๐บ๐ธ
TPI-Abuse
2026-09-25 04:53:32
(22 minutes ago)
(mod_security) mod_security (id:210730) triggered by 122.10.18.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 122.10.18.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 00:53:26.088290 2026] [security2:error] [pid 5948:tid 5948] [client 122.10.18.7:39246] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||deborahbein.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "deborahbein.com"] [uri "/okok.cer"] [unique_id "arX-Rk2V70xV-GhwsQGjeAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ธ๐ฌ
Cloudkul Cloudkul
2026-09-24 14:00:33
(15 hours ago)
Attempted Brute Force on our application
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 18:34:31
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 122.10.18.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 122.10.18.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 14:34:25.200392 2026] [security2:error] [pid 2846584:tid 2846584] [client 122.10.18.7:34554] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cor-ex.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cor-ex.com"] [uri "/okok.cer"] [unique_id "arQbsbBoqFxfigQMV4H1sQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 17:09:59
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 122.10.18.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 122.10.18.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 13:09:52.752549 2026] [security2:error] [pid 29164:tid 29220] [client 122.10.18.7:36480] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||coloradocritterpics.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "coloradocritterpics.com"] [uri "/okok.cer"] [unique_id "arQH4KlMxdguKqHm4Oco-gAAANM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-22 15:36:35
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 122.10.18.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 122.10.18.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 11:36:30.782562 2026] [security2:error] [pid 18637:tid 18637] [client 122.10.18.7:42482] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||blog.ontrek.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blog.ontrek.com"] [uri "/okok.cer"] [unique_id "arKgfv3i7KHKxJGHiChW4gAAAGU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 12:15:23
(3 days ago)
access denied too many times (more than 12 attempts in 60 seconds)
...
Web App Attack
Brute-Force
Anonymous
2026-09-17 09:54:36
(1 week ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 21:00:55
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 122.10.18.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 122.10.18.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 17:00:48.380804 2026] [security2:error] [pid 22729:tid 22783] [client 122.10.18.7:55612] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||atechtransmission.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "atechtransmission.com"] [uri "/okok.cer"] [unique_id "aqsDgDiB3eUr9PeuuOBiWAAAAVM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 19:43:05
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 122.10.18.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 122.10.18.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 15:42:58.943968 2026] [security2:error] [pid 25301:tid 25301] [client 122.10.18.7:55116] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||astglobalgroup.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "astglobalgroup.com"] [uri "/okok.cer"] [unique_id "aqrxQm1iKwOruzwpvO5Q7gAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-09-16 18:06:13
(1 week ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 15:42:48
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 122.10.18.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 122.10.18.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 11:42:41.227614 2026] [security2:error] [pid 18680:tid 18680] [client 122.10.18.7:54364] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||asbechiro.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "asbechiro.com"] [uri "/okok.cer"] [unique_id "aqq48WoudQ1XAZoeKFMg6wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 12:44:16
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 122.10.18.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 122.10.18.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 08:44:09.167987 2026] [security2:error] [pid 31057:tid 31057] [client 122.10.18.7:51046] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||arrowhead30.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arrowhead30.com"] [uri "/okok.cer"] [unique_id "aqqPGXHVdqRGSCqeU86mngAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-16 12:22:34
(1 week ago)
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: ...
show more
Malicious web request: probing for secrets, traversal or a known exploit path | method: GET | path: /shell.php | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36 | 2026-09-16 12:22 UTC
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 12:37:49
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 122.10.18.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 122.10.18.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 08:37:42.750240 2026] [security2:error] [pid 967:tid 967] [client 122.10.18.7:40534] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||amychop.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "amychop.com"] [uri "/okok.cer"] [unique_id "aqk8FuCpYe-1X4YZ541V1wAAAIg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 10:17:01
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 122.10.18.7 (-): 1 in the last 300 secs; Ports: ...
show more
(mod_security) mod_security (id:210730) triggered by 122.10.18.7 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 06:16:52.551142 2026] [security2:error] [pid 688:tid 688] [client 122.10.18.7:34400] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||americancryonics.org|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "americancryonics.org"] [uri "/okok.cer"] [unique_id "aqkbFERwhDaV2SwfoiRsTgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack