๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-28 05:41:17
(16 minutes ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Web App Attack
Bad Web Bot
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-27 04:49:28
(1 day ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Web App Attack
Bad Web Bot
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-25 20:59:36
(2 days ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Web App Attack
Bad Web Bot
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-19 05:00:18
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Web App Attack
Bad Web Bot
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-14 21:22:44
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-09 11:03:51
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:191:8159::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:191:8159::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 09 07:03:47.024443 2026] [security2:error] [pid 2940716:tid 2940716] [client 2a01:4f8:191:8159::2:60878] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||infodevman.net|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "infodevman.net"] [uri "/Archives/CU67covid/[email protected] "] [unique_id "anhek0FU0Yr_4YYVJVq75AAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob
2026-08-08 20:00:53
(2 weeks ago)
CrowdSec: crowdsecurity/http-bad-user-agent | req: /robots.txt | 2 distinct paths | UA: serpstatbot/ ...
show more
CrowdSec: crowdsecurity/http-bad-user-agent | req: /robots.txt | 2 distinct paths | UA: serpstatbot/2.1 (advanced backlink tracking bot; https://serpstatbot.com/; [email protected] )
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-13 00:09:07
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:191:8159::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:191:8159::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 20:09:01.504378 2026] [security2:error] [pid 4486:tid 4486] [client 2a01:4f8:191:8159::2:32848] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bali-nanny-babysitter.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bali-nanny-babysitter.com"] [uri "/[email protected] "] [unique_id "aiyfnVp2z3uzjSY0JugLuQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
aranguren.org
2026-05-30 07:04:01
(2 months ago)
2a01:4f8:191:8159::2 - - [30/May/2026:16:52:46 +1000] "GET /?displaymode=n&end=now&start=2025-11-21+ ...
show more
2a01:4f8:191:8159::2 - - [30/May/2026:16:52:46 +1000] "GET /?displaymode=n&end=now&start=2025-11-21+21%3A29&target=network.bitcoin_abc HTTP/1.1" 200 8546 "-" "serpstatbot/2.1 (advanced backlink tracking bot; https://serpstatbot.com/; [email protected] )"
2a01:4f8:191:8159::2 - - [30/May/2026:17:03:48 +1000] "GET /?target=network.bitcoin HTTP/1.1" 200 8474 "-" "serpstatbot/2.1 (advanced backlink tracking bot; https://serpstatbot.com/; [email protected] )"
2a01:4f8:191:8159::2 - - [30/May/2026:17:04:00 +1000] "GET /?target=network.bitcoin_abc HTTP/1.1" 200 8508 "-" "serpstatbot/2.1 (advanced backlink tracking bot; https://serpstatbot.com/; [email protected] )"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-29 23:02:00
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:191:8159::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:191:8159::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 19:01:55.096241 2026] [security2:error] [pid 31847:tid 31847] [client 2a01:4f8:191:8159::2:39530] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lloydprins.com|F|2"] [data ".nealcitron.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lloydprins.com"] [uri "/www.nealcitron.com"] [unique_id "ahoa4xT5OtveRtNpaKX1GwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-25 12:49:54
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:191:8159::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:191:8159::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 07:49:48.919884 2026] [security2:error] [pid 14918:tid 14931] [client 2a01:4f8:191:8159::2:55030] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jean-paullederer.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jean-paullederer.com"] [uri "/[email protected] "] [unique_id "aZ7v7EHzjPsGPhpeYLWUqgAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-25 07:55:17
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:191:8159::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:191:8159::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 25 02:55:11.856158 2026] [security2:error] [pid 15644:tid 15644] [client 2a01:4f8:191:8159::2:58304] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||idodat.com|F|2"] [data ".php.old"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "idodat.com"] [uri "/index.php.OLD"] [unique_id "aZ6q30XMjGPLA6mAApF-3AAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-12 06:34:59
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:191:8159::2 (Unknown): 1 in the last 3 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a01:4f8:191:8159::2 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 12 01:34:55.490454 2026] [security2:error] [pid 24578:tid 24578] [client 2a01:4f8:191:8159::2:57314] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||keystroke.info|F|2"] [data ".php.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "keystroke.info"] [uri "/LocalSettings.php.backup"] [unique_id "aY10j81nwKQGObU9iG2AKQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2026-01-09 22:37:54
(7 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Bad Web Bot
Web App Attack
๐ฆ๐บ
2000cn.com.au
2025-12-25 07:50:37
(8 months ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-bad-user-agent
Bad Web Bot
Web App Attack