Anonymous
2026-08-25 19:35:00
(21 hours ago)
Excessive crawling/scraping. Vulnerable file probing.
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-24 09:33:43
(2 days ago)
160.20.109.30 - - [24/Aug/2026:11:33:38 +0200] "GET /borngatesventureslimited.zip HTTP/1.1" 404 124 ...
show more
160.20.109.30 - - [24/Aug/2026:11:33:38 +0200] "GET /borngatesventureslimited.zip HTTP/1.1" 404 124 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/28.0"
160.20.109.30 - - [24/Aug/2026:11:33:38 +0200] "GET /borngatesventureslimited.zip HTTP/1.1" 404 124 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/28.0"
160.20.109.30 - - [24/Aug/2026:11:33:39 +0200] "GET /borngatesventureslimited.zip HTTP/1.1" 404 124 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/28.0"
160.20.109.30 - - [24/Aug/2026:11:33:39 +0200] "GET /borngatesventureslimited.zip HTTP/1.1" 404 124 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/28.0"
160.20.109.30 - - [24/Aug/2026:11:33:39 +0200] "GET /borngatesventureslimited.zip HTTP/1.1" 404 124 "-" "Mozilla/5.0 (X11; Ubuntu; Linux i686; rv:28.0) Gecko/20100101 Firefox/28.0"
160.20.109.30 - - [24/Aug/2026:11:33:39 +0200] "GET /borngatesventureslimited.tar.gz HTTP/1.1"
...
show less
Bad Web Bot
Web App Attack
π¬π§
thetomtaylor.co.uk
2026-08-19 04:08:01
(1 week ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice02,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-19 02:04:40
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 160.20.109.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 160.20.109.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 22:04:32.608004 2026] [security2:error] [pid 25819:tid 25819] [client 160.20.109.30:60327] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||donshotrodshop.net|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "donshotrodshop.net"] [uri "/logs/combined.log"] [unique_id "aoUPMHD_nDPXhTzqiYWiiwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-18 23:15:28
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 160.20.109.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 160.20.109.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 19:15:23.233784 2026] [security2:error] [pid 16518:tid 16518] [client 160.20.109.30:64080] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||diveshop-pr.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "diveshop-pr.com"] [uri "/log/access.log"] [unique_id "aoTniwSubNj0war16f4qfQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
consul.to
2026-08-18 18:48:45
(1 week ago)
Web attack/malicious scanning detected
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-18 18:10:13
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 160.20.109.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 160.20.109.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 14:10:09.557903 2026] [security2:error] [pid 20168:tid 20176] [client 160.20.109.30:59813] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||designshopadmin.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "designshopadmin.com"] [uri "/access.log"] [unique_id "aoSgARFpzcGqW2XKtEk5IQAAAIQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΈπͺ
vaia.cloud
2026-08-18 17:40:02
(1 week ago)
crowdsecurity/http-probing
Brute-Force
Web App Attack
π§πͺ
taivas.nl
2026-08-18 16:02:11
(1 week ago)
Site scraper
Web App Attack
π³π±
SysAdmin Dylan
2026-08-18 12:58:38
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 160.20.109.30 (TR/Turkey/-): 10 in the last 360 ...
show more
(mod_security) mod_security (id:210730) triggered by 160.20.109.30 (TR/Turkey/-): 10 in the last 3600 secs
show less
Brute-Force
πΊπΈ
mnsf
2026-08-18 09:05:13
(1 week ago)
Too many Status 40X (12)
Brute-Force
Web App Attack
π©πͺ
paissangroup
2026-08-18 02:57:41
(1 week ago)
Multiple WAF Violations
Web App Attack
Anonymous
2026-08-18 01:33:05
(1 week ago)
Blocked by ModSec and CSF
Port Scan
πΊπΈ
TPI-Abuse
2026-08-17 23:40:09
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 160.20.109.30 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 160.20.109.30 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 19:40:00.087765 2026] [security2:error] [pid 1936:tid 1936] [client 160.20.109.30:63570] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||comobarbershop.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "comobarbershop.com"] [uri "/logs/combined.log"] [unique_id "aoOb0GIih1jVrjOsGoFsEgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-17 17:34:22
(1 week ago)
160.20.109.30 - - [17/Aug/2026:19:34:21 +0200] "GET /log/access.log HTTP/1.1" 403 124 "-" "Mozilla/5 ...
show more
160.20.109.30 - - [17/Aug/2026:19:34:21 +0200] "GET /log/access.log HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
160.20.109.30 - - [17/Aug/2026:19:34:21 +0200] "GET /access.log HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
160.20.109.30 - - [17/Aug/2026:19:34:21 +0200] "GET /logs/combined.log HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
160.20.109.30 - - [17/Aug/2026:19:34:21 +0200] "GET /logs/access.log HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
160.20.109.30 - - [17/Aug/2026:19:34:21 +0200] "GET /storage/logs/laravel.log HTTP/1.1" 403 124 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
160.20.109.30 - - [17/Aug/2026:19:34:21 +0200] "GET /storage/logs/laravel-2026-08-16.log HTTP/1.1" 403 124 "-" "Mozilla/5.0 (
...
show less
Bad Web Bot
Web App Attack