Anonymous
2026-09-05 16:11:03
(15 hours ago)
Web App Attack, Hacking
Hacking
Web App Attack
🇳🇱
Site.eu
2026-09-04 19:59:07
(1 day ago)
Excessive multi-domain requests
Brute-Force
Anonymous
2026-09-04 04:06:48
(2 days ago)
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: KR, Attack patterns: Back ...
show more
Blocked by FortiWeb WAF ML threat detection. ML probability: 99%, Country: KR, Attack patterns: Backup file probing
show less
Bad Web Bot
Web App Attack
🇸🇪
vaia.cloud
2026-09-03 18:30:01
(2 days ago)
crowdsecurity/http-sensitive-files
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 16:33:16
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 221.150.78.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 221.150.78.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 12:33:09.667924 2026] [security2:error] [pid 22225:tid 22225] [client 221.150.78.8:11826] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.noelramos.com|F|2"] [data ".noelramos.com.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.noelramos.com"] [uri "/www.noelramos.com.bak"] [unique_id "apmhRVDCStzTsTR7tcS_GAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 16:15:12
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 221.150.78.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 221.150.78.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 12:15:06.443129 2026] [security2:error] [pid 12156:tid 12156] [client 221.150.78.8:17792] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.indoorfreeflight.com|F|2"] [data ".indoorfreeflight.com.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.indoorfreeflight.com"] [uri "/www.indoorfreeflight.com.bak"] [unique_id "apmdCuw133MMaReVKToTiwAAAHc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 15:55:34
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 221.150.78.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 221.150.78.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 11:55:26.375614 2026] [security2:error] [pid 31944:tid 31944] [client 221.150.78.8:48054] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.weathercarib.com|F|2"] [data ".weathercarib.com.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.weathercarib.com"] [uri "/www.weathercarib.com.bak"] [unique_id "apmYboNdsjZgZo_ZV_-RoAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇦🇺
A.i.D.A.N.N
2026-09-03 15:05:30
(2 days ago)
A.i.D.A.N.N: Anomaly Detected - Signature match Web Service - Web vulnerability scanning detected
Web App Attack
🇩🇪
MusicLibrary
2026-09-03 10:39:54
(2 days ago)
Attempted access to sensitive configuration files (.env, .git, etc.)
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 08:31:04
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 221.150.78.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 221.150.78.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 04:30:59.882516 2026] [security2:error] [pid 24744:tid 24747] [client 221.150.78.8:4034] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.whatismetamodern.com|F|2"] [data ".whatismetamodern.com.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.whatismetamodern.com"] [uri "/www.whatismetamodern.com.bak"] [unique_id "apkwQ2kTnGCP-kv67GWzcAAAAUE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
ghostwarriors
2026-09-03 08:20:06
(2 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
🇺🇸
ipblock.com
2026-09-03 07:16:00
(3 days ago)
IPBlock protected site ID [4055-d][s=07].
Persistent 404, vulnerability scanner
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 05:55:11
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 221.150.78.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 221.150.78.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 01:55:04.771527 2026] [security2:error] [pid 26232:tid 26232] [client 221.150.78.8:29824] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||smogsandiego.com|F|2"] [data ".com.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "smogsandiego.com"] [uri "/smogsandiego.com.bak"] [unique_id "apkLuM7sAHEPFqxVjns4-gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 23:08:59
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 221.150.78.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 221.150.78.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 19:08:55.859013 2026] [security2:error] [pid 26503:tid 26503] [client 221.150.78.8:1280] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bassboatmagazine.com|F|2"] [data ".bassboatmagazine.com.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bassboatmagazine.com"] [uri "/www.bassboatmagazine.com.bak"] [unique_id "apish-WufkYjNy97tQMTYwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-02 22:36:48
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 221.150.78.8 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 221.150.78.8 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 18:36:44.094061 2026] [security2:error] [pid 10666:tid 10666] [client 221.150.78.8:57850] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.empoweruohio.org|F|2"] [data ".empoweruohio.org.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.empoweruohio.org"] [uri "/www.empoweruohio.org.bak"] [unique_id "apik_Cvkg0xExUGkfauw9QAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack