๐บ๐ธ
TPI-Abuse
2026-10-08 11:59:26
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): ...
show more
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 08 07:59:19.224239 2026] [security2:error] [pid 13498:tid 13498] [client 2404:ccc0:263:102:5054:ff:fef8:d42a:56374] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||theopinionatedowl.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "theopinionatedowl.com"] [uri "/okok.cer"] [unique_id "aseFl627Uujis_XgCcGBpwAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-05 13:23:47
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): ...
show more
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 09:23:42.102473 2026] [security2:error] [pid 827:tid 827] [client 2404:ccc0:263:102:5054:ff:fef8:d42a:48558] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||elearning.nextngnr.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "elearning.nextngnr.com"] [uri "/okok.cer"] [unique_id "asOk3kqUm-PnLl1re3bp2QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 17:46:16
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): ...
show more
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 13:46:11.532597 2026] [security2:error] [pid 14969:tid 14969] [client 2404:ccc0:263:102:5054:ff:fef8:d42a:48636] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.divingmachines.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.divingmachines.com"] [uri "/okok.cer"] [unique_id "ar_t4_mGj5SODyTaF773TQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 05:11:52
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): ...
show more
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 01:11:49.684846 2026] [security2:error] [pid 6558:tid 6558] [client 2404:ccc0:263:102:5054:ff:fef8:d42a:53380] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bandsolution.net|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bandsolution.net"] [uri "/okok.cer"] [unique_id "ar89FdnNusvaTDhlutAZ3wAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 09:33:02
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): ...
show more
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 05:32:53.507738 2026] [security2:error] [pid 17124:tid 17124] [client 2404:ccc0:263:102:5054:ff:fef8:d42a:40120] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||webjemm.net|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "webjemm.net"] [uri "/okok.cer"] [unique_id "ar4oxWUVpIfXEmq7n1EnywAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
[email protected]
2026-10-01 00:37:38
(1 week ago)
CrowdSec ban: crowdsecurity/http-backdoors-attempts (duration: 71h59m56s)
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 05:06:00
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): ...
show more
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 01:05:55.516840 2026] [security2:error] [pid 16031:tid 16031] [client 2404:ccc0:263:102:5054:ff:fef8:d42a:44896] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||shofarmusic.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "shofarmusic.com"] [uri "/okok.cer"] [unique_id "aryYs2iOQEE8Ndk503rfJwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
Charlesiv
2026-09-29 06:00:48
(1 week ago)
Triggered Cloudflare WAF (firewallCustom) from HK.
Action taken: BLOCK
ASN: 139021 (West263 Internat ...
show more
Triggered Cloudflare WAF (firewallCustom) from HK.
Action taken: BLOCK
ASN: 139021 (West263 International Limited)
Protocol: HTTP/1.1 (GET method)
Endpoint: /static/warn/close.php
Timestamp: 2026-09-29T05:13:58Z
Ray ID: a428806d2b09850e
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-28 15:11:58
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): ...
show more
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 11:11:55.146395 2026] [security2:error] [pid 14902:tid 14927] [client 2404:ccc0:263:102:5054:ff:fef8:d42a:39854] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||merart.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "merart.com"] [uri "/okok.cer"] [unique_id "arqDuxy1RjWljWFPqFCcQAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 14:20:17
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): ...
show more
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 10:20:14.352731 2026] [security2:error] [pid 26659:tid 26659] [client 2404:ccc0:263:102:5054:ff:fef8:d42a:51476] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||meghanmack.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "meghanmack.com"] [uri "/okok.cer"] [unique_id "arp3nnEj67gyYO1Bpx5PRwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 20:11:48
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): ...
show more
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 16:11:42.424407 2026] [security2:error] [pid 6141:tid 6141] [client 2404:ccc0:263:102:5054:ff:fef8:d42a:37086] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||khovanov.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "khovanov.com"] [uri "/okok.cer"] [unique_id "arl4fmsYeAAPWOd6wveKGAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-27 08:58:45
(1 week ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-26 03:08:16
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): ...
show more
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 23:08:09.862310 2026] [security2:error] [pid 17873:tid 17873] [client 2404:ccc0:263:102:5054:ff:fef8:d42a:45910] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||doreenkimura.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "doreenkimura.com"] [uri "/okok.cer"] [unique_id "arc3GW4e0v871BZr4ReEjgAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 09:44:15
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): ...
show more
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 05:44:11.307419 2026] [security2:error] [pid 10161:tid 10161] [client 2404:ccc0:263:102:5054:ff:fef8:d42a:45994] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dentsville398.org|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dentsville398.org"] [uri "/okok.cer"] [unique_id "arZCa3nrGF459blp7pNNDwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 04:52:31
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): ...
show more
(mod_security) mod_security (id:210730) triggered by 2404:ccc0:263:102:5054:ff:fef8:d42a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 25 00:52:23.358489 2026] [security2:error] [pid 13274:tid 13274] [client 2404:ccc0:263:102:5054:ff:fef8:d42a:52472] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||deborbonfoundation.org|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "deborbonfoundation.org"] [uri "/okok.cer"] [unique_id "arX-ByOO3uPMUJhngQsrdwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack