๐บ๐ธ
TPI-Abuse
2026-09-23 05:42:07
(1 week ago)
(mod_security) mod_security (id:217210) triggered by 209.101.150.251 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217210) triggered by 209.101.150.251 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 01:41:51.235263 2026] [security2:error] [pid 13725:tid 13725] [client 209.101.150.251:51409] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||poltorak.net|F|4"] [data "GET http://poltorak.net HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "poltorak.net"] [uri "/"] [unique_id "arNmn2GuZPXr-y3jpFuhogAAAEM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 05:12:21
(1 week ago)
(mod_security) mod_security (id:217210) triggered by 209.101.150.251 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217210) triggered by 209.101.150.251 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 23 01:12:04.838942 2026] [security2:error] [pid 19664:tid 19664] [client 209.101.150.251:7436] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||simia.com|F|4"] [data "GET http://simia.com HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "simia.com"] [uri "/"] [unique_id "arNfpPahQh4q7Jb37l24AgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
DRI
2026-09-23 03:02:24
(1 week ago)
Web attack/Malicious activity detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-23 02:39:44
(1 week ago)
(mod_security) mod_security (id:217210) triggered by 209.101.150.251 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217210) triggered by 209.101.150.251 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 22 22:39:29.375571 2026] [security2:error] [pid 332:tid 332] [client 209.101.150.251:17789] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||brianmindy.com|F|4"] [data "GET http://brianmindy.com HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "brianmindy.com"] [uri "/"] [unique_id "arM74cf9qXSiwE_OE-YfAwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ph
2026-09-22 20:07:35
(1 week ago)
Bad web bot attempting to run wp-json on non-WP site
Hacking
Bad Web Bot
Web App Attack
Anonymous
2026-09-21 06:46:30
(1 week ago)
Web application attack detected.
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-20 22:54:34
(1 week ago)
(mod_security) mod_security (id:217210) triggered by 209.101.150.251 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217210) triggered by 209.101.150.251 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 20 18:54:16.686172 2026] [security2:error] [pid 28634:tid 28634] [client 209.101.150.251:2956] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||grupoporvenir.com|F|4"] [data "GET http://grupoporvenir.com HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "grupoporvenir.com"] [uri "/"] [unique_id "arBkGGLb2EQs8fJO5MwjVwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
dot.mg
2026-09-20 10:46:19
(1 week ago)
Scan of vulnerable files
Web App Attack
๐ฆ๐บ
electronico
2026-09-19 15:21:00
(2 weeks ago)
209.101.150.251 - - [20/Sep/2026:02:20:59 +1100] "POST /xmlrpc.php HTTP/1.1" 404 2049 "-" "Mozilla/5 ...
show more
209.101.150.251 - - [20/Sep/2026:02:20:59 +1100] "POST /xmlrpc.php HTTP/1.1" 404 2049 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/119.0.0.0 Safari/537.36 Edg/119.0.0.0"
...
show less
Brute-Force
Web App Attack