Anonymous
2026-06-16 18:50:06
(4 days ago)
Detected Hacking, SQL Injection or general Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 20:21:31
(1 week ago)
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 16:21:25.982243 2026] [security2:error] [pid 24460:tid 24470] [client 2600:3c15::2000:aff:fe0a:fcee:36820] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||alicefaye.com:443|F|4"] [data "CONNECT alicefaye.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "alicefaye.com"] [uri "/"] [unique_id "aiXSxSIKVd891RiHAKQ6XgAAAQg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 10:14:15
(2 weeks ago)
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 06:14:09.658144 2026] [security2:error] [pid 4367:tid 4367] [client 2600:3c15::2000:aff:fe0a:fcee:36164] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||edscontracting.com:443|F|4"] [data "CONNECT edscontracting.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "edscontracting.com"] [uri "/"] [unique_id "aiFP8fbC23EDvuOiNXRWDAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-31 03:39:13
(3 weeks ago)
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 23:39:10.283618 2026] [security2:error] [pid 23435:tid 23493] [client 2600:3c15::2000:aff:fe0a:fcee:47218] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||wpe.uk.com:2083|F|4"] [data "CONNECT wpe.uk.com:2083 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "wpe.uk.com"] [uri "/"] [unique_id "ahutXjMRtNBk4EAOUqaHcQAAAc4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-31 02:46:21
(3 weeks ago)
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 22:46:17.494498 2026] [security2:error] [pid 30432:tid 30432] [client 2600:3c15::2000:aff:fe0a:fcee:47244] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||spacebooger.com:443|F|4"] [data "CONNECT spacebooger.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "spacebooger.com"] [uri "/"] [unique_id "ahug-V2Ywi5mraZgKvW-xQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-30 22:59:46
(3 weeks ago)
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat May 30 18:59:40.839137 2026] [security2:error] [pid 26849:tid 26849] [client 2600:3c15::2000:aff:fe0a:fcee:46846] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||bodiehistory.com:443|F|4"] [data "CONNECT bodiehistory.com:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "bodiehistory.com"] [uri "/"] [unique_id "ahtr3AitfmiwbN6vAnshKQAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
xmission.com
2026-05-30 07:04:28
(3 weeks ago)
2600:3c15::2000:aff:fe0a:fcee - - [29/May/2026:20:58:17 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 ...
show more
2600:3c15::2000:aff:fe0a:fcee - - [29/May/2026:20:58:17 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
2600:3c15::2000:aff:fe0a:fcee - - [29/May/2026:21:21:32 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
2600:3c15::2000:aff:fe0a:fcee - - [29/May/2026:22:20:45 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
2600:3c15::2000:aff:fe0a:fcee - - [30/May/2026:00:37:40 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
2600:3c15::2000:aff:fe0a:fcee - - [30/May/2026:01:04:27 -0600] "CONNECT dooce.com:443 HTTP/1.1" 400 150 "-" "-"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-07 01:20:30
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:210730) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 21:20:24.123310 2026] [security2:error] [pid 787561:tid 787561] [client 2600:3c15::2000:aff:fe0a:fcee:55078] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gamepart.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gamepart.com"] [uri "/home/tancedi1/gamepart.com"] [unique_id "adRb2GDytAWHS_dvj-NEbwAAACo"], referer: http://gamepart.com/home/tancedi1/gamepart.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
Murazaki
2026-03-27 23:59:18
(2 months ago)
lemmy.balamb.fr 2600:3c15::2000:aff:fe0a:fcee - - [27/Mar/2026:08:50:21 +0100] "CONNECT lemmy.balamb ...
show more
lemmy.balamb.fr 2600:3c15::2000:aff:fe0a:fcee - - [27/Mar/2026:08:50:21 +0100] "CONNECT lemmy.balamb.fr:443 HTTP/1.1" 405 150 "-" "-" "-"
...
show less
Hacking
๐ซ๐ท
Murazaki
2026-03-25 23:47:11
(2 months ago)
lemmy.balamb.fr 2600:3c15::2000:aff:fe0a:fcee - - [25/Mar/2026:10:35:07 +0100] "CONNECT lemmy.balamb ...
show more
lemmy.balamb.fr 2600:3c15::2000:aff:fe0a:fcee - - [25/Mar/2026:10:35:07 +0100] "CONNECT lemmy.balamb.fr:443 HTTP/1.1" 405 150 "-" "-" "-"
...
show less
Hacking
๐ซ๐ท
Murazaki
2026-03-24 23:14:53
(2 months ago)
lemmy.balamb.fr 2600:3c15::2000:aff:fe0a:fcee - - [24/Mar/2026:14:10:49 +0100] "CONNECT lemmy.balamb ...
show more
lemmy.balamb.fr 2600:3c15::2000:aff:fe0a:fcee - - [24/Mar/2026:14:10:49 +0100] "CONNECT lemmy.balamb.fr:443 HTTP/1.1" 405 150 "-" "-" "-"
...
show less
Hacking
๐ซ๐ท
Murazaki
2026-03-23 23:47:42
(2 months ago)
lemmy.balamb.fr 2600:3c15::2000:aff:fe0a:fcee - - [23/Mar/2026:03:49:44 +0100] "CONNECT lemmy.balamb ...
show more
lemmy.balamb.fr 2600:3c15::2000:aff:fe0a:fcee - - [23/Mar/2026:03:49:44 +0100] "CONNECT lemmy.balamb.fr:443 HTTP/1.1" 405 150 "-" "-" "-"
...
show less
Hacking
๐บ๐ธ
TPI-Abuse
2026-03-11 18:37:47
(3 months ago)
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:217210) triggered by 2600:3c15::2000:aff:fe0a:fcee (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Mar 11 14:37:40.395897 2026] [security2:error] [pid 26626:tid 26626] [client 2600:3c15::2000:aff:fe0a:fcee:49512] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||wmionline.org:443|F|4"] [data "CONNECT wmionline.org:443 HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "wmionline.org"] [uri "/"] [unique_id "abG2dNVyi3VizXypxzCUsAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
jjnxpct
2026-02-12 04:48:55
(4 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: / (Rule ID: 911100) - Method is not allowed by policy
show less
Web App Attack
๐ณ๐ฑ
jjnxpct
2026-02-08 04:46:18
(4 months ago)
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting UR ...
show more
Automated security incident from hosting server. ModSecurity blocked suspicious request targeting URI: / (Rule ID: 911100) - Method is not allowed by policy
show less
Web App Attack