๐บ๐ธ
TPI-Abuse
2026-10-06 03:20:27
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown ...
show more
(mod_security) mod_security (id:210730) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 23:20:22.501352 2026] [security2:error] [pid 13225:tid 13225] [client 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2:10572] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||shawnlayne.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "shawnlayne.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asRo9qExG8oSIVPpSDS_RgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 07:04:43
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 03:04:37.562919 2026] [security2:error] [pid 10803:tid 10803] [client 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2:9684] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.register-yacht-cayman.com"] [uri "/.env.backup"] [unique_id "asH6hUj28V3OBVG9i_EPHgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 06:36:17
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 02:36:10.039659 2026] [security2:error] [pid 12071:tid 12071] [client 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2:12113] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "sinko-intl.com"] [uri "/.env.old"] [unique_id "asHz2iVePJm1keSAFlp3NQAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-04 03:13:52
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 23:13:48.987013 2026] [security2:error] [pid 9757:tid 9757] [client 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2:11600] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "landjudging.com"] [uri "/.git/HEAD"] [unique_id "asHEbI9FXXNS9c9PNCTEHgAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 19:06:09
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 15:06:00.510742 2026] [security2:error] [pid 14926:tid 14926] [client 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2:14044] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.blackoakprop.com"] [uri "/.git/config"] [unique_id "ar6vGEh5V2WDgAjnsZGm5QAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:38:17
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:38:13.819430 2026] [security2:error] [pid 13951:tid 13951] [client 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2:13394] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.aden.us"] [uri "/wp-config.php.bak"] [unique_id "ar0s5fG04BFGRT7vqyj9-AAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 22:31:28
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 18:31:20.247993 2026] [security2:error] [pid 30043:tid 30043] [client 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2:10917] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "bentonflybox.com"] [uri "/wp-config.php"] [unique_id "arw8OEZESIKmJ3rIZtDjQgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 20:31:07
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:31:01.563736 2026] [security2:error] [pid 3727:tid 3727] [client 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2:12035] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.wendeenicole.com"] [uri "/.htaccess"] [unique_id "arwgBYUehFubZHrJlzJzHgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 10:36:20
(6 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 06:36:16.172634 2026] [security2:error] [pid 30186:tid 30186] [client 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2:12516] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "nebraskaadaptivesports.org"] [uri "/.env"] [unique_id "aruUoA1PUkERBZ3yxPKlIQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 08:09:52
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 04:09:47.705427 2026] [security2:error] [pid 14649:tid 14649] [client 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2:12210] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.muslera.com"] [uri "/wp-config.php"] [unique_id "arogy-203pDe02DsNG1pJgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 11:40:33
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown ...
show more
(mod_security) mod_security (id:949110) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 07:40:27.963967 2026] [security2:error] [pid 31367:tid 31367] [client 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2:13477] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "clintess.biz"] [uri "/.git/config"] [unique_id "arevKyfA3wwfH6HSsppDpAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 09:59:16
(1 week ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 05:59:09.497773 2026] [security2:error] [pid 27006:tid 27006] [client 2400:cb00:555:1000:3d6f:cafc:c0ab:d4b2:13018] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "old.renju.net"] [uri "/.env.local"] [unique_id "areXbVQFhJy4nKgFLeC-GAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
homeshowdomain.nl
2026-06-06 22:00:32
(3 months ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-06-05.
show less
Web App Attack
SSH
Hacking
๐ฏ๐ต
S.O.B.A. Dev.
2025-11-25 20:01:46
(10 months ago)
Persistent port scanning or vulnerability scanning
Port Scan