🇺🇸
TPI-Abuse
2026-09-07 00:29:04
(2 hours ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 20:28:59.165091 2026] [security2:error] [pid 21229:tid 21229] [client 180.153.236.176:6181] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||waypoint-solutions.us|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "waypoint-solutions.us"] [uri "/"] [unique_id "ap4FS5nJ3Z_exc3n-Z3hRgAAAAQ"], referer: https://waypoint-solutions.us/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 15:02:34
(3 days ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 11:02:30.543896 2026] [security2:error] [pid 3086:tid 3086] [client 180.153.236.176:4617] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.alexetjeremy.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.alexetjeremy.com"] [uri "/"] [unique_id "apmMBq8dXDEj67h0zmV2UQAAAAU"], referer: https://www.alexetjeremy.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
CoreTech srl
2026-09-01 12:08:57
(5 days ago)
cloudlinux2 fail2ban: 2026-09-01 14:04:12,374 fail2ban.filter [1605]: INFO [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-01 14:04:12,374 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 112.208.76.237 - 2026-09-01 14:04:12cloudlinux2 fail2ban: 2026-09-01 14:04:12,374 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 112.208.76.237 - 2026-09-01 14:04:12cloudlinux2 fail2ban: 2026-09-01 14:04:28,409 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 180.153.236.176 - 2026-09-01 14:04:28cloudlinux2 fail2ban: 2026-09-01 14:04:28,409 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 180.153.236.176 - 2026-09-01 14:04:28cloudlinux2 fail2ban: 2026-09-01 14:04:32,337 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 180.153.236.70 - 2026-09-01 14:04:32cloudlinux2 fail2ban: 2026-09-01 14:04:32,337 fail2ban.filter [1605]: INFO [plesk-modsecurity] Found 180.153.236.70 - 2026-09-01 14:04:32cloudlinux2 fail2ban: 2026-09-01 14:04:44,882 fail2ban.actions [1605]: NOTICE [plesk-modsecurity] Ban 112.208.76.237cloudlinux
show less
Brute-Force
🇺🇸
TPI-Abuse
2026-09-01 05:17:28
(5 days ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 01:17:21.776334 2026] [security2:error] [pid 20203:tid 20203] [client 180.153.236.176:25773] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||schonmusic.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "schonmusic.com"] [uri "/403.shtml"] [unique_id "apZf4Qvh-wV70x1JufAuDQAAACE"], referer: https://schonmusic.com/403.shtml
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-01 03:32:29
(5 days ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 23:32:23.329807 2026] [security2:error] [pid 26036:tid 26036] [client 180.153.236.176:9421] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||thephysicsroom.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "thephysicsroom.com"] [uri "/robots.txt"] [unique_id "apZHR4uFk5YUVAESFvZyFgAAACs"], referer: https://thephysicsroom.com/robots.txt
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-01 02:13:09
(6 days ago)
[Tue Sep 01 12:13:08.440046 2026] [security2:error] [pid 188316] [client 180.153.236.176:33291] [cli ...
show more
[Tue Sep 01 12:13:08.440046 2026] [security2:error] [pid 188316] [client 180.153.236.176:33291] [client 180.153.236.176] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "valueaddedpromotions.com.au"] [uri "/valueaddedpromotionscomau"] [unique_id "apY0tEUFz6EagSLdVgr75AAAAAE"], referer: https://valueaddedpromotions.com.au/valueaddedpromotionscomau
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 20:44:58
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 16:44:53.976313 2026] [security2:error] [pid 8391:tid 8391] [client 180.153.236.176:28729] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||acatucson.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "acatucson.com"] [uri "/"] [unique_id "apSWRUWxt3kNS7d7S5wrTQAAAAY"], referer: https://acatucson.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 19:10:57
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 15:10:53.614968 2026] [security2:error] [pid 2666252:tid 2666311] [client 180.153.236.176:58195] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||exede-sales.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "exede-sales.com"] [uri "/"] [unique_id "apSAPf3WbFk9eu4WwEUOtwAAAIk"], referer: https://exede-sales.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 14:53:05
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 10:52:57.086225 2026] [security2:error] [pid 1227:tid 1227] [client 180.153.236.176:46897] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.borzois.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.borzois.com"] [uri "/"] [unique_id "apRDycw5xyof1XxnjBj1TgAAAA4"], referer: http://www.borzois.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 13:15:06
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 09:15:00.306649 2026] [security2:error] [pid 5144:tid 5144] [client 180.153.236.176:5335] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.mmaccaux.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.mmaccaux.com"] [uri "/"] [unique_id "apQs1CEPIrhl6gpgZTX1ugAAABU"], referer: http://www.mmaccaux.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-30 08:56:46
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 04:56:39.160638 2026] [security2:error] [pid 15535:tid 15535] [client 180.153.236.176:26899] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.med-engineering.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.med-engineering.com"] [uri "/"] [unique_id "apPwR_DhEoHcKqVy7d5p0gAAAAA"], referer: http://www.med-engineering.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 05:41:57
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 01:41:48.293432 2026] [security2:error] [pid 9656:tid 9656] [client 180.153.236.176:64693] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||freestonepress.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "freestonepress.com"] [uri "/"] [unique_id "apEfnFShnioFk0NO8WJIcAAAAA4"], referer: http://freestonepress.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-27 06:32:13
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 02:32:05.538012 2026] [security2:error] [pid 8367:tid 8367] [client 180.153.236.176:24937] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||highfield.us|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "highfield.us"] [uri "/"] [unique_id "ao_Z5cue8hXM-yZEdhJD3QAAAAU"], referer: http://highfield.us/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-24 03:33:01
(1 week ago)
apache vulnerability scan
Web App Attack
🇺🇸
TPI-Abuse
2026-08-23 20:09:07
(2 weeks ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.176 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 16:09:00.604684 2026] [security2:error] [pid 16505:tid 16505] [client 180.153.236.176:16275] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||explorediablo.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "explorediablo.com"] [uri "/"] [unique_id "aotTXD5hYyBaiOxXsSBdcQAAAA4"], referer: https://explorediablo.com/
show less
Brute-Force
Bad Web Bot
Web App Attack