๐ซ๐ท
Bensay
2026-10-08 19:59:06
(3 hours ago)
Repeated suspicious HTTP service scan against a blocked web sinkhole; threshold=3 events/10m; result ...
show more
Repeated suspicious HTTP service scan against a blocked web sinkhole; threshold=3 events/10m; result=blocked; user-agent=unknown
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-08 18:34:35
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown ...
show more
(mod_security) mod_security (id:210730) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 14:34:31.429895 2026] [security2:error] [pid 13948:tid 13948] [client 2400:cb00:994:1000:e7b0:ebee:8cef:14d2:10047] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||syscomprint.com|F|2"] [data ".php.bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "syscomprint.com"] [uri "/index.php.bak"] [unique_id "asfiN9xAS0Q0o0jrw7NH6AAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Bensay
2026-10-08 16:25:19
(6 hours ago)
Repeated suspicious HTTP service scan against a blocked web sinkhole; threshold=3 events/10m; result ...
show more
Repeated suspicious HTTP service scan against a blocked web sinkhole; threshold=3 events/10m; result=blocked; user-agent=Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/122.0.0.0 Safari/537.36 Edg/122.0.0.0
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-08 14:16:54
(9 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 10:16:48.440116 2026] [security2:error] [pid 5476:tid 5497] [client 2400:cb00:994:1000:e7b0:ebee:8cef:14d2:11671] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "amazinglips.com"] [uri "/.env.bak"] [unique_id "asel0FCPQC07dxoNtXFRhAAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-08 10:52:35
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 06:52:28.204809 2026] [security2:error] [pid 32604:tid 32604] [client 2400:cb00:994:1000:e7b0:ebee:8cef:14d2:13497] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "mdivietnam.com"] [uri "/wp-config.php"] [unique_id "asd17EMUqivIKGOnCdpoCgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
sonot
2026-10-08 02:27:33
(20 hours ago)
Blocked by UFW on mail [8880/tcp] | SPT: 12071 | TTL: null | LEN: 80 | TOS: null โข Reported by: gith ...
show more
Blocked by UFW on mail [8880/tcp] | SPT: 12071 | TTL: null | LEN: 80 | TOS: null โข Reported by: github.com/sefinek/UFW-AbuseIPDB-Reporter
show less
Port Scan
๐บ๐ธ
TPI-Abuse
2026-10-08 00:12:27
(23 hours ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 20:12:19.459674 2026] [security2:error] [pid 24475:tid 24475] [client 2400:cb00:994:1000:e7b0:ebee:8cef:14d2:10561] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "almudenastrust.com"] [uri "/.env"] [unique_id "asbf4xbNRG4fU0heoNy1DQAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 19:02:25
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 15:02:18.934582 2026] [security2:error] [pid 27055:tid 27055] [client 2400:cb00:994:1000:e7b0:ebee:8cef:14d2:12857] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "stevescottcoaching.com"] [uri "/.env.local"] [unique_id "asaXOqPa9wASIzOkfic9MAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 09:19:07
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 05:19:01.689086 2026] [security2:error] [pid 20004:tid 20004] [client 2400:cb00:994:1000:e7b0:ebee:8cef:14d2:12750] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "davidtempleofdeliverance.org"] [uri "/.env.old"] [unique_id "asYOhQhKPqIfFGFlw03_YQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 07:13:51
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 07 03:13:48.089447 2026] [security2:error] [pid 7683:tid 7683] [client 2400:cb00:994:1000:e7b0:ebee:8cef:14d2:10739] ModSecurity: Access denied with code 403 (phase 1). Matched phrase ".htaccess" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "120"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "3n1ent.com"] [uri "/.htaccess"] [unique_id "asXxLIAM1YAg_MgPMn795wAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-07 02:52:15
(1 day ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 22:52:11.268061 2026] [security2:error] [pid 26189:tid 26199] [client 2400:cb00:994:1000:e7b0:ebee:8cef:14d2:12107] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "lasertagmetairie.com"] [uri "/.env.old"] [unique_id "asWz28TPbK5yUswcEmMoXgAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 14:00:31
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 10:00:28.483096 2026] [security2:error] [pid 30572:tid 30572] [client 2400:cb00:994:1000:e7b0:ebee:8cef:14d2:10408] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "officechristmascards.com"] [uri "/.env.backup"] [unique_id "asT-_Cxj9eOuIJvrI8MoMgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 09:28:20
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown ...
show more
(mod_security) mod_security (id:210730) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 05:28:15.245576 2026] [security2:error] [pid 5801:tid 5801] [client 2400:cb00:994:1000:e7b0:ebee:8cef:14d2:10310] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||drayvian.com|F|2"] [data ".tfstate.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "drayvian.com"] [uri "/.terraform/terraform.tfstate.backup"] [unique_id "asS_L4G2B4ltVSjuK2d0JwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 08:48:32
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 04:48:29.324193 2026] [security2:error] [pid 8352:tid 8352] [client 2400:cb00:994:1000:e7b0:ebee:8cef:14d2:11371] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "fingercult.com"] [uri "/.git/config"] [unique_id "asS13VUjxi-WiVGon28xdgAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-06 01:09:00
(2 days ago)
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown ...
show more
(mod_security) mod_security (id:210492) triggered by 2400:cb00:994:1000:e7b0:ebee:8cef:14d2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 21:08:54.532413 2026] [security2:error] [pid 14636:tid 14636] [client 2400:cb00:994:1000:e7b0:ebee:8cef:14d2:10023] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "radiointernational.net"] [uri "/.env.backup"] [unique_id "asRKJieZ4iEjVU-f0OkCUQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack