๐ง๐ฌ
HighWay
2026-06-30 23:12:20
(2 months ago)
2001:41d0:801:2000::c38 - - [30/Jun/2026:23:12:17 +0000] "GET /auto.jpg HTTP/1.1" 200 595172 "-" "Go ...
show more
2001:41d0:801:2000::c38 - - [30/Jun/2026:23:12:17 +0000] "GET /auto.jpg HTTP/1.1" 200 595172 "-" "Go-http-client/1.1"
2001:41d0:801:2000::c38 - - [30/Jun/2026:23:12:17 +0000] "GET /auto1.jpg HTTP/1.1" 200 497677 "-" "Go-http-client/1.1"
2001:41d0:801:2000::c38 - - [30/Jun/2026:23:12:18 +0000] "GET /auto2.jpg HTTP/1.1" 200 373432 "-" "Go-http-client/1.1"
2001:41d0:801:2000::c38 - - [30/Jun/2026:23:12:18 +0000] "GET /auto3.jpg HTTP/1.1" 200 574901 "-" "Go-http-client/1.1"
...
show less
IoT Targeted
Bad Web Bot
๐ซ๐ท
Catalin Negru
2026-06-29 18:56:44
(2 months ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-29 04:47:35
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:801:2000::c38 (vps-bd272fa4.vps.ovh.n ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:801:2000::c38 (vps-bd272fa4.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 29 00:47:26.928189 2026] [security2:error] [pid 16016:tid 16016] [client 2001:41d0:801:2000::c38:43262] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.timezonespro.com.verdadesreales.com:80|F|2"] [data ".lnk"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.timezonespro.com.verdadesreales.com"] [uri "/!!!!imbnsjh5 - Acceso directo.lnk"] [unique_id "akH43gazSeCSX9SjHaf0ZgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Catalin Negru
2026-06-25 13:03:44
(2 months ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐ซ๐ท
Catalin Negru
2026-06-17 09:37:03
(3 months ago)
Recidive ban by fail2ban on server.blackbit.ro
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-06-13 21:09:41
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:801:2000::c38 (vps-bd272fa4.vps.ovh.n ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:801:2000::c38 (vps-bd272fa4.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 13 17:09:32.940449 2026] [security2:error] [pid 21646:tid 21646] [client 2001:41d0:801:2000::c38:55550] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||genesis-castle.com:443|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "genesis-castle.com"] [uri "/4D/lastupdate.log"] [unique_id "ai3HDE2x5AtrFQqkCYssewAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-05-24 02:02:08
(3 months ago)
54.379 requests in 1 hour (4d13h59m)
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-22 05:00:25
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 2001:41d0:801:2000::c38 (vps-bd272fa4.vps.ovh.n ...
show more
(mod_security) mod_security (id:210492) triggered by 2001:41d0:801:2000::c38 (vps-bd272fa4.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 22 01:00:19.314634 2026] [security2:error] [pid 16594:tid 16594] [client 2001:41d0:801:2000::c38:38320] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "needtoorder.us"] [uri "/USE-To-BLOCKwww.countryipblocks.net.htaccess"] [unique_id "ag_i4x9D-jnssbkSU804VQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-21 06:39:58
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:801:2000::c38 (vps-bd272fa4.vps.ovh.n ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:801:2000::c38 (vps-bd272fa4.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 21 02:39:49.195445 2026] [security2:error] [pid 27960:tid 27960] [client 2001:41d0:801:2000::c38:50658] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||koswerks.net:80|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "koswerks.net"] [uri "/index.bak"] [unique_id "ag6otZu5WIB-ILGMnuoycQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
Erpelstolz
2026-05-18 13:29:18
(4 months ago)
external host: 2001:41d0:801:2000::c38 - - [18/May/2026:15:29:15 +0200] "HEAD /backup.zip HTTP/1.1" ...
show more
external host: 2001:41d0:801:2000::c38 - - [18/May/2026:15:29:15 +0200] "HEAD /backup.zip HTTP/1.1" 200 250 "-" "Go-http-client/1.1"
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-18 09:31:12
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:801:2000::c38 (vps-bd272fa4.vps.ovh.n ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:801:2000::c38 (vps-bd272fa4.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 18 05:31:04.338409 2026] [security2:error] [pid 27871:tid 27871] [client 2001:41d0:801:2000::c38:32962] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.chaosstaffing.apfarrell.com:443|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.chaosstaffing.apfarrell.com"] [uri "/devu3bonlinetest_anthony.sql"] [unique_id "agrcWCaq6UcnJ_9XL0B8BAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-17 21:46:16
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:801:2000::c38 (vps-bd272fa4.vps.ovh.n ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:801:2000::c38 (vps-bd272fa4.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 17:46:12.746378 2026] [security2:error] [pid 28651:tid 28739] [client 2001:41d0:801:2000::c38:39844] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||digital4z.com:80|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "digital4z.com"] [uri "/Digital4z.com/Digital4z/wp-content/plugins/app-your-wordpress-uppsite/WS_FTP.LOG"] [unique_id "ago3JKo0Ag-vKFghX9KBsAAAAhE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 14:03:25
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:801:2000::c38 (vps-bd272fa4.vps.ovh.n ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:801:2000::c38 (vps-bd272fa4.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 10:03:19.826081 2026] [security2:error] [pid 27008:tid 27008] [client 2001:41d0:801:2000::c38:58084] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mindchill.net:443|F|2"] [data ".exe.config"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mindchill.net"] [uri "/mindchill.net/otherstuff/Application Files/RockeTXT_1_0_0_18/RockeTXT.exe.config"] [unique_id "agh5J6a8AFsQQ1Fug-GZVQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 10:44:24
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:801:2000::c38 (vps-bd272fa4.vps.ovh.n ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:801:2000::c38 (vps-bd272fa4.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 16 06:44:16.812106 2026] [security2:error] [pid 625:tid 625] [client 2001:41d0:801:2000::c38:58954] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.timezonespro.com.verdadesreales.com:443|F|2"] [data ".lnk"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.timezonespro.com.verdadesreales.com"] [uri "/!!!!imbnsjh5 - Acceso directo.lnk"] [unique_id "aghKgK9-lyVR7j2ohSw_eAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-16 01:30:21
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2001:41d0:801:2000::c38 (vps-bd272fa4.vps.ovh.n ...
show more
(mod_security) mod_security (id:210730) triggered by 2001:41d0:801:2000::c38 (vps-bd272fa4.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 15 21:30:14.123666 2026] [security2:error] [pid 19759:tid 19759] [client 2001:41d0:801:2000::c38:41256] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gapanda.unionega.com:80|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gapanda.unionega.com"] [uri "/php-old.ini"] [unique_id "agfIpkUx2FpnZSFonwFiIgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack