π©πͺ
LRob
2026-09-17 06:37:16
(21 hours ago)
Abusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: User-Agen ...
show more
Abusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: User-Agent:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36 Edg/1 | path: / | 2026-09-17 06:37 UTC
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-15 05:08:48
(2 days ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 01:08:39.845802 2026] [security2:error] [pid 2356:tid 2356] [client 180.153.236.214:50965] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||anniversarynapkins.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "anniversarynapkins.com"] [uri "/"] [unique_id "aqjS19P2fWn98TBPGpeH0QAAAA4"], referer: https://anniversarynapkins.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 04:11:41
(3 days ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 00:11:34.908021 2026] [security2:error] [pid 473:tid 473] [client 180.153.236.214:58449] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.tribwatch.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.tribwatch.com"] [uri "/"] [unique_id "aqjFdkWNZWewz-fYCOmL7wAAAAI"], referer: https://www.tribwatch.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 03:40:33
(3 days ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 23:40:27.349348 2026] [security2:error] [pid 27521:tid 27521] [client 180.153.236.214:24419] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||prestigedomainsales.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "prestigedomainsales.com"] [uri "/"] [unique_id "aqi-K301JhKCPERpflnYCQAAAAQ"], referer: https://prestigedomainsales.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π
4server
2026-09-15 02:59:51
(3 days ago)
[TueSep1504:59:45.0684572026][security2:error][pid3293870:tid3293895][client180.153.236.214:0]ModSec ...
show more
[TueSep1504:59:45.0684572026][security2:error][pid3293870:tid3293895][client180.153.236.214:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Matchof\"rx\(http://bsalsa\\\\\\\\.com\|\^site24x7\)\"against\"REQUEST_HEADERS:user-agent\"required.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"282\"][id\"330094\"][rev\"5\"][msg\"Atomicorp.comWAFRules:CompromisedUser-AgentAgentAttackblocked\"][severity\"CRITICAL\"][hostname\"www.aid-web.ch\"][uri\"/403.shtml\"][unique_id\"aqi0oWHyR0aTDikV5BCm4QAAAIs\"]\,referer:https://www.aid-web.ch/403.shtml
show less
Hacking
Web App Attack
πͺπΈ
gnom4ik
2026-09-07 09:16:21
(1 week ago)
ban-reviewer auto report; ip=180.153.236.214; scenario=http:scan; verdict=valid_ban; confidence=0.92 ...
show more
ban-reviewer auto report; ip=180.153.236.214; scenario=http:scan; verdict=valid_ban; confidence=0.92; categories=15; active_decisions=3; lookback_decisions=3; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=ip_decision_count_high; ip_active_decision_count_high
show less
Hacking
πΊπΈ
TPI-Abuse
2026-09-06 22:33:39
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 18:33:35.204119 2026] [security2:error] [pid 8780:tid 8780] [client 180.153.236.214:36093] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||financesf.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "financesf.com"] [uri "/"] [unique_id "ap3qP5j5ORNHuc3UDC8O1AAAABk"], referer: https://financesf.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
Bay13
2026-09-06 14:15:09
(1 week ago)
CrowdSec:custom/modsecurity
Web App Attack
π¨π³
SA19999
2026-09-05 12:10:25
(1 week ago)
Auto-report: ps:modsec:913100 | sources=["ps-feeder"] | Fox honeypot cluster
Web App Attack
π΅π±
mkey
2026-09-01 09:14:40
(2 weeks ago)
[First: 2026-09-01 06:55:02/single] HITS=1 Repeated suspicious IDS-detected activity; sample=[nessus ...
show more
[First: 2026-09-01 06:55:02/single] HITS=1 Repeated suspicious IDS-detected activity; sample=[nessus/10302] : Unauthorized robots.txt access
show less
Port Scan
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-01 01:31:43
(2 weeks ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 21:31:34.784446 2026] [security2:error] [pid 16999:tid 16999] [client 180.153.236.214:51449] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.zezel.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.zezel.com"] [uri "/robots.txt"] [unique_id "apYq9vVvAuRPcxbx21yiJgAAAAU"], referer: https://www.zezel.com/robots.txt
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-30 18:17:01
(2 weeks ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 14:16:56.144032 2026] [security2:error] [pid 17858:tid 17858] [client 180.153.236.214:44651] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||iplayriichi.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "iplayriichi.com"] [uri "/"] [unique_id "apRzmLvxd2evIklwdMw7oQAAAAw"], referer: https://iplayriichi.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-30 15:30:18
(2 weeks ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 11:30:14.121761 2026] [security2:error] [pid 24187:tid 24187] [client 180.153.236.214:58759] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.hacertests.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.hacertests.com"] [uri "/"] [unique_id "apRMhozMjeUBnthoPLasbwAAAAU"], referer: http://www.hacertests.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-30 13:00:14
(2 weeks ago)
(mod_security) mod_security (id:949110) triggered by 180.153.236.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:949110) triggered by 180.153.236.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 30 08:59:57.619674 2026] [security2:error] [pid 30932:tid 30932] [client 180.153.236.214:27459] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "www.exorex.com"] [uri "/"] [unique_id "apQpTWRWfa50RxFR09PHEQAAAA8"], referer: https://www.exorex.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-27 09:10:28
(3 weeks ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.214 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 27 05:10:20.723044 2026] [security2:error] [pid 20238:tid 20238] [client 180.153.236.214:6753] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.sprektech.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.sprektech.com"] [uri "/"] [unique_id "ao_-_IoXemIN7J1lKEZmhwAAAAE"], referer: http://www.sprektech.com/
show less
Brute-Force
Bad Web Bot
Web App Attack