🇩🇪
LRob
2026-09-18 08:08:27
(1 day ago)
Abusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: User-Agen ...
show more
Abusive crawler: User-Agent on the known-bad list or claiming a placeholder identity | ua: User-Agent:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36 Edg/1 | path: / | 2026-09-18 08:08 UTC
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-17 07:14:20
(2 days ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 03:14:15.046228 2026] [security2:error] [pid 29768:tid 29785] [client 180.153.236.217:29639] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.pflagabq.org|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.pflagabq.org"] [uri "/"] [unique_id "aquTR-PcX0KCi7yuECYKeAAAAIo"], referer: http://www.pflagabq.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
Mediashaker
2026-09-17 07:03:05
(2 days ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 180.153.236.217 (CN/ ...
show more
(apache-useragents) Failed apache-useragents trigger with match [redacted] from 180.153.236.217 (CN/China/-)
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-17 06:43:02
(2 days ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 02:42:56.494380 2026] [security2:error] [pid 25750:tid 25750] [client 180.153.236.217:5943] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.nationalnova.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.nationalnova.com"] [uri "/"] [unique_id "aquL8LumIo2zfHGB6yoVjAAAACs"], referer: http://www.nationalnova.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
paulshipley.com.au
2026-09-15 08:35:03
(4 days ago)
[Tue Sep 15 18:35:02.233332 2026] [security2:error] [pid 226552] [client 180.153.236.217:56681] [cli ...
show more
[Tue Sep 15 18:35:02.233332 2026] [security2:error] [pid 226552] [client 180.153.236.217:56681] [client 180.153.236.217] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "valueaddedpromotions.com.au"] [uri "/"] [unique_id "aqkDNiKTwgr1XUpYpNubOQAAAAA"], referer: https://valueaddedpromotions.com.au/
...
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 05:13:09
(4 days ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 01:13:01.924741 2026] [security2:error] [pid 4432:tid 4432] [client 180.153.236.217:8337] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||damonmarks.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "damonmarks.com"] [uri "/"] [unique_id "aqjT3QehpPPG-YmntFvoVAAAABI"], referer: http://damonmarks.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-15 04:22:07
(4 days ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 00:22:03.252620 2026] [security2:error] [pid 18072:tid 18072] [client 180.153.236.217:39679] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.ohiohca.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.ohiohca.com"] [uri "/"] [unique_id "aqjH6-D5eW6bmeG635FNYgAAAAU"], referer: http://www.ohiohca.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-15 04:14:38
(4 days ago)
Asking over plain http and never following the redirect served — a crawler that reads nothing it ask ...
show more
Asking over plain http and never following the redirect served — a crawler that reads nothing it asks for | method: GET | path: / | ua: User-Agent:Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36 Edg/1 | 2026-09-15 04:14 UTC
show less
Bad Web Bot
Anonymous
2026-09-15 03:49:33
(4 days ago)
apache vulnerability scan
Web App Attack
🇪🇸
gnom4ik
2026-09-07 09:23:28
(1 week ago)
ban-reviewer auto report; ip=180.153.236.217; scenario=http:scan; verdict=valid_ban; confidence=0.92 ...
show more
ban-reviewer auto report; ip=180.153.236.217; scenario=http:scan; verdict=valid_ban; confidence=0.92; categories=15; active_decisions=3; lookback_decisions=3; nginx_requests=0; appsec_matches=0; auth_events=0; kernel_events=0; signals=ip_decision_count_high; ip_active_decision_count_high
show less
Hacking
🇺🇸
TPI-Abuse
2026-09-07 08:38:13
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:38:06.562045 2026] [security2:error] [pid 30074:tid 30074] [client 180.153.236.217:35339] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||seizinthebook.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "seizinthebook.com"] [uri "/"] [unique_id "ap537uiOy4bu3ZjvZzIJkAAAAAg"], referer: https://seizinthebook.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 08:17:18
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 04:17:11.760924 2026] [security2:error] [pid 5897:tid 5897] [client 180.153.236.217:31501] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.ttel-llc.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.ttel-llc.com"] [uri "/"] [unique_id "ap5zB2no3dt3dufOuYiXVwAAAA8"], referer: http://www.ttel-llc.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 20:38:41
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 16:38:34.582957 2026] [security2:error] [pid 27603:tid 27603] [client 180.153.236.217:37017] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.hayrun.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.hayrun.com"] [uri "/"] [unique_id "ap3PStWYnT1FxoCjlDfSTgAAAAM"], referer: https://www.hayrun.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-06 07:09:14
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.217 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.217 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 03:09:10.112755 2026] [security2:error] [pid 8516:tid 8516] [client 180.153.236.217:16895] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.moralportfolio.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.moralportfolio.com"] [uri "/"] [unique_id "ap0Rllj8ab3CWjAlxIO6RgAAABY"], referer: http://www.moralportfolio.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-06 04:48:40
(1 week ago)
apache vulnerability scan
Web App Attack