๐บ๐ธ
TPI-Abuse
2026-09-30 07:31:47
(1 day ago)
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 03:31:39.777066 2026] [security2:error] [pid 21583:tid 21583] [client 183.23.149.61:58993] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||diamondtrailerserv.com|F|4"] [data "eCollector"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "diamondtrailerserv.com"] [uri "/robots.txt"] [unique_id "ary621F3CX8CIfey-jCJygAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 04:15:51
(1 day ago)
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 00:15:46.733708 2026] [security2:error] [pid 12028:tid 12028] [client 183.23.149.61:62919] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||openheartwellness.com|F|4"] [data "eCollector"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "openheartwellness.com"] [uri "/robots.txt"] [unique_id "aryM8tfN8w93mQQeaNWjLwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 22:26:53
(1 day ago)
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:26:48.868263 2026] [security2:error] [pid 9917:tid 9917] [client 183.23.149.61:51713] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||leveeboard.org|F|4"] [data "eCollector"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "leveeboard.org"] [uri "/robots.txt"] [unique_id "arw7KB-xdPdChwcrfY3BFQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
debaba
2026-09-29 22:15:29
(1 day ago)
aktiv
[29/Sep/2026:22:15:26.040103 +0000] arw4fWV8c_LjrK27ejIIhAAAAEk 183.23.149.61 58712 127.0.0.1 ...
show more
aktiv
[29/Sep/2026:22:15:26.040103 +0000] arw4fWV8c_LjrK27ejIIhAAAAEk 183.23.149.61 58712 127.0.0.1 7081
[29/Sep/2026:22:15:27.242381 +0000] arw4fmV8c_LjrK2
...
show less
Brute-Force
Web App Attack
๐ฉ๐ช
4server
2026-09-29 14:57:29
(1 day ago)
[TueSep2916:57:27.7543642026][security2:error][pid2422176:tid2422251][client183.23.149.61:0]ModSecur ...
show more
[TueSep2916:57:27.7543642026][security2:error][pid2422176:tid2422251][client183.23.149.61:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Matchof\"rx\(windows-live-social-object-extractor-engine\|nutch-\)\"against\"REQUEST_HEADERS:User-Agent\"required.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"236\"][id\"330056\"][rev\"10\"][msg\"Atomicorp.comWAFRules:EmailHarvesterSpambotUseragentdetected\"][severity\"CRITICAL\"][hostname\"archi-box.ch\"][uri\"/robots.txt\"][unique_id\"arvR12-tGkFyJcoyxVyxXgAAAFU\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 12:27:10
(1 day ago)
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 08:27:04.622774 2026] [security2:error] [pid 26477:tid 26477] [client 183.23.149.61:52632] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||dpcfab.com|F|4"] [data "eCollector"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "dpcfab.com"] [uri "/robots.txt"] [unique_id "aruumPDQsMiuYBMIgvD4vwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 11:26:31
(1 day ago)
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 07:26:24.576390 2026] [security2:error] [pid 30224:tid 30224] [client 183.23.149.61:56765] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||xcengineering.xyz|F|4"] [data "eCollector"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "xcengineering.xyz"] [uri "/robots.txt"] [unique_id "arugYLU4z-yTT5WpoAmlxQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-09-28 14:28:25
(2 days ago)
WAF-refused requests | method: GET | path: /robots.txt | ua: PublicBusinessRoleCollector/1.0 (public ...
show more
WAF-refused requests | method: GET | path: /robots.txt | ua: PublicBusinessRoleCollector/1.0 (public company role inbox research; respects robots.txt) | 2026-09-28 14:28 UTC
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-28 12:30:48
(2 days ago)
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 08:30:41.213253 2026] [security2:error] [pid 26485:tid 26485] [client 183.23.149.61:64430] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||flinthillsveterans.org|F|4"] [data "eCollector"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "flinthillsveterans.org"] [uri "/robots.txt"] [unique_id "arpd8fXNyJEIsgS2aY8FvgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 05:34:11
(3 days ago)
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 01:34:09.498033 2026] [security2:error] [pid 8580:tid 8580] [client 183.23.149.61:54510] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||accordionfactory.com|F|4"] [data "eCollector"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "accordionfactory.com"] [uri "/robots.txt"] [unique_id "arn8UfZqjv-k0hIZOmsjfwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 03:19:21
(3 days ago)
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 23:19:14.981801 2026] [security2:error] [pid 22674:tid 22674] [client 183.23.149.61:57370] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||advmach.com|F|4"] [data "eCollector"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "advmach.com"] [uri "/robots.txt"] [unique_id "arncsqgskpvDBH4C7UA6rwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 01:54:08
(3 days ago)
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 21:54:04.390157 2026] [security2:error] [pid 24525:tid 24525] [client 183.23.149.61:59102] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||epicureankids.com|F|4"] [data "eCollector"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "epicureankids.com"] [uri "/robots.txt"] [unique_id "arnIvK_V07Q1F4XAFYmN5wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 16:34:12
(3 days ago)
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 12:34:04.139428 2026] [security2:error] [pid 19573:tid 19573] [client 183.23.149.61:51842] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||jolankagroup.com|F|4"] [data "eCollector"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "jolankagroup.com"] [uri "/robots.txt"] [unique_id "arlFfCllBZYPLTgxCk8hCgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-09-27 15:46:28
(3 days ago)
[SunSep2717:46:27.0766442026][security2:error][pid3832396:tid3832512][client183.23.149.61:0]ModSecur ...
show more
[SunSep2717:46:27.0766442026][security2:error][pid3832396:tid3832512][client183.23.149.61:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Matchof\"rx\(windows-live-social-object-extractor-engine\|nutch-\)\"against\"REQUEST_HEADERS:User-Agent\"required.[file\"/etc/apache2/conf.d/modsec_rules/20_asl_useragents.conf\"][line\"236\"][id\"330056\"][rev\"10\"][msg\"Atomicorp.comWAFRules:EmailHarvesterSpambotUseragentdetected\"][severity\"CRITICAL\"][hostname\"dgtime.ch\"][uri\"/robots.txt\"][unique_id\"ark6UwhS3HoTRbj5hHxFxQAAANg\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 13:04:30
(3 days ago)
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 183.23.149.61 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 09:04:25.774831 2026] [security2:error] [pid 13751:tid 13875] [client 183.23.149.61:59989] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||secdc.org|F|4"] [data "eCollector"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "secdc.org"] [uri "/robots.txt"] [unique_id "arkUWaAncNKVwcaAkQJ1UAAAAZY"]
show less
Brute-Force
Bad Web Bot
Web App Attack