๐บ๐ธ
masterguru
2025-11-24 22:58:07
(9 months ago)
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" ...
show more
COMODO WAF: URL file extension is restricted by policy. Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. (210730-124)
show less
Hacking
๐บ๐ธ
ipblock.com
2025-11-24 20:06:00
(9 months ago)
IPBlock protected site ID [669-fx].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Bouncer
2025-11-22 03:06:29
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 125.208.17.45 (CN/China/-): 5 in the last 60 se ...
show more
(mod_security) mod_security (id:210730) triggered by 125.208.17.45 (CN/China/-): 5 in the last 60 secs
show less
Brute-Force
๐บ๐ธ
TPI-Abuse
2025-11-22 02:56:51
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 125.208.17.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 125.208.17.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 21 21:56:48.050404 2025] [security2:error] [pid 17919:tid 17919] [client 125.208.17.45:64062] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.franklinheatandair.com|F|2"] [data ".franklinheatandair.com.mdb"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.franklinheatandair.com"] [uri "/www.franklinheatandair.com.mdb"] [unique_id "aSEmcEOB3B-zB4-2Dz9NEwAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2025-11-22 01:04:23
(9 months ago)
(bad_user_agent) srv101 Bad User-Agent 2002:7dd0:112d::7dd0:112d (Unknown): 10 in the last 3600 secs ...
show more
(bad_user_agent) srv101 Bad User-Agent 2002:7dd0:112d::7dd0:112d (Unknown): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-21 00:37:47
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 125.208.17.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 125.208.17.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 20 19:37:40.377522 2025] [security2:error] [pid 8302:tid 8302] [client 125.208.17.45:50133] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.theneighborswindow.com|F|2"] [data ".theneighborswindow.com.mdb"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.theneighborswindow.com"] [uri "/www.theneighborswindow.com.mdb"] [unique_id "aR-0VLf6c3QJb6S65VwINwAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ipblock.com
2025-11-19 19:59:00
(9 months ago)
IPBlock protected site ID [669-fx].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-19 17:31:07
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 125.208.17.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 125.208.17.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 19 12:30:59.196644 2025] [security2:error] [pid 20782:tid 20782] [client 125.208.17.45:50430] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ilandman.com|F|2"] [data ".ilandman.com.mdb"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ilandman.com"] [uri "/www.ilandman.com.mdb"] [unique_id "aR3-093gNuzKROetVy5mRQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-19 16:10:30
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 125.208.17.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 125.208.17.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 19 11:10:26.987253 2025] [security2:error] [pid 6818:tid 6818] [client 125.208.17.45:52632] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.johnprimerano.com|F|2"] [data ".johnprimerano.com.mdb"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.johnprimerano.com"] [uri "/www.johnprimerano.com.mdb"] [unique_id "aR3r8nRHhsvGAWDkNZ0GowAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WizardsToolkit
2025-11-19 13:49:30
(9 months ago)
attempted to access /website.tar.gz
Web App Attack
๐บ๐ธ
kosada.com
2025-11-19 12:20:03
(9 months ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-19 05:46:40
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2002:7dd0:112d::7dd0:112d (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 2002:7dd0:112d::7dd0:112d (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Nov 19 00:46:31.814536 2025] [security2:error] [pid 11349:tid 11349] [client 2002:7dd0:112d::7dd0:112d:52382] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.prestigedomainsales.com|F|2"] [data ".prestigedomainsales.com.mdb"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.prestigedomainsales.com"] [uri "/www.prestigedomainsales.com.mdb"] [unique_id "aR1Zt_f9Jija2CliPjiJewAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-19 00:57:53
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 125.208.17.45 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 125.208.17.45 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 18 19:57:47.803515 2025] [security2:error] [pid 3479666:tid 3479666] [client 125.208.17.45:50658] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.informant-systems.com|F|2"] [data ".mdb"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.informant-systems.com"] [uri "/informant-systems.mdb"] [unique_id "aR0WCzHFVQ5kooi_c82-BQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack