๐บ๐ธ
TPI-Abuse
2026-08-23 14:08:03
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:19:1000:1d:97b8:d3c2:a3aa (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:19:1000:1d:97b8:d3c2:a3aa (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 23 10:07:56.425058 2026] [security2:error] [pid 29919:tid 29919] [client 2400:cb00:19:1000:1d:97b8:d3c2:a3aa:10954] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "autodiscover.sharawi-gum.com"] [uri "/.git/config"] [unique_id "aor-vAaQGMzwL4jvW7HdZgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 17:48:02
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:19:1000:1d:97b8:d3c2:a3aa (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:19:1000:1d:97b8:d3c2:a3aa (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 13:47:48.114314 2026] [security2:error] [pid 28459:tid 28459] [client 2400:cb00:19:1000:1d:97b8:d3c2:a3aa:11453] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.cycontechnology.com"] [uri "/.git/config"] [unique_id "aongxNECEcuT3JJxc-c0DQAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2026-08-22 17:41:01
(3 days ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐บ๐ธ
TPI-Abuse
2026-08-22 16:39:04
(3 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:19:1000:1d:97b8:d3c2:a3aa (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:19:1000:1d:97b8:d3c2:a3aa (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 12:38:56.776419 2026] [security2:error] [pid 25117:tid 25117] [client 2400:cb00:19:1000:1d:97b8:d3c2:a3aa:9896] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "webmail.hiddenhistory.info"] [uri "/.git/HEAD"] [unique_id "aonQoBC3sNs8tO3UyRyutQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-19 02:27:39
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:19:1000:1d:97b8:d3c2:a3aa (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:19:1000:1d:97b8:d3c2:a3aa (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 22:27:32.486673 2026] [security2:error] [pid 21954:tid 21954] [client 2400:cb00:19:1000:1d:97b8:d3c2:a3aa:11055] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "cpcalendars.edgewatertaxidermy.com"] [uri "/.git/config"] [unique_id "aoUUlLRhYzwQoyEYwkzMUQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-07-05 21:59:11
(1 month ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-07-04.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2025-05-06 08:48:55
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2400:cb00:19:1000:1d:97b8:d3c2:a3aa (Unknown): ...
show more
(mod_security) mod_security (id:210730) triggered by 2400:cb00:19:1000:1d:97b8:d3c2:a3aa (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue May 06 04:48:50.665191 2025] [security2:error] [pid 808843:tid 808843] [client 2400:cb00:19:1000:1d:97b8:d3c2:a3aa:54856] [client 2400:cb00:19:1000:1d:97b8:d3c2:a3aa] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.ndanetworks.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.ndanetworks.com"] [uri "/wp-content/debug.log"] [unique_id "aBnM8q7bvbuNn3tLEKlAygAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-17 14:13:59
(1 year ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:19:1000:1d:97b8:d3c2:a3aa (Unknown): ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:19:1000:1d:97b8:d3c2:a3aa (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 17 10:13:53.619658 2025] [security2:error] [pid 2685346:tid 2685346] [client 2400:cb00:19:1000:1d:97b8:d3c2:a3aa:31540] [client 2400:cb00:19:1000:1d:97b8:d3c2:a3aa] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/config/config.yml" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mail.rodrigoaldecoa.com"] [uri "/api/config/config.yml"] [unique_id "Z9guIZ4ULZfQqf9BfT_AbgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฏ๐ต
S.O.B.A. Dev.
2025-02-07 06:48:53
(1 year ago)
Persistent port scanning or vulnerability scanning
Port Scan
๐บ๐ธ
TPI-Abuse
2024-11-09 23:21:36
(1 year ago)
(mod_security) mod_security (id:240335) triggered by 2400:cb00:19:1000:1d:97b8:d3c2:a3aa (Unknown): ...
show more
(mod_security) mod_security (id:240335) triggered by 2400:cb00:19:1000:1d:97b8:d3c2:a3aa (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 09 18:21:31.411838 2024] [security2:error] [pid 1610938:tid 1610938] [client 2400:cb00:19:1000:1d:97b8:d3c2:a3aa:37552] [client 2400:cb00:19:1000:1d:97b8:d3c2:a3aa] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at IP. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "5956"] [id "240335"] [rev "5"] [msg "COMODO WAF: XML-RPC Attack Identified (CVE-2013-0235)|Source 91.134.248.249 (0+1 hits since last alert)|rodrigoaldecoa.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "rodrigoaldecoa.com"] [uri "/xmlrpc.php"] [unique_id "Zy_ue2arl9SC9U4reTtvKQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack