๐บ๐ธ
TPI-Abuse
2026-10-05 07:45:02
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:10c:c22::1580 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:10c:c22::1580 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 03:44:56.659372 2026] [security2:error] [pid 10708:tid 10708] [client 240e:974:e801:10c:c22::1580:54764] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||dantobinlaw.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dantobinlaw.com"] [uri "/okok.cer"] [unique_id "asNVeBgtccX_0WDS2c04uwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 07:27:49
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:10c:c22::1580 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:10c:c22::1580 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 03:27:42.992724 2026] [security2:error] [pid 20921:tid 20921] [client 240e:974:e801:10c:c22::1580:35584] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.lejzerowicz.org|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.lejzerowicz.org"] [uri "/okok.cer"] [unique_id "asCubvcN7DQDO3jZa-W89gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 03:59:58
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:10c:c22::1580 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:10c:c22::1580 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 23:59:53.190244 2026] [security2:error] [pid 20873:tid 20886] [client 240e:974:e801:10c:c22::1580:42612] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.jofdt.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.jofdt.com"] [uri "/okok.cer"] [unique_id "asB9uV2WDqfgkUTl4_Y8ugAAAMs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 12:03:42
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:10c:c22::1580 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:10c:c22::1580 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 08:03:37.045083 2026] [security2:error] [pid 14089:tid 14089] [client 240e:974:e801:10c:c22::1580:53950] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.cgi-city.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.cgi-city.com"] [uri "/okok.cer"] [unique_id "ar-dmV8fRI1_Osj_cpTWaQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
nzhost.co.nz
2026-10-02 07:23:57
(3 days ago)
$f2bV_matches
Hacking
Brute-Force
๐ธ๐ฌ
securejdprop
2026-10-01 15:41:39
(3 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing.
Hacking
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-09-30 15:58:24
(4 days ago)
240e:974:e801:10c:c22::1580 - - [30/Sep/2026:16:58:42 +0100] "GET /login8.php HTTP/1.1" 404 5619 "ht ...
show more
240e:974:e801:10c:c22::1580 - - [30/Sep/2026:16:58:42 +0100] "GET /login8.php HTTP/1.1" 404 5619 "https://trailrides-wales.com/login8.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
240e:974:e801:10c:c22::1580 - - [30/Sep/2026:16:58:42 +0100] "GET /wp-2019.php HTTP/1.1" 404 5619 "https://trailrides-wales.com/wp-2019.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
240e:974:e801:10c:c22::1580 - - [30/Sep/2026:16:58:42 +0100] "GET /logins.php HTTP/1.1" 404 5619 "https://trailrides-wales.com/logins.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 15:56:46
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:10c:c22::1580 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:10c:c22::1580 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 11:56:40.282352 2026] [security2:error] [pid 28526:tid 28526] [client 240e:974:e801:10c:c22::1580:33828] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||trailofcrumbs.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "trailofcrumbs.com"] [uri "/okok.cer"] [unique_id "ar0xOFNJbFPJGyrsw3NMtQAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
ghostwarriors
2026-09-30 12:20:06
(5 days ago)
Attempts against non-existent wp-login
Brute-Force
Web App Attack
๐ฉ๐ช
yitzhaq
2026-09-30 12:06:34
(5 days ago)
240e:974:e801:10c:c22::1580 - - [30/Sep/2026:14:06:31 +0200] "GET /statics/images/ext/dir.gif HTTP/1 ...
show more
240e:974:e801:10c:c22::1580 - - [30/Sep/2026:14:06:31 +0200] "GET /statics/images/ext/dir.gif HTTP/1.1" 404 4554 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
240e:974:e801:10c:c22::1580 - - [30/Sep/2026:14:06:31 +0200] "GET /public/ui/met/images/dt-9.gif HTTP/1.1" 404 4555 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
240e:974:e801:10c:c22::1580 - - [30/Sep/2026:14:06:31 +0200] "GET /public/images/metinfo.gif HTTP/1.1" 404 458 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
240e:974:e801:10c:c22::1580 - - [30/Sep/2026:14:06:32 +0200] "GET /zb_users/emotion/face/Music.gif HTTP/1.1" 404 458 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
240e:974:e801:10c:c22::1580 - - [30/Sep/2026:14:06:32 +0200] "GET /zb_u
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-30 02:11:45
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:10c:c22::1580 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:10c:c22::1580 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:11:38.456656 2026] [security2:error] [pid 10239:tid 10239] [client 240e:974:e801:10c:c22::1580:50438] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sentientresearch.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sentientresearch.com"] [uri "/okok.cer"] [unique_id "arxv2ibBhbtEbBhWqwQizgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 11:48:17
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:10c:c22::1580 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:10c:c22::1580 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 07:48:13.037136 2026] [security2:error] [pid 27739:tid 27739] [client 240e:974:e801:10c:c22::1580:42230] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.streetcarz.net|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.streetcarz.net"] [uri "/okok.cer"] [unique_id "arpT_fq4-7lD7cGDqK7wqwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 05:10:20
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:10c:c22::1580 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:10c:c22::1580 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 01:10:12.359626 2026] [security2:error] [pid 23927:tid 23927] [client 240e:974:e801:10c:c22::1580:55320] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||fletcherdouglas.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fletcherdouglas.com"] [uri "/okok.cer"] [unique_id "arilNKwzbzD1PotLUtt2ugAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 13:42:25
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:10c:c22::1580 (Unknown): 1 in the ...
show more
(mod_security) mod_security (id:210730) triggered by 240e:974:e801:10c:c22::1580 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 09:42:16.771159 2026] [security2:error] [pid 26735:tid 26735] [client 240e:974:e801:10c:c22::1580:53508] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||efsews.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "efsews.com"] [uri "/okok.cer"] [unique_id "arfLuNJPpnw6zA_RKGaGJAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
WizardsToolkit
2026-09-24 18:07:30
(1 week ago)
tried to access server backup files
Web App Attack