๐บ๐ธ
TPI-Abuse
2026-06-22 10:20:54
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 06:20:48.562419 2026] [security2:error] [pid 4944:tid 4944] [client 2a02:4780:12:69a3::1:45330] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thehealthyplaceclayton.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thehealthyplaceclayton.com"] [uri "/data.sql"] [unique_id "ajkMgMZ18QCC0fLXNdm4NAAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 18:23:10
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 14:23:04.963494 2026] [security2:error] [pid 20291:tid 20291] [client 2a02:4780:12:69a3::1:59294] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thebrotherhoodlounge.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thebrotherhoodlounge.com"] [uri "/database.sql"] [unique_id "ajgsCEzGdp019UaIV8H6jQAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 13:28:09
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 09:28:03.721419 2026] [security2:error] [pid 10919:tid 10919] [client 2a02:4780:12:69a3::1:35400] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||theateroobleck.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "theateroobleck.com"] [uri "/database.sql"] [unique_id "ajfm4z5MYd35UJa4lNSN6AAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 11:58:56
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 21 07:58:48.920987 2026] [security2:error] [pid 32264:tid 32264] [client 2a02:4780:12:69a3::1:35482] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||theamarals.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "theamarals.com"] [uri "/data.sql"] [unique_id "ajfR-M1U42zf0u8DZi2oPwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-06-21 04:19:24
(1 day ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-21 02:42:21
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 22:42:13.193263 2026] [security2:error] [pid 13116:tid 13116] [client 2a02:4780:12:69a3::1:56418] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||texaslawman.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "texaslawman.net"] [uri "/dump.sql"] [unique_id "ajdPhdAgsFqEu1pJ86GUrQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
alferez
2026-06-20 17:31:21
(2 days ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 16:55:28
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 12:55:24.630330 2026] [security2:error] [pid 306:tid 309] [client 2a02:4780:12:69a3::1:34900] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||teritemme.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "teritemme.com"] [uri "/users.sql"] [unique_id "ajbF_GfibbmCLBZxevs0IAAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
LRob.fr
2026-06-20 15:45:03
(2 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 09:19:49
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 05:19:42.908733 2026] [security2:error] [pid 4773:tid 4773] [client 2a02:4780:12:69a3::1:45048] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||televisonic.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "televisonic.com"] [uri "/db_backup.sql"] [unique_id "ajZbLo7UiC4867glQkEGzgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 08:57:25
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 20 04:57:17.163032 2026] [security2:error] [pid 28780:tid 28780] [client 2a02:4780:12:69a3::1:52050] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||teleplussolutions.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "teleplussolutions.com"] [uri "/site.sql"] [unique_id "ajZV7R7AlhT6Ky-QUmrkvwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 03:49:15
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 23:49:10.253858 2026] [security2:error] [pid 2521:tid 2521] [client 2a02:4780:12:69a3::1:57676] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||tedharris.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "tedharris.com"] [uri "/1.sql"] [unique_id "ajYNtu6CGrRaFZMPGGziaAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 01:34:56
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 21:34:51.997811 2026] [security2:error] [pid 30911:tid 30911] [client 2a02:4780:12:69a3::1:52228] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||techworksunlimited.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "techworksunlimited.com"] [uri "/backup.sql"] [unique_id "ajXuO3izBuJju6Mv33nrVQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-20 00:58:07
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): ...
show more
(mod_security) mod_security (id:210730) triggered by 2a02:4780:12:69a3::1 (srv1676526.hstgr.cloud): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 19 20:58:00.520258 2026] [security2:error] [pid 4161:tid 4161] [client 2a02:4780:12:69a3::1:38224] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||techspertnet.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "techspertnet.com"] [uri "/www.sql"] [unique_id "ajXlmMXF9DwIB1kKGLbVWwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Mangelot Hosting
2026-06-20 00:39:05
(2 days ago)
(modsecurity) srv101 ModSecurity 2a02:4780:12:69a3::1 (IN/India/-): 10 in the last 3600 secs; Ports: ...
show more
(modsecurity) srv101 ModSecurity 2a02:4780:12:69a3::1 (IN/India/-): 10 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs:
show less
Web App Attack