๐ฉ๐ช
BlueWire Hosting
2026-10-02 13:23:14
(2 hours ago)
Aggressive scanning resulting into 404
Bad Web Bot
๐ฉ๐ช
Gwyneth Llewelyn
2026-10-02 06:45:11
(9 hours ago)
2603:3:6100:1b0:: - - [02/Oct/2026:07:45:08 +0100] "GET /mail.php HTTP/2.0" 404 994 "https://www.bes ...
show more
2603:3:6100:1b0:: - - [02/Oct/2026:07:45:08 +0100] "GET /mail.php HTTP/2.0" 404 994 "https://www.bestasquadradas.org/mail.php" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36"
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-10-02 02:17:17
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 2603:3:6100:1b0:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2603:3:6100:1b0:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 22:17:11.885278 2026] [security2:error] [pid 8907:tid 8925] [client 2603:3:6100:1b0:::0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.ajbruner.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.ajbruner.com"] [uri "/okok.cer"] [unique_id "ar8UJ4-VCFyCFmM2xj_JsgAAANA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 00:24:38
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 2603:3:6100:1b0:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2603:3:6100:1b0:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 20:24:33.669138 2026] [security2:error] [pid 17441:tid 17441] [client 2603:3:6100:1b0:::58848] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vanzant.thenewplace.org|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vanzant.thenewplace.org"] [uri "/okok.cer"] [unique_id "ar2oQRBQgx3kzsZWGz4npAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 06:46:49
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 2603:3:6100:1b0:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2603:3:6100:1b0:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 02:46:44.626203 2026] [security2:error] [pid 28399:tid 28399] [client 2603:3:6100:1b0:::55218] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sketchnotebook.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sketchnotebook.com"] [uri "/okok.cer"] [unique_id "arywVN9oq4_rtLGvrcUd_AAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-09-30 02:16:10
(2 days ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-09-30 02:04:36
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 2603:3:6100:1b0:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2603:3:6100:1b0:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 22:04:29.857806 2026] [security2:error] [pid 27662:tid 27662] [client 2603:3:6100:1b0:::44644] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||seoanalyticslocal.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "seoanalyticslocal.com"] [uri "/okok.cer"] [unique_id "arxuLX7Kprnvq0FAvHFhqwAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 00:02:57
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 2603:3:6100:1b0:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2603:3:6100:1b0:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 20:02:54.334038 2026] [security2:error] [pid 10468:tid 10468] [client 2603:3:6100:1b0:::48184] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||seagrovesrealty.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "seagrovesrealty.com"] [uri "/okok.cer"] [unique_id "arxRriJ1SoD3GordJoKikQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 20:02:21
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 2603:3:6100:1b0:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2603:3:6100:1b0:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 16:02:12.789585 2026] [security2:error] [pid 24674:tid 24674] [client 2603:3:6100:1b0:::42574] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sasquatchproductionsltd.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sasquatchproductionsltd.com"] [uri "/okok.cer"] [unique_id "arwZRAAGVelWx8KntZe96QAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 16:33:53
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 2603:3:6100:1b0:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2603:3:6100:1b0:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 12:33:49.413528 2026] [security2:error] [pid 24203:tid 24203] [client 2603:3:6100:1b0:::38496] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||missyallen.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "missyallen.com"] [uri "/okok.cer"] [unique_id "arqW7RXtoE23vi8mYBv9KAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 10:20:47
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 2603:3:6100:1b0:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2603:3:6100:1b0:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 06:20:44.050673 2026] [security2:error] [pid 29771:tid 29771] [client 2603:3:6100:1b0:::55476] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||macau-muaythai.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "macau-muaythai.com"] [uri "/okok.cer"] [unique_id "aro_fHyqtdCzy6-Rm4GL2QAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Nrbrtkls
2026-09-28 05:46:06
(4 days ago)
Vulnerability scanner blocked (444 response)
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 12:59:57
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 2603:3:6100:1b0:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2603:3:6100:1b0:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 08:59:51.122212 2026] [security2:error] [pid 3319:tid 3319] [client 2603:3:6100:1b0:::47750] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||healingtrek.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "healingtrek.com"] [uri "/okok.cer"] [unique_id "arkTRx2jPLEvRv_8nKznigAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-26 20:04:38
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 2603:3:6100:1b0:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2603:3:6100:1b0:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 26 16:04:34.427697 2026] [security2:error] [pid 19152:tid 19152] [client 2603:3:6100:1b0:::50658] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||etudesoftware.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "etudesoftware.com"] [uri "/okok.cer"] [unique_id "arglUgsmGSYY6wiez-TrIAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
AetherFox
2026-09-26 01:15:44
(6 days ago)
AetherFox VoidGuard detected: [Sat Sep 26 01:15:43.160739 2026] [authz_core:error] [pid 4167808:tid ...
show more
AetherFox VoidGuard detected: [Sat Sep 26 01:15:43.160739 2026] [authz_core:error] [pid 4167808:tid 4167844] [client 2603:3:6100:1b0:::41738] AH01630: client denied by server configuration: proxy:https://[MASKED]/, referer: https://forum.draconigen.net/
[Sat Sep 26 01:15:43.698852 2026] [authz_core:error] [pid 4167808:tid 4167848] [client 2603:3:6100:1b0:::41738] AH01630: client denied by server configuration: proxy:https://[MASKED]/d/js/acmsd/close_o.gif, referer: https://forum.draconigen.net/d/js/acmsd/close_o.gif
[Sat Sep 26 01:15:43.870164 2026] [authz_core:error] [pid 4167808:tid 4167840] [client 2603:3:6100:1b0:::41738] AH01630: client denied by server configuration: proxy:https://[MASKED]/plus/img/df_dedetitle.gif, referer: https://forum.draconigen.net/plus/img/df_dedetitle.gif
[Sat Sep 26 01:15:44.039721 2026] [authz_core:error] [pid 4167808:tid 4167853] [client 2603:3:6100:1b0:::41738] AH01630: client denied by server configuration: proxy:https://5
...
show less
Bad Web Bot
Web App Attack