:19.727957 2026] [security2:error] [pid 2251:tid 2251] [client 121.24.36.35:31813] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.steamboatrowena.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.steamboatrowena.com"] [uri "/"] [unique_id "adGN78SnjGxNLapBM3LjwwAAAAs"], referer: http://www.steamboatrowena.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-03-22 22:57:32
(6 months ago)
(mod_security) mod_security (id:210831) triggered by 121.24.36.35 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210831) triggered by 121.24.36.35 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Mar 22 18:57:17.094863 2026] [security2:error] [pid 2571158:tid 2571158] [client 121.24.36.35:32092] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.crixbot.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.crixbot.com"] [uri "/"] [unique_id "acBzzRWGO0Vs_q1SySf5CwAAAAw"], referer: http://www.crixbot.com/
show less
Brute-Force
Bad Web Bot
Web App Attack