๐บ๐ธ
TPI-Abuse
2026-09-03 23:33:26
(1 hour ago)
(mod_security) mod_security (id:210492) triggered by 24.199.108.195 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210492) triggered by 24.199.108.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 19:33:19.889140 2026] [security2:error] [pid 3802:tid 3802] [client 24.199.108.195:45432] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "brittb.com"] [uri "/bak.htaccess"] [unique_id "apoDv7g49XtxdGsyzua2qAAAACc"], referer: https://www.google.com/search?q=brittb
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 21:13:44
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 24.199.108.195 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 24.199.108.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 17:13:36.148137 2026] [security2:error] [pid 805:tid 1014] [client 24.199.108.195:54216] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gafm.org|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gafm.org"] [uri "/http/charteredfinancialmanager.com"] [unique_id "apnjAFuQPnP8mn7ZIkb_wwAAAMk"], referer: https://www.google.com/search?q=gafm
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
mscode.pl
2026-09-03 18:53:49
(6 hours ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 14061 (DigitalOcean, LLC ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 14061 (DigitalOcean, LLC)
Protocol: HTTP/2 (GET method)
Zone: ankiety.mscode.pl
Endpoint: /
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/143.0.0.0 Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
gerensat
2026-09-03 07:32:12
(17 hours ago)
2026-09-03 04:32:12 | /auth/recuperar | [] | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWe ...
show more
2026-09-03 04:32:12 | /auth/recuperar | [] | Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-03 05:59:06
(19 hours ago)
(mod_security) mod_security (id:210730) triggered by 24.199.108.195 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 24.199.108.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 01:59:02.442421 2026] [security2:error] [pid 10959:tid 10959] [client 24.199.108.195:59714] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.phantomkennels.com|F|2"] [data "[email protected] "] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.phantomkennels.com"] [uri "/[email protected] "] [unique_id "apkMpnP-G2TC9KhOCHknIQAAAAk"], referer: https://www.google.com/search?q=phantomkennels
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-02 20:03:01
(1 day ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
ASN: 14061 (Digit ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: MANAGED_CHALLENGE
ASN: 14061 (DigitalOcean, LLC)
Protocol: HTTP/2 (GET method)
Endpoint: /
Timestamp: 2026-09-02T19:28:41Z
Ray ID: a34eeb564f0638ce
UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36
show less
Bad Web Bot
๐ฉ๐ช
bazter.pro
2026-09-02 18:28:51
(1 day ago)
Auto-Ban [2026-09-02 18:28:51]: CRITICAL: bot trap (soft) | host=www.geoproceso.com | route=/api/tra ...
show more
Auto-Ban [2026-09-02 18:28:51]: CRITICAL: bot trap (soft) | host=www.geoproceso.com | route=/api/trap/internal/reviews-sync | hits=1 | ua=Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like
show less
Hacking
Web App Attack
๐ต๐ฑ
Budyn
2026-09-02 16:10:46
(1 day ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: goblinpot.website | URI: /.git/HEAD | UA: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/141.0.0.0 Safari/537.36 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐จ๐ญ
backslash
2026-09-02 08:21:00
(1 day ago)
block ruleset CC531825F9395F9A07FB06C1247C46770A2690F8
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-02 07:04:37
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 24.199.108.195 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 24.199.108.195 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 02 03:04:31.431556 2026] [security2:error] [pid 6211:tid 6211] [client 24.199.108.195:49970] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cameronsol.com|F|2"] [data ".camairhvac.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cameronsol.com"] [uri "/www.camairhvac.com"] [unique_id "apfKf4kZpbpHs3JdHwNrqAAAAA8"], referer: https://www.google.com/search?q=cameronsol
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-18 06:43:28
(2 weeks ago)
Blocked by firewall on hugin [11111/tcp] | Rule: UFW | SPT: 61008 | TTL: 238 | LEN: 44 | TOS: 0x00 โข ...
show more
Blocked by firewall on hugin [11111/tcp] | Rule: UFW | SPT: 61008 | TTL: 238 | LEN: 44 | TOS: 0x00 โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan