๐บ๐ธ
TPI-Abuse
2026-09-15 07:27:45
(1 day ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.207 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 03:27:39.691487 2026] [security2:error] [pid 11863:tid 11863] [client 180.153.236.207:2849] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.azcrittergetter.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.azcrittergetter.com"] [uri "/"] [unique_id "aqjza5ONT3qeZKhz3XncAAAAAAM"], referer: https://www.azcrittergetter.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 06:21:39
(1 day ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.207 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 02:21:32.045686 2026] [security2:error] [pid 2554:tid 2554] [client 180.153.236.207:1717] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||beautyradio.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "beautyradio.com"] [uri "/"] [unique_id "aqjj7IkMbyhmdvlN-bo1XAAAABw"], referer: http://beautyradio.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 05:04:47
(1 day ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.207 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 01:04:43.001330 2026] [security2:error] [pid 10971:tid 10971] [client 180.153.236.207:3357] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||myersbarnescpa.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "myersbarnescpa.com"] [uri "/"] [unique_id "aqjR6g2OdLLNyvGycKZwLQAAABQ"], referer: https://myersbarnescpa.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
CoreTech srl
2026-09-15 04:43:57
(1 day ago)
cloudlinux2 fail2ban: 2026-09-15 06:38:54,093 fail2ban.actions [1908]: NOTICE [plesk-modsecu ...
show more
cloudlinux2 fail2ban: 2026-09-15 06:38:54,093 fail2ban.actions [1908]: NOTICE [plesk-modsecurity] Unban 35.201.198.85cloudlinux2 fail2ban: 2026-09-15 06:39:06,830 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 168.231.102.168 - 2026-09-15 06:39:06cloudlinux2 fail2ban: 2026-09-15 06:40:37,128 fail2ban.filter [1908]: INFO [plesk-wordpress] Found 45.130.83.232 - 2026-09-15 06:40:36cloudlinux2 fail2ban: 2026-09-15 06:40:36,411 fail2ban.filter [1908]: INFO [plesk-wordpress] Found 45.130.83.210 - 2026-09-15 06:40:36cloudlinux2 fail2ban: 2026-09-15 06:42:06,930 fail2ban.filter [1908]: INFO [plesk-wordpress] Found 5.140.215.170 - 2026-09-15 06:42:05cloudlinux2 fail2ban: 2026-09-15 06:42:13,546 fail2ban.actions [1908]: NOTICE [plesk-modsecurity] Unban 34.146.236.70cloudlinux2 fail2ban: 2026-09-15 06:42:12,835 fail2ban.filter [1908]: INFO [plesk-modsecurity] Found 180.153.236.167 - 2026-09-15 06:42:12cloudlinux2 fail2ban: 2026-09-15 06:42:34
show less
Web App Attack
๐ฉ๐ช
LRob
2026-09-15 04:24:39
(1 day ago)
Asking over plain http and never following the redirect served โ a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served โ a crawler that reads nothing it asks for | method: GET | path: / | ua: User-Agent:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36 Edg/1 | 2026-09-15 04:24 UTC
show less
Bad Web Bot
๐ช๐ธ
gnom4ik
2026-09-07 09:23:48
(1 week ago)
ban-reviewer auto report; ip=180.153.236.207; scenario=http:scan; verdict=valid_ban; confidence=0.92 ...
show more
ban-reviewer auto report; ip=180.153.236.207; scenario=http:scan; verdict=valid_ban; confidence=0.92; categories=15; active_decisions=3; lookback_decisions=3; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=ip_decision_count_high; ip_active_decision_count_high
show less
Hacking
๐ฆ๐บ
paulshipley.com.au
2026-09-06 21:46:12
(1 week ago)
[Mon Sep 07 07:46:11.445054 2026] [security2:error] [pid 30016] [client 180.153.236.207:47321] [clie ...
show more
[Mon Sep 07 07:46:11.445054 2026] [security2:error] [pid 30016] [client 180.153.236.207:47321] [client 180.153.236.207] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "angleseaarthouse.com.au"] [uri "/"] [unique_id "ap3fI6AQ6L9pTR6dsFrxUAAAABE"], referer: https://angleseaarthouse.com.au/
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 20:40:56
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.207 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:40:50.997662 2026] [security2:error] [pid 13439:tid 13439] [client 180.153.236.207:2571] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||areaware-archive.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "areaware-archive.com"] [uri "/"] [unique_id "ap3P0nSujjgY_XGZscXCZAAAAAM"], referer: https://areaware-archive.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 18:44:49
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.207 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 14:44:43.177837 2026] [security2:error] [pid 18542:tid 18542] [client 180.153.236.207:56009] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||arthuryeung.net|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "arthuryeung.net"] [uri "/"] [unique_id "ap20mxqs4K2z7VdJuiXX8AAAAAY"], referer: https://arthuryeung.net/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-06 09:58:35
(1 week ago)
[SunSep0611:58:32.8107052026][security2:error][pid2753871:tid2753993][client180.153.236.207:0]ModSec ...
show more
[SunSep0611:58:32.8107052026][security2:error][pid2753871:tid2753993][client180.153.236.207:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Matchof\"rx\(http://bsalsa\\\\\\\\.com\|\^site24x7\)\"against\"REQUEST_HEADERS:user-agent\"required.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"282\"][id\"330094\"][rev\"5\"][msg\"Atomicorp.comWAFRules:CompromisedUser-AgentAgentAttackblocked\"][severity\"CRITICAL\"][hostname\"feldenkraisticino.ch\"][uri\"/\"][unique_id\"ap05SIiOyKoWThpPvVWF-AAAAEo\"]\,referer:https://feldenkraisticino.ch/
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 06:03:07
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.207 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 02:03:01.106940 2026] [security2:error] [pid 31701:tid 31701] [client 180.153.236.207:27221] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.coolwebsites.org|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.coolwebsites.org"] [uri "/"] [unique_id "ap0CFfkQL0g1oR67Pm-OtgAAABE"], referer: https://www.coolwebsites.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 13:39:43
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.207 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 09:39:37.906540 2026] [security2:error] [pid 5793:tid 5793] [client 180.153.236.207:2771] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.handyrehab.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.handyrehab.com"] [uri "/"] [unique_id "apl4mXLjlNpDCd3dyNcLaAAAAAc"], referer: https://www.handyrehab.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 13:15:26
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.207 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 09:15:19.886881 2026] [security2:error] [pid 13225:tid 13225] [client 180.153.236.207:7369] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.comsew.com.au|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.comsew.com.au"] [uri "/index.html"] [unique_id "aply519f1gxTdWB9K0oH5QAAAAk"], referer: https://www.comsew.com.au/index.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 10:12:27
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.207 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 06:12:21.414258 2026] [security2:error] [pid 8322:tid 8404] [client 180.153.236.207:42079] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.heworeblack.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.heworeblack.com"] [uri "/"] [unique_id "aplIBRmQAm_UMpJgGhUALQAAAUI"], referer: http://www.heworeblack.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 07:29:39
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.207 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.207 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 03:29:35.177275 2026] [security2:error] [pid 16826:tid 16826] [client 180.153.236.207:28081] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.gdpeters.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.gdpeters.com"] [uri "/"] [unique_id "apkh38iePMck7J1AArEBmgAAAA8"], referer: http://www.gdpeters.com/
show less
Brute-Force
Bad Web Bot
Web App Attack