๐บ๐ธ
TPI-Abuse
2026-08-28 22:47:18
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 179.61.245.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 179.61.245.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 18:46:48.442741 2026] [security2:error] [pid 26179:tid 26179] [client 179.61.245.37:37587] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nbcnewsradio.com|F|2"] [data ".key"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nbcnewsradio.com"] [uri "/www.key"] [unique_id "apIP2ObVlTsy88gIPjgOvgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
bigorre.org
2026-08-06 15:19:30
(1 month ago)
Forbidden access for mozilla/5.0 (compatible; googlebot/2.1; +http://www.google.com/bot.html)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-01-27 02:37:13
(8 months ago)
(mod_security) mod_security (id:221260) triggered by 179.61.245.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:221260) triggered by 179.61.245.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jan 26 21:35:19.584710 2026] [security2:error] [pid 1535:tid 1982] [client 179.61.245.37:52671] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||cpcalendars.kettlehill.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.kettlehill.com"] [uri "/cgi-bin/status/status.cgi"] [unique_id "aXgkZ7ZfoZ-BogEqpvEZCQAAAQg"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-17 04:37:05
(8 months ago)
(mod_security) mod_security (id:221260) triggered by 179.61.245.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:221260) triggered by 179.61.245.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jan 16 23:36:53.434106 2026] [security2:error] [pid 22068:tid 22068] [client 179.61.245.37:36177] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||cpcalendars.nbcnewsradio.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/"] [unique_id "aWsR5YBibgheA2Fg1lO-XwAAABM"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-10-29 17:06:27
(10 months ago)
(mod_security) mod_security (id:210730) triggered by 179.61.245.37 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 179.61.245.37 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 29 13:06:22.011815 2025] [security2:error] [pid 21482:tid 21482] [client 179.61.245.37:48115] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.davispickering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.davispickering.com"] [uri "/file=http:/example.com"] [unique_id "aQJJjhIXtzYKX2iAMkg4DAAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
slartybartfast69420blazit
2025-08-14 20:27:39
(1 year ago)
Fail2ban picked up 179.61.245.37 attacking nginx
Web App Attack
๐ฟ๐ฆ
slartybartfast69420blazit
2025-08-13 20:23:24
(1 year ago)
Fail2ban picked up 179.61.245.37 attacking nginx
Web App Attack
๐ฟ๐ฆ
slartybartfast69420blazit
2025-08-12 20:21:02
(1 year ago)
Fail2ban picked up 179.61.245.37 attacking nginx
Web App Attack
๐ฟ๐ฆ
slartybartfast69420blazit
2025-08-11 20:17:25
(1 year ago)
Fail2ban picked up 179.61.245.37 attacking nginx
Web App Attack
๐ฟ๐ฆ
slartybartfast69420blazit
2025-08-09 20:33:30
(1 year ago)
Fail2ban picked up 179.61.245.37 attacking nginx
Web App Attack
๐ฟ๐ฆ
slartybartfast69420blazit
2025-08-08 20:30:30
(1 year ago)
Fail2ban picked up 179.61.245.37 attacking nginx
Web App Attack
๐ฟ๐ฆ
slartybartfast69420blazit
2025-08-07 20:27:25
(1 year ago)
Fail2ban picked up 179.61.245.37 attacking nginx
Web App Attack
๐ฟ๐ฆ
slartybartfast69420blazit
2025-08-06 20:24:35
(1 year ago)
Fail2ban picked up 179.61.245.37 attacking nginx
Web App Attack
๐ฟ๐ฆ
slartybartfast69420blazit
2025-08-05 20:21:19
(1 year ago)
Fail2ban picked up 179.61.245.37 attacking nginx
Web App Attack
๐ฟ๐ฆ
slartybartfast69420blazit
2025-08-04 20:17:55
(1 year ago)
Fail2ban picked up 179.61.245.37 attacking nginx
Web App Attack