🇪🇸
librebit
2026-09-08 02:15:45
(5 days ago)
Bad guys doing bad things, bad crawling
Bad Web Bot
🇺🇸
factor1
2026-09-07 23:31:31
(5 days ago)
CrowdSec at apollo Reports Abuse
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 23:31:27
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 2602:fa59:5:62::1 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:fa59:5:62::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 19:31:22.836437 2026] [security2:error] [pid 24867:tid 24867] [client 2602:fa59:5:62::1:49790] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||soulwolf.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "soulwolf.com"] [uri "/storage/logs/laravel.log"] [unique_id "ap9JSqBbafUzFpAffATYwQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-09-07 23:19:37
(5 days ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-09-07 23:16:18
(5 days ago)
(mod_security) mod_security (id:210492) triggered by 2602:fa59:5:62::1 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 2602:fa59:5:62::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 19:16:11.273718 2026] [security2:error] [pid 32703:tid 32703] [client 2602:fa59:5:62::1:41358] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "modernsalessolutions.com"] [uri "/.git/config"] [unique_id "ap9Fu5XzMYHp4gVa_AoS0wAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-04 01:09:40
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2602:fa59:5:62::1 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:fa59:5:62::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 21:09:31.201318 2026] [security2:error] [pid 4846:tid 4846] [client 2602:fa59:5:62::1:44128] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mcarrollcommunications.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mcarrollcommunications.com"] [uri "/storage/logs/laravel.log"] [unique_id "apoaSxs6-R_lntZ8W5WwMQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
LRob
2026-09-04 00:55:18
(1 week ago)
Enumerating paths that do not exist (scanning) | method: GET | path: /info.php | ua: Mozilla/5.0 (Ma ...
show more
Enumerating paths that do not exist (scanning) | method: GET | path: /info.php | ua: Mozilla/5.0 (Macintosh; Intel Mac OS X 10.15; rv:126.0) Gecko/20100101 Firefox/126.0 | 2026-09-04 00:55 UTC
show less
Port Scan
Web App Attack
🇺🇸
www.winos.me
2026-09-03 23:21:38
(1 week ago)
Malicious bot scraper
Port Scan
Bad Web Bot
🇳🇱
Site.eu
2026-09-03 20:42:26
(1 week ago)
Excessive multi-domain requests
Brute-Force
🇩🇪
maxpower
2026-09-03 20:26:36
(1 week ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 2602:fa59:5:62::1 (-): 1 in the last 360 ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 2602:fa59:5:62::1 (-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2602:fa59:5:62::1 - - [03/Sep/2026:22:26:34 +0200] "GET /.aws/credentials HTTP/1.1" 200 4735 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36" "173.26.168.140" host=kleos81.com
show less
Port Scan
🇩🇪
KP_Security
2026-09-03 20:04:55
(1 week ago)
Automated web application attack detected. Rules: DET-IGNITION-EXEC, DET-SPRING-HEAP, DET-SPRING-ENV ...
show more
Automated web application attack detected. Rules: DET-IGNITION-EXEC, DET-SPRING-HEAP, DET-SPRING-ENV, DET-AWS-CREDS, DET-AWS-CONFIG, DET-WP-CONFIG, DET-WP-CONTENT. Evidence: 365.
show less
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 19:39:33
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2602:fa59:5:62::1 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:fa59:5:62::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 15:39:28.644378 2026] [security2:error] [pid 19182:tid 19182] [client 2602:fa59:5:62::1:40670] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||trlservice.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "trlservice.com"] [uri "/storage/logs/laravel.log"] [unique_id "apnM8De5eMEbVCjdjDtgFAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-03 19:22:46
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2602:fa59:5:62::1 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:fa59:5:62::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 15:22:39.396708 2026] [security2:error] [pid 1591161:tid 1591198] [client 2602:fa59:5:62::1:36526] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||transitionalcareservices.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "transitionalcareservices.com"] [uri "/storage/logs/laravel.log"] [unique_id "apnI_y9AW-EQ-tMLAGve7wAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇧🇪
cmbplf
2026-09-03 18:39:56
(1 week ago)
534 requests with url.path *config.php
102 requests with url.path *secrets.json
Brute-Force
Bad Web Bot
🇺🇸
TPI-Abuse
2026-09-03 17:13:58
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2602:fa59:5:62::1 (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2602:fa59:5:62::1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 03 13:13:52.216465 2026] [security2:error] [pid 10318:tid 10318] [client 2602:fa59:5:62::1:48850] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||televisonic.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "televisonic.com"] [uri "/storage/logs/laravel.log"] [unique_id "apmq0GxolvtxtDYiOCanAwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack