🇺🇸
SX Communications
2026-08-24 21:04:28
(1 week ago)
HTTP application-layer DoS / botnet traffic from 23.236.230.2: repeated high-cost dynamic page and f ...
show more
HTTP application-layer DoS / botnet traffic from 23.236.230.2: repeated high-cost dynamic page and feed requests (profile/tag views, forums, tracker, RSS) at abusive rates via completed TCP/HTTPS. Likely compromised end-user host.
show less
DDoS Attack
Bad Web Bot
Exploited Host
🇳🇱
homeshowdomain.nl
2026-04-12 21:59:19
(4 months ago)
Auto-ban: >3000 req/min op 2026-04-12
Web App Attack
SSH
Hacking
🇺🇸
TPI-Abuse
2026-04-12 17:35:56
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 23.236.230.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 23.236.230.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 12 13:35:49.304902 2026] [security2:error] [pid 3206925:tid 3207011] [client 23.236.230.2:45462] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||madring.click|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "madring.click"] [uri "/dump.sql"] [unique_id "advX9Ye7AoFV-DNrUA_STQAAANg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-12 03:14:09
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 23.236.230.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 23.236.230.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 11 23:14:04.211205 2026] [security2:error] [pid 3715694:tid 3715694] [client 23.236.230.2:55096] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||resizephoto.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "resizephoto.org"] [uri "/database.sql"] [unique_id "adsN_ICQHNyUPICUuYeX3AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-10 20:40:23
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 23.236.230.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 23.236.230.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 10 16:40:17.165836 2026] [security2:error] [pid 2415247:tid 2415247] [client 23.236.230.2:49863] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rankandfile.lgbt|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rankandfile.lgbt"] [uri "/dump.sql"] [unique_id "adlgMeRSSio77WNyiuJU5gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-10 01:15:00
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 23.236.230.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 23.236.230.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 09 21:14:53.408655 2026] [security2:error] [pid 1086293:tid 1086293] [client 23.236.230.2:57719] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||qovintheloop.org|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "qovintheloop.org"] [uri "/database.sql"] [unique_id "adhPDRc3hQb6Pq2mRVou0AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-08 12:16:15
(4 months ago)
Fuzzing/Looking for credentials files.
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-04-08 11:50:11
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 23.236.230.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 23.236.230.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 08 07:50:04.831614 2026] [security2:error] [pid 2719211:tid 2719211] [client 23.236.230.2:56383] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||preskitpc.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "preskitpc.com"] [uri "/db.sql"] [unique_id "adZA7ETAUWrT02PWysIf_wAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-05 17:10:22
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 23.236.230.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 23.236.230.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 13:10:16.983455 2026] [security2:error] [pid 14024:tid 14024] [client 23.236.230.2:51421] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arcticwarriors.org"] [uri "/wp-config.php"] [unique_id "adKXeMFITQXKbRKOq2SKyAAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-05 15:08:50
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 23.236.230.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 23.236.230.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 05 11:08:46.527368 2026] [security2:error] [pid 21257:tid 21257] [client 23.236.230.2:39632] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "arapi.org"] [uri "/.env.staging"] [unique_id "adJ6_tuppW-z8dfsNckX-AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-04 22:30:58
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 23.236.230.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 23.236.230.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 04 18:30:53.465889 2026] [security2:error] [pid 16069:tid 16090] [client 23.236.230.2:51504] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "annaly.org"] [uri "/.env.development"] [unique_id "adGRHZbUQoaW0Hqfxh2HjAAAAJI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-04-03 04:03:39
(5 months ago)
(mod_security) mod_security (id:210492) triggered by 23.236.230.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 23.236.230.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Apr 03 00:03:22.194540 2026] [security2:error] [pid 24241:tid 24275] [client 23.236.230.2:41236] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "marinkovich.org"] [uri "/.git/config"] [unique_id "ac88CrlIah339KBkmNDY_QAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
ipblock.com
2026-03-29 11:27:00
(5 months ago)
IPBlock protected site ID [3192-af][s=06].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-03-28 09:34:55
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 23.236.230.2 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 23.236.230.2 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Mar 28 05:34:18.717277 2026] [security2:error] [pid 3256:tid 3256] [client 23.236.230.2:50643] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.neff.family.name|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.neff.family.name"] [uri "/backup.sql"] [unique_id "acegmruqJNZOwpIruhLBmgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack