๐ซ๐ท
bigorre.org
2026-08-21 17:15:46
(4 days ago)
Forbidden access for mozilla/5.0 (compatible; googlebot/2.1; +http://www.google.com/bot.html)
Bad Web Bot
๐ซ๐ท
bigorre.org
2026-08-12 15:13:33
(1 week ago)
Forbidden access for mozilla/5.0 (compatible; googlebot/2.1; +http://www.google.com/bot.html)
Bad Web Bot
Anonymous
2026-07-29 09:45:03
(4 weeks ago)
Fake Googlebot crawler detected. The IP used the Googlebot user-agent but does not belong to Google' ...
show more
Fake Googlebot crawler detected. The IP used the Googlebot user-agent but does not belong to Google's verified crawler IP ranges.
show less
Bad Web Bot
๐ซ๐ท
bigorre.org
2026-06-22 10:36:19
(2 months ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-01-17 12:17:01
(7 months ago)
(mod_security) mod_security (id:210492) triggered by 23.27.203.132 (23-27-203-132.ips.acedatacenter. ...
show more
(mod_security) mod_security (id:210492) triggered by 23.27.203.132 (23-27-203-132.ips.acedatacenter.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 17 07:16:50.042130 2026] [security2:error] [pid 5117:tid 5117] [client 23.27.203.132:55233] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.nbcnewsradio.com"] [uri "/.env.backup"] [unique_id "aWt9smvaT_XDvYC-nENOhwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-29 19:16:35
(7 months ago)
(mod_security) mod_security (id:221260) triggered by 23.27.203.132 (23-27-203-132.ips.acedatacenter. ...
show more
(mod_security) mod_security (id:221260) triggered by 23.27.203.132 (23-27-203-132.ips.acedatacenter.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 29 14:16:20.865890 2025] [security2:error] [pid 31734:tid 31762] [client 23.27.203.132:34509] ModSecurity: Access denied with code 403 (phase 1). Pattern match "^(?:\\\\'\\\\w+?=)?\\\\(\\\\)\\\\s{" at MATCHED_VAR. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "77"] [id "221260"] [rev "3"] [msg "COMODO WAF: Shellshock Command Injection Vulnerabilities in GNU Bash through 4.3 bash43-026 (CVE-2014-7187, CVE-2014-7186, CVE-2014-7169, CVE-2014-6278, CVE-2014-6277, CVE-2014-6271)||ftp.kettlehill.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.kettlehill.net"] [uri "/cgi-bin/test"] [unique_id "aVLThGCDVM70TD0LIjvaCQAAAVU"], referer: () { ignored; }; echo Content-Type: text/html; echo ; /bin/cat /etc/passwd
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-13 10:03:46
(9 months ago)
(mod_security) mod_security (id:210492) triggered by 23.27.203.132 (23-27-203-132.ips.acedatacenter. ...
show more
(mod_security) mod_security (id:210492) triggered by 23.27.203.132 (23-27-203-132.ips.acedatacenter.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 05:03:40.909743 2025] [security2:error] [pid 11666:tid 11666] [client 23.27.203.132:37627] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.nbcnewsradio.com"] [uri "/.env.prod.local"] [unique_id "aRWs_M-CMCA7AC8NzgskSwAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-27 00:23:54
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 23.27.203.132 (23-27-203-132.ips.acedatacenter. ...
show more
(mod_security) mod_security (id:210492) triggered by 23.27.203.132 (23-27-203-132.ips.acedatacenter.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 26 20:23:34.948013 2025] [security2:error] [pid 172499:tid 172627] [client 23.27.203.132:38289] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/Web.config" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.kettlehill.net"] [uri "/web.config"] [unique_id "aIVxhoEn7YGnahfIo_jNPgAAAVU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-29 17:27:09
(1 year ago)
(mod_security) mod_security (id:211190) triggered by 23.27.203.132 (23-27-203-132.ips.acedatacenter. ...
show more
(mod_security) mod_security (id:211190) triggered by 23.27.203.132 (23-27-203-132.ips.acedatacenter.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu May 29 13:27:00.261829 2025] [security2:error] [pid 3062688:tid 3062688] [client 23.27.203.132:38799] ModSecurity: Access denied with code 403 (phase 2). Match of "contains cpanel" against "REQUEST_URI" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "55"] [id "211190"] [rev "9"] [msg "COMODO WAF: Remote File Access Attempt||ftp.farmers123.com|F|2"] [data "Matched Data: /etc/ found within REQUEST_URI: /cgi-bin/koha/svc/virtualshelves/search?template_path=..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "ftp.farmers123.com"] [uri "/cgi-bin/koha/svc/virtualshelves/search"] [unique_id "aDiY5FEqn4wGHjLdG6yHTAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-05-04 08:47:06
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 23.27.203.132 (23-27-203-132.ips.acedatacenter. ...
show more
(mod_security) mod_security (id:210492) triggered by 23.27.203.132 (23-27-203-132.ips.acedatacenter.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 04 04:47:02.934558 2025] [security2:error] [pid 3771329:tid 3771329] [client 23.27.203.132:51139] [client 23.27.203.132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpanel.nbcnewsradio.com"] [uri "/.env.dev"] [unique_id "aBcphmL2EKbKXbr045Kp0QAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-19 05:31:32
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 23.27.203.132 (23-27-203-132.ips.acedatacenter. ...
show more
(mod_security) mod_security (id:210492) triggered by 23.27.203.132 (23-27-203-132.ips.acedatacenter.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 19 01:30:27.746538 2025] [security2:error] [pid 22650:tid 22675] [client 23.27.203.132:60063] [client 23.27.203.132] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "blog.spinningdesigns.com"] [uri "/.env_1"] [unique_id "aAM088LYwl69KqC_78idQAAAAFY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-17 15:50:40
(1 year ago)
| A web attack returned code 200 (success).
Hacking
SQL Injection
Web App Attack