🇺🇸
TPI-Abuse
2026-09-15 07:21:26
(13 minutes ago)
(mod_security) mod_security (id:210730) triggered by 129.212.220.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 129.212.220.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 03:21:22.476673 2026] [security2:error] [pid 21705:tid 21705] [client 129.212.220.28:58060] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hydrometal-js.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hydrometal-js.com"] [uri "/wp-content/debug.log"] [unique_id "aqjx8rACgYon3iLqfJnGPwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
stinpriza
2026-09-15 05:26:36
(2 hours ago)
Web App Attack
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 04:42:57
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 129.212.220.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 129.212.220.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 00:42:50.540908 2026] [security2:error] [pid 27057:tid 27057] [client 129.212.220.28:50766] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||chickiesbeef.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "chickiesbeef.com"] [uri "/wp-content/debug.log"] [unique_id "aqjMyr1GfsgNV5rH2Z9GHwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇲🇽
octageeks.com
2026-09-15 04:08:53
(3 hours ago)
Wordpress malicious attack:[octawpauthor]
Web App Attack
🇮🇹
CoreTech srl
2026-09-15 02:58:57
(4 hours ago)
cloudlinux2 fail2ban: 2026-09-15 04:54:34,241 fail2ban.filter [1908]: INFO [plesk-wordpre ...
show more
cloudlinux2 fail2ban: 2026-09-15 04:54:34,241 fail2ban.filter [1908]: INFO [plesk-wordpress] Found 193.36.225.66 - 2026-09-15 04:54:33cloudlinux2 fail2ban: 2026-09-15 04:55:15,573 fail2ban.filter [1908]: INFO [plesk-wordpress] Found 45.130.83.217 - 2026-09-15 04:55:14cloudlinux2 fail2ban: 2026-09-15 04:55:19,699 fail2ban.filter [1908]: INFO [plesk-wordpress] Found 45.130.83.217 - 2026-09-15 04:55:19cloudlinux2 fail2ban: 2026-09-15 04:55:19,768 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 129.212.220.28 - 2026-09-15 04:55:19cloudlinux2 fail2ban: 2026-09-15 04:58:12,414 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 217.181.71.101 - 2026-09-15 04:58:12cloudlinux2 fail2ban: 2026-09-15 04:58:14,531 fail2ban.filter [1908]: INFO [plesk-wordpress] Found 195.63.8.148 - 2026-09-15 04:58:14cloudlinux2 fail2ban: 2026-09-15 04:58:15,971 fail2ban.filter [1908]: INFO [plesk-wordpress] Found 217.181.74.140 - 2026-09-15 04:58:15clo
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 23:27:05
(8 hours ago)
(mod_security) mod_security (id:210730) triggered by 129.212.220.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 129.212.220.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 19:27:00.533345 2026] [security2:error] [pid 28465:tid 28465] [client 129.212.220.28:51024] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||aroilcontrolsystem.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "aroilcontrolsystem.com"] [uri "/wp-content/debug.log"] [unique_id "aqiCxBZ751K1WqLmCJo9ewAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
SCHAPPY
2026-09-14 21:45:05
(9 hours ago)
Brute-force attack to identify web exploits
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 20:47:07
(10 hours ago)
(mod_security) mod_security (id:210730) triggered by 129.212.220.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 129.212.220.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 16:47:03.003747 2026] [security2:error] [pid 1389:tid 1389] [client 129.212.220.28:40072] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hotelkona.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hotelkona.com"] [uri "/wp-content/debug.log"] [unique_id "aqhdR7-6SmTzrOyB3RZpmQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 15:57:46
(15 hours ago)
(mod_security) mod_security (id:210730) triggered by 129.212.220.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 129.212.220.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 11:57:42.187645 2026] [security2:error] [pid 10445:tid 10445] [client 129.212.220.28:58610] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||citrineartstudio.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "citrineartstudio.com"] [uri "/wp-content/debug.log"] [unique_id "aqgZdpEqUDQfsUm0nt-lMwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 15:33:36
(16 hours ago)
(mod_security) mod_security (id:210730) triggered by 129.212.220.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 129.212.220.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 11:33:32.878136 2026] [security2:error] [pid 2932959:tid 2932959] [client 129.212.220.28:56830] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||hotelausland.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "hotelausland.com"] [uri "/wp-content/debug.log"] [unique_id "aqgTzIhiz8nVK3CrheooTAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 10:48:16
(20 hours ago)
(mod_security) mod_security (id:210730) triggered by 129.212.220.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 129.212.220.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 06:48:08.497455 2026] [security2:error] [pid 9969:tid 9969] [client 129.212.220.28:60842] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||weddingmusicguitar.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "weddingmusicguitar.com"] [uri "/wp-content/debug.log"] [unique_id "aqfQ6Bi23njQT4H19C8lZQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-14 09:13:21
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 129.212.220.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 129.212.220.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 05:13:15.315476 2026] [security2:error] [pid 2192:tid 2192] [client 129.212.220.28:34682] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rogerheath.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rogerheath.com"] [uri "/wp-content/debug.log"] [unique_id "aqe6qwuE_EOSafai4Wlx1AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
BlueWire Hosting
2026-09-14 07:47:58
(23 hours ago)
Bad bot ignoring robot.txt
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-14 05:19:57
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 129.212.220.28 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 129.212.220.28 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 01:19:50.370304 2026] [security2:error] [pid 26553:tid 26553] [client 129.212.220.28:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rodrigoaldecoa.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rodrigoaldecoa.com"] [uri "/wp-content/debug.log"] [unique_id "aqeD9jnObWYRaxvRXwOPhQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇪🇸
scaballe
2026-09-14 05:15:06
(1 day ago)
Web App Attack