|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 175.24.248.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 175.24.248.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 16:38:50.859224 2026] [security2:error] [pid 22362:tid 22362] [client 175.24.248.212:8552] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gamepart.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gamepart.com"] [uri "/home/tancedi1/gamepart.com"] [unique_id "ae_JWlKL6ysmNOHjXJ4vjAAAAAc"], referer: https://gamepart.com/
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:217291) triggered by 175.24.248.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:217291) triggered by 175.24.248.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 21:44:40.105352 2026] [security2:error] [pid 3515136:tid 3515136] [client 175.24.248.212:16050] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(\\\\n|\\\\r)" at ARGS_NAMES:tngneedres\\r\\n1f40\\r\\nults. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "145"] [id "217291"] [rev "2"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)||kountz.org|F|2"] [data "Matched Data: \\x0d found within ARGS_NAMES:tngneedres\\x5cr\\x5cn1f40\\x5cr\\x5cnults: tngneedres\\x0d\\x0a1f40\\x0d\\x0aults"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "kountz.org"] [uri "/anniversaries.php"] [unique_id "ael5iKRS0zeYrxlQBdXUGwAAAAc"], referer: https://kountz.org/
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:217291) triggered by 175.24.248.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:217291) triggered by 175.24.248.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 07 22:11:51.163672 2025] [security2:error] [pid 9451:tid 9451] [client 175.24.248.212:41338] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(\\\\n|\\\\r)" at ARGS_NAMES:\\r\\n1f40\\r\\namp;tngmonth. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "145"] [id "217291"] [rev "2"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)||kountz.org|F|2"] [data "Matched Data: \\x0d found within ARGS_NAMES:\\x5cr\\x5cn1f40\\x5cr\\x5cnamp;tngmonth: \\x0d\\x0a1f40\\x0d\\x0aamp;tngmonth"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "kountz.org"] [uri "/anniversaries.php"] [unique_id "aTZB90X4Ds9Hm2_E6gV-fAAAAAI"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
botreporter
|
|
botnet ignoring robots.txt
|
Bad Web Bot
|
|
|
๐ฉ๐ช
botreporter
|
|
botnet ignoring robots.txt
|
Bad Web Bot
|
|
|
๐ฉ๐ช
botreporter
|
|
botnet ignoring robots.txt
|
Bad Web Bot
|
|
|
๐ฉ๐ช
botreporter
|
|
botnet ignoring robots.txt
|
Bad Web Bot
|
|
|
๐ฉ๐ช
botreporter
|
|
botnet ignoring robots.txt
|
Bad Web Bot
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:217291) triggered by 175.24.248.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:217291) triggered by 175.24.248.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 06 08:02:00.944625 2025] [security2:error] [pid 4175:tid 4175] [client 175.24.248.212:64411] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(\\\\n|\\\\r)" at ARGS_NAMES:\\r\\n3\\r\\nm. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "145"] [id "217291"] [rev "2"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)||kountz.org|F|2"] [data "Matched Data: \\x0d found within ARGS_NAMES:\\x5cr\\x5cn3\\x5cr\\x5cnm: \\x0d\\x0a3\\x0d\\x0am"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "kountz.org"] [uri "/calendar.php"] [unique_id "aOOvuCfsgHpIX_QG121NVQAAABk"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
botreporter
|
|
botnet ignoring robots.txt
|
Bad Web Bot
|
|
|
๐บ๐ธ
bigscoots-staff
|
|
Reported via Slack bot
|
Bad Web Bot
|
|
|
๐ฉ๐ช
botreporter
|
|
botnet ignoring robots.txt
|
Bad Web Bot
|
|
|
๐ฉ๐ช
botreporter
|
|
botnet ignoring robots.txt
|
Bad Web Bot
|
|
|
๐ฉ๐ช
botreporter
|
|
botnet ignoring robots.txt
|
Bad Web Bot
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 175.24.248.212 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 175.24.248.212 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 25 15:14:44.646019 2025] [security2:error] [pid 6885:tid 6885] [client 175.24.248.212:8308] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||glassclublake.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "glassclublake.com"] [uri "/[email protected]"] [unique_id "aKy2JCge5FsU2VkFbnqcQAAAABA"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|