๐บ๐ธ
TPI-Abuse
2026-10-01 20:12:49
(30 minutes ago)
(mod_security) mod_security (id:210831) triggered by 213.32.23.83 (vps-7aea15b0.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:210831) triggered by 213.32.23.83 (vps-7aea15b0.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 16:12:43.102556 2026] [security2:error] [pid 26449:tid 26449] [client 213.32.23.83:44940] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||theledman.net|F|4"] [data "SurveyBot"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "theledman.net"] [uri "/.well-known/security.txt"] [unique_id "ar6-u3gHZWomj4cObvSYJgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 18:45:56
(1 hour ago)
(mod_security) mod_security (id:210831) triggered by 213.32.23.83 (vps-7aea15b0.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:210831) triggered by 213.32.23.83 (vps-7aea15b0.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 14:45:49.443315 2026] [security2:error] [pid 23808:tid 23808] [client 213.32.23.83:49806] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||puckerbuttbikini.com|F|4"] [data "SurveyBot"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "puckerbuttbikini.com"] [uri "/.well-known/security.txt"] [unique_id "ar6qXS9oIELBEmmBL9SYfQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-10-01 18:18:19
(2 hours ago)
Not following 301 redirects โ wasted requests | method: GET | path: /security.txt | ua: Mozilla/5.0 ...
show more
Not following 301 redirects โ wasted requests | method: GET | path: /security.txt | ua: Mozilla/5.0 (compatible; SecurityTxtSurveyBot/1.0; recherche journalistique sur l'adoption de security.txt sur le TLD .fr; conta | 2026-10-01 18:18 UTC
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 17:56:27
(2 hours ago)
(mod_security) mod_security (id:210831) triggered by 213.32.23.83 (vps-7aea15b0.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:210831) triggered by 213.32.23.83 (vps-7aea15b0.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:56:20.678927 2026] [security2:error] [pid 24504:tid 24504] [client 213.32.23.83:50822] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||jackierankin.com|F|4"] [data "SurveyBot"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "jackierankin.com"] [uri "/.well-known/security.txt"] [unique_id "ar6exOGMdfarfYP0_0DzMQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
jfz-abuse
2026-10-01 17:45:04
(2 hours ago)
fail2ban: apache-filepath-recon
...
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 17:03:51
(3 hours ago)
(mod_security) mod_security (id:210831) triggered by 213.32.23.83 (vps-7aea15b0.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:210831) triggered by 213.32.23.83 (vps-7aea15b0.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 13:03:46.264311 2026] [security2:error] [pid 26760:tid 26760] [client 213.32.23.83:36424] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||garyandthegroove.com|F|4"] [data "SurveyBot"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "garyandthegroove.com"] [uri "/.well-known/security.txt"] [unique_id "ar6SchniBX_i6goHMOPNOQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ช
Coolnagour
2026-10-01 15:35:23
(5 hours ago)
http-probing: /security.txt
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 15:26:53
(5 hours ago)
(mod_security) mod_security (id:210831) triggered by 213.32.23.83 (vps-7aea15b0.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:210831) triggered by 213.32.23.83 (vps-7aea15b0.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 11:26:45.826292 2026] [security2:error] [pid 4896:tid 4896] [client 213.32.23.83:36250] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||dianadelapava.com|F|4"] [data "SurveyBot"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "dianadelapava.com"] [uri "/.well-known/security.txt"] [unique_id "ar57tWg5mp9HpoL5YBjb_wAAACo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 11:23:48
(9 hours ago)
(mod_security) mod_security (id:210831) triggered by 213.32.23.83 (vps-7aea15b0.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:210831) triggered by 213.32.23.83 (vps-7aea15b0.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:23:45.222247 2026] [security2:error] [pid 22958:tid 22958] [client 213.32.23.83:47594] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||safeharbourfund.com|F|4"] [data "SurveyBot"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "safeharbourfund.com"] [uri "/.well-known/security.txt"] [unique_id "ar5CwXCzpqEcLipAGHjnsAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-10-01 10:42:58
(10 hours ago)
Not following 301 redirects โ wasted requests | method: GET | path: /security.txt | ua: Mozilla/5.0 ...
show more
Not following 301 redirects โ wasted requests | method: GET | path: /security.txt | ua: Mozilla/5.0 (compatible; SecurityTxtSurveyBot/1.0; recherche journalistique sur l'adoption de security.txt sur le TLD .fr; conta
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-01 10:21:54
(10 hours ago)
(mod_security) mod_security (id:210831) triggered by 213.32.23.83 (vps-7aea15b0.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:210831) triggered by 213.32.23.83 (vps-7aea15b0.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:21:51.711341 2026] [security2:error] [pid 5740:tid 5790] [client 213.32.23.83:52186] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||dcmproductionsgroup.com|F|4"] [data "SurveyBot"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "dcmproductionsgroup.com"] [uri "/.well-known/security.txt"] [unique_id "ar40P2bMWyF67PExjIZvMQAAAM4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 09:25:29
(11 hours ago)
(mod_security) mod_security (id:210831) triggered by 213.32.23.83 (vps-7aea15b0.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:210831) triggered by 213.32.23.83 (vps-7aea15b0.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 05:25:25.043865 2026] [security2:error] [pid 21812:tid 21812] [client 213.32.23.83:58994] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||tenmenband.com|F|4"] [data "SurveyBot"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "tenmenband.com"] [uri "/.well-known/security.txt"] [unique_id "ar4nBYKVzgVON2C6vlSEcQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 08:56:57
(11 hours ago)
(mod_security) mod_security (id:210831) triggered by 213.32.23.83 (vps-7aea15b0.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:210831) triggered by 213.32.23.83 (vps-7aea15b0.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 04:56:52.430684 2026] [security2:error] [pid 11564:tid 11564] [client 213.32.23.83:40452] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||greatchristianadventure.com|F|4"] [data "SurveyBot"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "greatchristianadventure.com"] [uri "/.well-known/security.txt"] [unique_id "ar4gVElhZYY82_eChpXU7gAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐ณ
soporte
2026-10-01 08:41:53
(12 hours ago)
Probe for vulnerabilities. Path attempted: /.well-known/security
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 07:29:24
(13 hours ago)
(mod_security) mod_security (id:210831) triggered by 213.32.23.83 (vps-7aea15b0.vps.ovh.net): 1 in t ...
show more
(mod_security) mod_security (id:210831) triggered by 213.32.23.83 (vps-7aea15b0.vps.ovh.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 03:29:16.835263 2026] [security2:error] [pid 8223:tid 8223] [client 213.32.23.83:59446] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||brupharm.org|F|4"] [data "SurveyBot"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "brupharm.org"] [uri "/.well-known/security.txt"] [unique_id "ar4LzF76-ZhBdyMGokejWQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack