πΊπΈ
LotPhantom
2026-07-31 20:44:22
(1 month ago)
2a01:4f8:151:841e::2 - - [31/Jul/2026:20:43:51 +0000] "GET /services/technologies/nitrous-oxide HTTP ...
show more
2a01:4f8:151:841e::2 - - [31/Jul/2026:20:43:51 +0000] "GET /services/technologies/nitrous-oxide HTTP/1.1" 404 9 "-" "\x22Google Chrome\x22;v=\x22135\x22, \x22Not-A.Brand\x22;v=\x228\x22, \x22Chromium\x22;v=\x22135\x22"
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-16 08:51:44
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:151:841e::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:151:841e::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 16 04:51:36.036491 2026] [security2:error] [pid 16317:tid 16317] [client 2a01:4f8:151:841e::2:64530] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.dalessalesandservice.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.dalessalesandservice.com"] [uri "/central-vacuums/[email protected] "] [unique_id "alibmKm6-eS6puxkgGfNcAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
SCHAPPY
2026-07-16 08:30:09
(2 months ago)
Excessive crawling, scraping, request limit exceeded, HTTP code 429.
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-15 13:24:40
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:151:841e::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:151:841e::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 15 09:24:32.165462 2026] [security2:error] [pid 3583:tid 3583] [client 2a01:4f8:151:841e::2:43000] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.aaabft.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.aaabft.com"] [uri "/[email protected] "] [unique_id "aleKELcqM81osieTNNHKHAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-14 11:07:03
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:151:841e::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:151:841e::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 14 07:06:57.234248 2026] [security2:error] [pid 21875:tid 21875] [client 2a01:4f8:151:841e::2:36034] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.citystreetsalon.com|F|2"] [data ".fionnardesign.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.citystreetsalon.com"] [uri "/www.fionnardesign.com"] [unique_id "alYYUVLyBw-iw9rip93T5QAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π§πͺ
cmbplf
2026-07-11 12:04:02
(2 months ago)
6.552 requests in 1 hour (3d17h59m)
Brute-Force
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-06-22 18:16:39
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:151:841e::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:151:841e::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 14:16:35.408570 2026] [security2:error] [pid 18098:tid 18098] [client 2a01:4f8:151:841e::2:49310] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.citystreetsalon.com|F|2"] [data ".fionnardesign.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.citystreetsalon.com"] [uri "/www.fionnardesign.com"] [unique_id "ajl8A8Bg5NJc3fL_qOosNgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-22 02:43:50
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:151:841e::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:151:841e::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 22:43:43.721708 2026] [security2:error] [pid 886:tid 886] [client 2a01:4f8:151:841e::2:16896] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.aaabft.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.aaabft.com"] [uri "/[email protected] "] [unique_id "ajihX3cRudIZzG6HLwtUzAAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
LotPhantom
2026-06-20 07:44:01
(3 months ago)
2a01:4f8:151:841e::2 - - [20/Jun/2026:07:43:51 +0000] "GET /services/technologies/nitrous-oxide HTTP ...
show more
2a01:4f8:151:841e::2 - - [20/Jun/2026:07:43:51 +0000] "GET /services/technologies/nitrous-oxide HTTP/1.1" 404 9 "-" "\x22Google Chrome\x22;v=\x22135\x22, \x22Not-A.Brand\x22;v=\x228\x22, \x22Chromium\x22;v=\x22135\x22"
...
show less
Web App Attack
π¨π
SOC [GOLINE SA]
2026-05-30 11:02:16
(3 months ago)
IDS Alert: IDS High-Severity Alert === ATTACK === Signature: IDS High-Severity Alert | SID: N/A | Se ...
show more
IDS Alert: IDS High-Severity Alert === ATTACK === Signature: IDS High-Severity Alert | SID: N/A | Severity: 1-2 | Category: Security Threat === SOURCE === IP: 2a01:4f8:151:841e::2 (IPv6) | Port: N/A | Country: Germany | ISP: HOS-431311 | rDNS: None === TARGET === Host: lg.goline.ch | IP: lg.goline.ch | Port: multiple | Protocol: TCP/UDP | App: N/A === RESPONSE === Time: 2026-05-30 13:02:16 | Action: Blocked
show less
Port Scan
Hacking
Bad Web Bot
π§πͺ
cmbplf
2026-05-24 18:02:21
(4 months ago)
7.738 requests in 1 hour (3d7h59m)
Brute-Force
Bad Web Bot
πΊπΈ
LotPhantom
2026-05-09 14:27:20
(4 months ago)
2026/05/09 14:27:19 [error] 2526858#2526858: *94281 connect() failed (111: Connection refused) while ...
show more
2026/05/09 14:27:19 [error] 2526858#2526858: *94281 connect() failed (111: Connection refused) while connecting to upstream, client: 2a01:4f8:151:841e::2, server: wynnesmiles.com, request: "GET / HTTP/1.1", upstream: "http://127.0.0.1:4001/", host: "wynnesmiles.com"
...
show less
Web App Attack
π¨π
SOC [GOLINE SA]
2026-04-30 22:23:21
(4 months ago)
IDS Alert: IDS High-Severity Alert === ATTACK === Signature: IDS High-Severity Alert | SID: N/A | Se ...
show more
IDS Alert: IDS High-Severity Alert === ATTACK === Signature: IDS High-Severity Alert | SID: N/A | Severity: 1-2 | Category: Security Threat === SOURCE === IP: 2a01:4f8:151:841e::2 (IPv6) | Port: N/A | Country: Germany | ISP: HOS-431311 | rDNS: None === TARGET === Host: lg.goline.ch | IP: lg.goline.ch | Port: multiple | Protocol: TCP/UDP | App: N/A === RESPONSE === Time: 2026-05-01 00:23:20 | Action: Blocked
show less
Port Scan
Hacking
Bad Web Bot
π¨π
SOC [GOLINE SA]
2026-04-30 17:11:14
(4 months ago)
IDS Alert: IDS High-Severity Alert === ATTACK === Signature: IDS High-Severity Alert | SID: N/A | Se ...
show more
IDS Alert: IDS High-Severity Alert === ATTACK === Signature: IDS High-Severity Alert | SID: N/A | Severity: 1-2 | Category: Security Threat === SOURCE === IP: 2a01:4f8:151:841e::2 (IPv6) | Port: N/A | Country: Germany | ISP: HOS-431311 | rDNS: None === TARGET === Host: lg.goline.ch | IP: lg.goline.ch | Port: multiple | Protocol: TCP/UDP | App: N/A === RESPONSE === Time: 2026-04-30 19:11:14 | Action: Blocked
show less
Port Scan
Hacking
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-04-19 10:52:35
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:151:841e::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:151:841e::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 19 06:52:28.991643 2026] [security2:error] [pid 1976915:tid 1976915] [client 2a01:4f8:151:841e::2:59034] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.citystreetsalon.com|F|2"] [data ".fionnardesign.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.citystreetsalon.com"] [uri "/www.fionnardesign.com"] [unique_id "aeSz7AKihVU4EgAiMbKHHAAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack