|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 175.24.248.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 175.24.248.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 16:28:40.325773 2026] [security2:error] [pid 9949:tid 9949] [client 175.24.248.53:41861] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gamepart.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gamepart.com"] [uri "/home/tancedi1/gamepart.com"] [unique_id "ae_G-PjtLqLCrlcVZwy1pQAAABU"], referer: https://gamepart.com/
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:217291) triggered by 175.24.248.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217291) triggered by 175.24.248.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 24 08:26:20.323521 2026] [security2:error] [pid 975242:tid 975242] [client 175.24.248.53:65149] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(\\\\n|\\\\r)" at ARGS_NAMES:\\r\\n117d\\r\\ntngdaymonth. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "145"] [id "217291"] [rev "2"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)||kountz.org|F|2"] [data "Matched Data: \\x0d found within ARGS_NAMES:\\x5cr\\x5cn117d\\x5cr\\x5cntngdaymonth: \\x0d\\x0a117d\\x0d\\x0atngdaymonth"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "kountz.org"] [uri "/anniversaries.php"] [unique_id "aethbGM0P2Ngob4D5Oxx6gAAAAw"], referer: https://kountz.org/
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:217291) triggered by 175.24.248.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217291) triggered by 175.24.248.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Dec 06 12:32:54.150199 2025] [security2:error] [pid 22572:tid 22572] [client 175.24.248.53:45252] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(\\\\n|\\\\r)" at ARGS_NAMES:\\r\\n1b\\r\\nm. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "145"] [id "217291"] [rev "2"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)||kountz.org|F|2"] [data "Matched Data: \\x0d found within ARGS_NAMES:\\x5cr\\x5cn1b\\x5cr\\x5cnm: \\x0d\\x0a1b\\x0d\\x0am"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "kountz.org"] [uri "/calendar.php"] [unique_id "aTRoxvkGGtfLmMYZJ01TDQAAAAQ"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
botreporter
|
|
botnet ignoring robots.txt
|
Bad Web Bot
|
|
|
๐ฉ๐ช
botreporter
|
|
botnet ignoring robots.txt
|
Bad Web Bot
|
|
|
๐ฉ๐ช
botreporter
|
|
botnet ignoring robots.txt
|
Bad Web Bot
|
|
|
๐ฉ๐ช
botreporter
|
|
botnet ignoring robots.txt
|
Bad Web Bot
|
|
|
๐ฉ๐ช
botreporter
|
|
botnet ignoring robots.txt
|
Bad Web Bot
|
|
|
๐ฉ๐ช
botreporter
|
|
botnet ignoring robots.txt
|
Bad Web Bot
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:217291) triggered by 175.24.248.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:217291) triggered by 175.24.248.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 06 12:10:13.685173 2025] [security2:error] [pid 24717:tid 24717] [client 175.24.248.53:59037] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(\\\\n|\\\\r)" at ARGS_NAMES:\\r\\n1a\\r\\nm. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "145"] [id "217291"] [rev "2"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)||kountz.org|F|2"] [data "Matched Data: \\x0d found within ARGS_NAMES:\\x5cr\\x5cn1a\\x5cr\\x5cnm: \\x0d\\x0a1a\\x0d\\x0am"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "kountz.org"] [uri "/calendar.php"] [unique_id "aOPp5aitHpnsHZ8Y7s14vQAAAAk"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|
|
๐ฉ๐ช
botreporter
|
|
botnet ignoring robots.txt
|
Bad Web Bot
|
|
|
๐บ๐ธ
bigscoots-staff
|
|
Reported via Slack bot
|
Bad Web Bot
|
|
|
๐ฉ๐ช
botreporter
|
|
botnet ignoring robots.txt
|
Bad Web Bot
|
|
|
๐ฉ๐ช
botreporter
|
|
botnet ignoring robots.txt
|
Bad Web Bot
|
|
|
๐บ๐ธ
TPI-Abuse
|
|
(mod_security) mod_security (id:210730) triggered by 175.24.248.53 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 175.24.248.53 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 08 13:31:57.428457 2025] [security2:error] [pid 23047:tid 23047] [client 175.24.248.53:3618] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||digbie.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "digbie.com"] [uri "/[email protected]"] [unique_id "aL8TDSSRlaa8AmP0UHP8pQAAABs"]
show less
|
Brute-Force
Bad Web Bot
Web App Attack
|
|