πΊπΈ
TPI-Abuse
2026-08-17 01:32:04
(43 minutes ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 21:31:58.371837 2026] [security2:error] [pid 7989:tid 7989] [client 180.153.236.240:36081] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||bonvivantorganics.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "bonvivantorganics.com"] [uri "/"] [unique_id "aoJkjn20NFObh4vRQp5e_gAAAAE"], referer: https://bonvivantorganics.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 22:01:06
(4 hours ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 18:01:00.485311 2026] [security2:error] [pid 6262:tid 6262] [client 180.153.236.240:41455] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.pikespeakjazz.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.pikespeakjazz.com"] [uri "/"] [unique_id "aoIzHAVH4ryqfCL-O5hUmAAAAAU"], referer: https://www.pikespeakjazz.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 08:37:25
(17 hours ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 04:37:18.011379 2026] [security2:error] [pid 24296:tid 24296] [client 180.153.236.240:50243] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.thesteeldrumman.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.thesteeldrumman.com"] [uri "/"] [unique_id "aoF2vlyOyHmrFLIJDLnHhwAAABA"], referer: https://www.thesteeldrumman.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 07:14:52
(19 hours ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 03:14:45.289096 2026] [security2:error] [pid 24144:tid 24165] [client 180.153.236.240:28115] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.newyorkfreepress.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.newyorkfreepress.com"] [uri "/"] [unique_id "aoFjZW9WWiAOTA26f2VyywAAAI0"], referer: https://www.newyorkfreepress.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-16 05:18:36
(20 hours ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 16 01:18:30.940737 2026] [security2:error] [pid 14079:tid 14079] [client 180.153.236.240:47197] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||sharonmauldin.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "sharonmauldin.com"] [uri "/"] [unique_id "aoFIJvLWdmKofUQfTNYFVgAAACg"], referer: https://sharonmauldin.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΉπ·
neron
2026-08-15 13:06:48
(1 day ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
πΉπ·
neron
2026-08-14 13:06:48
(2 days ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
πΉπ·
neron
2026-08-13 07:06:48
(3 days ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
πΉπ·
neron
2026-08-12 01:06:48
(5 days ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
πΉπ·
neron
2026-08-11 00:29:21
(6 days ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
πΉπ·
neron
2026-08-09 20:29:21
(1 week ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
π©πͺ
Hazzard
2026-08-09 07:17:13
(1 week ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted]): (CF_ENABLE)
Bad Web Bot
πΉπ·
neron
2026-08-08 20:29:21
(1 week ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack
πΊπΈ
TPI-Abuse
2026-08-08 16:00:11
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 180.153.236.240 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210831) triggered by 180.153.236.240 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 08 12:00:06.391674 2026] [security2:error] [pid 4026115:tid 4026138] [client 180.153.236.240:39937] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||vcschief.org|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "vcschief.org"] [uri "/"] [unique_id "andShvg_r5JAMhNC349QDAAAARA"], referer: http://vcschief.org/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΉπ·
neron
2026-08-07 13:37:17
(1 week ago)
CrowdSec blocked: http:exploit detected via OPNsense firewall
Hacking
Web App Attack