🇺🇸
TPI-Abuse
2026-09-13 16:35:13
(50 minutes ago)
(mod_security) mod_security (id:210730) triggered by 206.42.109.58 (crawl-4.sofya.co): 1 in the last ...
show more
(mod_security) mod_security (id:210730) triggered by 206.42.109.58 (crawl-4.sofya.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 12:35:05.705192 2026] [security2:error] [pid 12961:tid 12972] [client 206.42.109.58:38160] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.gafm.org|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.gafm.org"] [uri "/http/charteredfinancialmanager.com"] [unique_id "aqbQuZ4djPlKlSF4a20XMwAAAUY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 15:12:34
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 206.42.109.58 (crawl-4.sofya.co): 1 in the last ...
show more
(mod_security) mod_security (id:210730) triggered by 206.42.109.58 (crawl-4.sofya.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 11:12:31.202489 2026] [security2:error] [pid 4819:tid 4819] [client 206.42.109.58:56342] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||henrietteg.com|F|2"] [data ".linguistes.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "henrietteg.com"] [uri "/archives-UTM/fre378/http;/www.linguistes.com"] [unique_id "aqa9X7l8_bDldue5x8DvqQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
bigorre.org
2026-09-13 14:53:48
(2 hours ago)
Unidentified crawling: not a self-announced bot in user-agent
Bad Web Bot
Anonymous
2026-09-13 12:12:04
(5 hours ago)
Suspicious activity detected in web server access logs
Web App Attack
🇺🇸
TPI-Abuse
2026-09-13 11:48:25
(5 hours ago)
(mod_security) mod_security (id:210730) triggered by 206.42.109.58 (crawl-4.sofya.co): 1 in the last ...
show more
(mod_security) mod_security (id:210730) triggered by 206.42.109.58 (crawl-4.sofya.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 07:48:20.967090 2026] [security2:error] [pid 27720:tid 27720] [client 206.42.109.58:33212] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ourodyssey.us|F|2"] [data ".blogspot.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ourodyssey.us"] [uri "/ourodyssey.blogspot.com"] [unique_id "aqaNhNMfmts8NYfPyl9qFgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Reinhard
2026-09-13 10:59:41
(6 hours ago)
Harvesting non-existent pages or unknown malicious BOT.
Bad Web Bot
🇮🇩
Burayot
2026-09-12 21:17:40
(20 hours ago)
LF_MODSEC: (mod_security) mod_security (id:10000003) triggered by 206.42.109.58 (US/United States/cr ...
show more
LF_MODSEC: (mod_security) mod_security (id:10000003) triggered by 206.42.109.58 (US/United States/crawl-4.sofya.co): 2 in the last 3600 secs
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 18:52:11
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 206.42.109.58 (crawl-4.sofya.co): 1 in the last ...
show more
(mod_security) mod_security (id:210730) triggered by 206.42.109.58 (crawl-4.sofya.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 14:52:06.339858 2026] [security2:error] [pid 20978:tid 20978] [client 206.42.109.58:54086] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||home.agingworkforcenews.com|F|2"] [data ".myceridian.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "home.agingworkforcenews.com"] [uri "/2005/08/http/www.myceridian.com"] [unique_id "aqWfVj0E3p1toGM_aOdwyAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
Phenix Info
2026-09-12 17:42:19
(23 hours ago)
SmallGuard.fr/Prestashop Massive 403
Web App Attack
🇺🇸
TPI-Abuse
2026-09-12 11:13:43
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 206.42.109.58 (crawl-4.sofya.co): 1 in the last ...
show more
(mod_security) mod_security (id:210730) triggered by 206.42.109.58 (crawl-4.sofya.co): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 12 07:13:38.900175 2026] [security2:error] [pid 2753102:tid 2753102] [client 206.42.109.58:33466] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nancyscafeandcatering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nancyscafeandcatering.com"] [uri "/wp-content/themes/eatery/crazyhotfuck.com"] [unique_id "aqUz4iyX6fFsUvdtg5OaBgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
bigorre.org
2026-09-12 10:46:01
(1 day ago)
Unidentified crawling: not a self-announced bot in user-agent
Bad Web Bot
🇨🇦
polycoda
2026-09-12 09:46:22
(1 day ago)
🔥 VERY AGGRESSIVE SCANNER probed over 200 inexistent files and PHP scripts in less than an hour.
Hacking
Web App Attack
🇨🇭
4server
2026-09-12 09:22:15
(1 day ago)
[SatSep1211:22:11.1511002026][security2:error][pid3053591:tid3053896][client206.42.109.58:0]ModSecur ...
show more
[SatSep1211:22:11.1511002026][security2:error][pid3053591:tid3053896][client206.42.109.58:0]ModSecurity:Accessdeniedwithcode403\(phase2\).OperatorGTmatched400atIP:wishlist_counter.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"445\"][id\"1004014\"][msg\"Wishlistabuseblocked\"][hostname\"prodotti.comarcosa.com\"][uri\"/prodotto/16866\"][unique_id\"aqUZw6sYg7IUZIS_KLoyeAAAAVE\"]
show less
Hacking
Web App Attack
🇸🇮
extremevital
2026-09-12 07:35:05
(1 day ago)
...
Bad Web Bot
🇧🇪
cmbplf
2026-09-12 01:00:35
(1 day ago)
25.061 requests in 1 hour (4d8h59m)
Brute-Force
Bad Web Bot