πΊπΈ
TPI-Abuse
2026-10-05 10:27:35
(15 hours ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f804:24:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f804:24:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 05 06:27:29.339167 2026] [security2:error] [pid 18285:tid 18285] [client 2a03:2880:f804:24:::25478] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||arsenalfordemocracy.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "arsenalfordemocracy.com"] [uri "/wp-json/wp/v2/users/3"] [unique_id "asN7kRyE7SpLGKlxBidarwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-10-05 03:56:57
(22 hours ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f804:24:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f804:24:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Oct 04 23:56:50.907357 2026] [security2:error] [pid 16426:tid 16426] [client 2a03:2880:f804:24:::53234] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.williamfitzsimmons.com|F|2"] [data ".majesticmadison.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.williamfitzsimmons.com"] [uri "/www.majesticmadison.com"] [unique_id "asMgAhCtnQQMovlEGSgIkQAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob
2026-10-04 14:30:27
(1 day ago)
Crawler ignoring refusals | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, ...
show more
Crawler ignoring refusals | ua: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; met | path: /comments/feed/ | 2026-10-04 14:30 UTC
show less
Bad Web Bot
π΅π±
mscode.pl
2026-10-01 14:58:49
(4 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 32934 (Facebook, Inc.)
P ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: BLOCK
ASN: 32934 (Facebook, Inc.)
Protocol: HTTP/2 (GET method)
Zone: r2.selify.io
Endpoint: /
UA: facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)
show less
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-09-29 18:20:47
(6 days ago)
(mod_security) mod_security (id:240950) triggered by 2a03:2880:f804:24:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:240950) triggered by 2a03:2880:f804:24:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 14:20:44.600197 2026] [security2:error] [pid 11795:tid 11795] [client 2a03:2880:f804:24:::62696] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||www.noelramos.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "www.noelramos.com"] [uri "/wiki/index.php"] [unique_id "arwBfFrKHIO2p913S3fKoAAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
jbcrn
2026-09-27 04:32:36
(1 week ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Reque ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Requested honeypot path: /. User-Agent: facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)
show less
Bad Web Bot
Web App Attack
π©πͺ
jbcrn
2026-09-24 13:32:37
(1 week ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Reque ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Requested honeypot path: /. User-Agent: facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 05:19:26
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f804:24:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f804:24:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 17 01:19:21.944593 2026] [security2:error] [pid 25161:tid 25161] [client 2a03:2880:f804:24:::45034] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.lumentravel.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.lumentravel.com"] [uri "/lumentravel.com"] [unique_id "aqt4WYoeJiLdINzDoreR9AAAACE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-17 00:51:18
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f804:24:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f804:24:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 20:51:11.927533 2026] [security2:error] [pid 28580:tid 28580] [client 2a03:2880:f804:24:::56276] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||z-industrial.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "z-industrial.com"] [uri "/z-industrial.com"] [unique_id "aqs5f3nokCJcixKC0uhCjgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
jbcrn
2026-09-16 21:32:15
(2 weeks ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Reque ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Requested honeypot path: /. User-Agent: facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)
show less
Bad Web Bot
Web App Attack
π©πͺ
jbcrn
2026-09-15 14:32:26
(2 weeks ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Reque ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Requested honeypot path: /. User-Agent: facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-15 02:51:07
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f804:24:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f804:24:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 22:50:59.022274 2026] [security2:error] [pid 4306:tid 4306] [client 2a03:2880:f804:24:::39082] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||computerservicesofflorida.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "computerservicesofflorida.com"] [uri "/computerservicesofflorida.com"] [unique_id "aqiyk9W8Hg472NtcOqGlOwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π΅π±
Budyn
2026-09-15 02:18:57
(2 weeks ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scan ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: Enterprise & Framework Recon Scanner. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: git.goblinpot.online | URI: /.git/HEAD | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/145.0.0.0 Safari/537.36 (compatible; meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)) | BODY: [Empty / GET Request]
show less
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-14 22:19:41
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f804:24:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f804:24:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 18:19:35.360745 2026] [security2:error] [pid 24453:tid 24466] [client 2a03:2880:f804:24:::32818] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mouserart.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mouserart.com"] [uri "/mouserart.com"] [unique_id "aqhy99wR7xalPw5R0tktbQAAAEo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-09-14 18:02:35
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f804:24:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f804:24:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 14 14:02:28.035934 2026] [security2:error] [pid 8235:tid 8235] [client 2a03:2880:f804:24:::33816] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||naturessecretresort.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "naturessecretresort.com"] [uri "/naturessecretresort.com"] [unique_id "aqg2tLkiQXN3tKud3XHVNwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack