Anonymous
2026-09-22 13:13:02
(1 week ago)
IP matched detection query bad paths many.
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 02:05:23
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 185.238.214.224 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 185.238.214.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 22:05:13.419058 2026] [security2:error] [pid 24187:tid 24261] [client 185.238.214.224:57161] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||paywithfortress.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "paywithfortress.com"] [uri "/logs/debug.log"] [unique_id "aqn5WQwHPcdkUn4WKJbijwAAAIY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 00:39:41
(2 weeks ago)
(mod_security) mod_security (id:210350) triggered by 185.238.214.224 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210350) triggered by 185.238.214.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:39:34.811479 2026] [security2:error] [pid 3815:tid 3815] [client 185.238.214.224:27979] ModSecurity: Access denied with code 403 (phase 2). Pattern match "\\\\b(close|keep-alive),[\\\\t\\\\n\\\\r ]{0,1}(close|keep-alive)\\\\b" at REQUEST_HEADERS:Connection. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "70"] [id "210350"] [rev "1"] [msg "COMODO WAF: Multiple/Conflicting Connection Header Data Found||payrrip.com|F|4"] [data "keep-alive, close"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "payrrip.com"] [uri "/request_data_logs.txt"] [unique_id "aqnlRn9wchqMdSfk3Jmo_wAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 00:08:05
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 185.238.214.224 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 185.238.214.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 20:07:54.447695 2026] [security2:error] [pid 405:tid 405] [client 185.238.214.224:12891] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||casapapayasanmiguel.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "casapapayasanmiguel.com"] [uri "/logs/debug.log"] [unique_id "aqnd2m2WIlFVHy3VKkc9TAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฟ๐ฆ
vanderhost
2026-09-15 21:47:09
(2 weeks ago)
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /storage/logs/laravel-20 ...
show more
[Laravel HoneypotPlus] Automated report - Honeypot access detected on path: /storage/logs/laravel-2026-09-14.log via rule: /storage/logs
show less
Web App Attack
Bad Web Bot
๐ฎ๐ฉ
Burayot
2026-09-15 21:43:09
(2 weeks ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 185.238.214.224 (US/United States/-) ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 185.238.214.224 (US/United States/-): 1 in the last 3600 secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:29:56
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 185.238.214.224 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 185.238.214.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:29:48.197022 2026] [security2:error] [pid 14488:tid 14488] [client 185.238.214.224:35555] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||headcount.dev|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "headcount.dev"] [uri "/storage/logs/laravel-2026-09-14.log"] [unique_id "aqm4zOHkarZobjv_AmwQsAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 21:12:11
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 185.238.214.224 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 185.238.214.224 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 17:12:04.024518 2026] [security2:error] [pid 4091:tid 4091] [client 185.238.214.224:52969] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||daveweisman.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "daveweisman.com"] [uri "/storage/logs/laravel-2026-09-14.log"] [unique_id "aqm0pEPKoejw25m-vGtlZgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ท๐บ
DZBOT
2026-07-14 02:46:59
(2 months ago)
DZBOT: Website Scanning / Scraping
Bad Web Bot
Exploited Host
Web App Attack