๐ฉ๐ช
webanyone
2026-07-28 07:01:00
(2 days ago)
Apache web server attack detected by Fail2Ban in plesk-apache jail
Web App Attack
๐ฉ๐ช
webanyone
2026-07-23 04:30:57
(1 week ago)
Apache web server attack detected by Fail2Ban in plesk-apache jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-21 17:27:11
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 172.71.120.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.120.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 13:27:07.502678 2026] [security2:error] [pid 38214:tid 38214] [client 172.71.120.113:14131] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.pasadenahairextensions.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.pasadenahairextensions.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "al-r6_sQtRDlsDq0wbL0iwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-07-19 15:04:39
(1 week ago)
Aggressive web scan
Web App Attack
Anonymous
2026-07-14 00:44:39
(2 weeks ago)
Aggressive web scan
Web App Attack
Anonymous
2026-07-12 11:49:37
(2 weeks ago)
Aggressive web scan
Web App Attack
Anonymous
2026-07-08 20:59:37
(3 weeks ago)
Aggressive web scan
Web App Attack
Anonymous
2026-07-06 15:09:59
(3 weeks ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 17:34:00
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 172.71.120.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.120.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 13:33:54.882426 2026] [security2:error] [pid 4841:tid 4841] [client 172.71.120.113:9948] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.cassandramarisalon.com|F|2"] [data "[email protected] "] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.cassandramarisalon.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "akfygmDmaVEuAk7JSxBdDwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-01 16:58:08
(4 weeks ago)
(mod_security) mod_security (id:210730) triggered by 172.71.120.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.120.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 01 12:58:02.313514 2026] [security2:error] [pid 16667:tid 16667] [client 172.71.120.113:13811] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.robertanders.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.robertanders.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "akVHGr_IAm0x8eKdDZssMQAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-27 08:59:49
(1 month ago)
Aggressive web scan
Web App Attack
Anonymous
2026-06-25 13:44:36
(1 month ago)
Aggressive web scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-25 02:04:48
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 172.71.120.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 172.71.120.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 24 22:04:43.569287 2026] [security2:error] [pid 16210:tid 16210] [client 172.71.120.113:11653] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "thegreatleapforward.com.herecometheplanes.com"] [uri "/.env.production.local"] [unique_id "ajyMu6V2e6Wolar0yqs1sQAAAAU"], referer: https://www.google.com/search?q=thegreatleapforward.com.herecometheplanes.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 22:41:43
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 172.71.120.113 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 172.71.120.113 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 18:41:35.885402 2026] [security2:error] [pid 21039:tid 21039] [client 172.71.120.113:12834] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.premierveterinarysurgery.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.premierveterinarysurgery.com"] [uri "/autodiscover/autodiscover.json/v1.0/[email protected] "] [unique_id "ajhon72NYUMXFQOW4eRX2wAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
todix
2026-06-21 08:45:48
(1 month ago)
Web App Attack Exploid from 172.71.120.113
Web App Attack