🇺🇸
TPI-Abuse
2026-09-21 08:10:39
(6 hours ago)
(mod_security) mod_security (id:210831) triggered by 27.54.169.89 (undefined.hostname.localhost): 1 ...
show more
(mod_security) mod_security (id:210831) triggered by 27.54.169.89 (undefined.hostname.localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 04:10:31.457522 2026] [security2:error] [pid 20504:tid 20504] [client 27.54.169.89:13343] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.advantagesystemsgroup.com|F|4"] [data "ContactBot/"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.advantagesystemsgroup.com"] [uri "/"] [unique_id "arDmdzl8VVTXPspnzAiE2wAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-21 07:10:46
(7 hours ago)
(mod_security) mod_security (id:210831) triggered by 27.54.169.89 (undefined.hostname.localhost): 1 ...
show more
(mod_security) mod_security (id:210831) triggered by 27.54.169.89 (undefined.hostname.localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 21 03:10:38.938618 2026] [security2:error] [pid 7348:tid 7348] [client 27.54.169.89:8165] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.gpaarch.com|F|4"] [data "ContactBot/"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.gpaarch.com"] [uri "/"] [unique_id "arDYbvavjTBCoEtmADk_0wAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-18 11:15:44
(3 days ago)
(mod_security) mod_security (id:210831) triggered by 27.54.169.89 (undefined.hostname.localhost): 1 ...
show more
(mod_security) mod_security (id:210831) triggered by 27.54.169.89 (undefined.hostname.localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 18 07:15:39.841081 2026] [security2:error] [pid 11632:tid 11632] [client 27.54.169.89:19971] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.carminestogo.com|F|4"] [data "ContactBot/"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.carminestogo.com"] [uri "/"] [unique_id "aq0dW8X0dtqOLew-fVUqJQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-16 10:19:57
(5 days ago)
(mod_security) mod_security (id:210831) triggered by 27.54.169.89 (undefined.hostname.localhost): 1 ...
show more
(mod_security) mod_security (id:210831) triggered by 27.54.169.89 (undefined.hostname.localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 06:19:50.418743 2026] [security2:error] [pid 23481:tid 23481] [client 27.54.169.89:17564] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.salinabible.org|F|4"] [data "ContactBot/"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.salinabible.org"] [uri "/"] [unique_id "aqptRgbIipPvITBpNEVDcAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
nyt
2026-09-08 13:28:48
(1 week ago)
Email Scraper UA
Web App Attack
Anonymous
2026-08-20 09:28:45
(1 month ago)
FortiWeb WAF: 67 attacks detected. Threat Score: 5200. Types: Known Bots Detection(26), Client Manag ...
show more
FortiWeb WAF: 67 attacks detected. Threat Score: 5200. Types: Known Bots Detection(26), Client Management(25), HTTP Protocol Constraints(16). Origin: India.
show less
Bad Web Bot
Anonymous
2026-08-07 09:23:47
(1 month ago)
FortiWeb WAF: 86 attacks detected. Threat Score: 10600. Types: Client Management(35), Known Bots Det ...
show more
FortiWeb WAF: 86 attacks detected. Threat Score: 10600. Types: Client Management(35), Known Bots Detection(35), HTTP Protocol Constraints(16). Origin: India.
show less
Bad Web Bot
🇺🇸
TPI-Abuse
2026-07-21 20:05:19
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 27.54.169.89 (undefined.hostname.localhost): 1 ...
show more
(mod_security) mod_security (id:210831) triggered by 27.54.169.89 (undefined.hostname.localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 16:05:13.996962 2026] [security2:error] [pid 32176:tid 32189] [client 27.54.169.89:9189] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.titanweb.com|F|4"] [data "ContactBot/"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.titanweb.com"] [uri "/"] [unique_id "al_Q-TMDI0ts7hUNLtn7SwAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-21 18:02:29
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 27.54.169.89 (undefined.hostname.localhost): 1 ...
show more
(mod_security) mod_security (id:210831) triggered by 27.54.169.89 (undefined.hostname.localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 21 14:02:23.468764 2026] [security2:error] [pid 14397:tid 14397] [client 27.54.169.89:19314] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.banapest.com|F|4"] [data "ContactBot/"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.banapest.com"] [uri "/"] [unique_id "al-0L6G6C84jXhQW-0e6ZAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-20 13:46:51
(2 months ago)
(mod_security) mod_security (id:210831) triggered by 27.54.169.89 (undefined.hostname.localhost): 1 ...
show more
(mod_security) mod_security (id:210831) triggered by 27.54.169.89 (undefined.hostname.localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 20 09:46:44.398684 2026] [security2:error] [pid 29732:tid 29732] [client 27.54.169.89:6891] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.mcacpas.com|F|4"] [data "ContactBot/"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.mcacpas.com"] [uri "/"] [unique_id "al4mxEtUp1IWixyekqCr5gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-11 14:12:08
(2 months ago)
(mod_security) mod_security (id:210831) triggered by 27.54.169.89 (undefined.hostname.localhost): 1 ...
show more
(mod_security) mod_security (id:210831) triggered by 27.54.169.89 (undefined.hostname.localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 10:12:02.509722 2026] [security2:error] [pid 13891:tid 13891] [client 27.54.169.89:3535] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.compmansys.com|F|4"] [data "ContactBot/"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.compmansys.com"] [uri "/"] [unique_id "alJPMv_zbI3AOA0axOYWhAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-11 13:29:18
(2 months ago)
(mod_security) mod_security (id:210831) triggered by 27.54.169.89 (undefined.hostname.localhost): 1 ...
show more
(mod_security) mod_security (id:210831) triggered by 27.54.169.89 (undefined.hostname.localhost): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 11 09:29:13.260135 2026] [security2:error] [pid 2378:tid 2378] [client 27.54.169.89:19371] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.arriagarealestate.com|F|4"] [data "ContactBot/"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.arriagarealestate.com"] [uri "/"] [unique_id "alJFKWlqAqLio9EXawNZPAAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇷🇸
Smel
2021-06-10 02:53:41
(5 years ago)
MultiHost/MultiPort Probe, Scan, Hack -
Port Scan
Hacking