๐บ๐ธ
TPI-Abuse
2026-06-10 20:07:30
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 16:07:23.375249 2026] [security2:error] [pid 5865:tid 5865] [client 2a03:2880:f806:13:::40354] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||automationmp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "automationmp.com"] [uri "/automationmp.com"] [unique_id "ainD--1S7dWjU4nNGBaJRwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 09:27:22
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 05:27:18.560271 2026] [security2:error] [pid 14903:tid 14903] [client 2a03:2880:f806:13:::54368] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||edfisherco.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "edfisherco.com"] [uri "/edfisherco.com"] [unique_id "aikt9qnWTKwTV5c_zzETrgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 04:50:29
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 00:50:22.336195 2026] [security2:error] [pid 31502:tid 31502] [client 2a03:2880:f806:13:::43128] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.civilwarzone.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.civilwarzone.com"] [uri "/~site/Scripts_ExternalRedirect/ExternalRedirect.dll"] [unique_id "aijtDueTDbVfs6mPnEhawQAAAAo"], referer: https://www.civilwarzone.com/GeorgeThomas.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 05:35:11
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 01:35:07.117307 2026] [security2:error] [pid 23177:tid 23177] [client 2a03:2880:f806:13:::54000] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||mitchellart.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mitchellart.com"] [uri "/mitchellart.com"] [unique_id "aiZUi_sTHv4_xXITmRylzQAAAEA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 15:11:41
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 11:11:38.129052 2026] [security2:error] [pid 22270:tid 22270] [client 2a03:2880:f806:13:::47966] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kiinlog.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kiinlog.com"] [uri "/kiinlog.com"] [unique_id "aiWKKjxoM4rOtxBzfxyXdQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 04:40:42
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 00:40:39.065882 2026] [security2:error] [pid 6018:tid 6018] [client 2a03:2880:f806:13:::50166] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nesetsv.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nesetsv.com"] [uri "/nesetsv.com"] [unique_id "aiOkx1Ruc3W5XrZ3LRtI7AAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
Peregrine
2026-06-06 03:21:07
(3 months ago)
Fail2Ban Jail s2: tomcat-honeypot | Evidence: 2a03:2880:f806:13:: 172.71.22.186 - - [19/May/2026:15: ...
show more
Fail2Ban Jail s2: tomcat-honeypot | Evidence: 2a03:2880:f806:13:: 172.71.22.186 - - [19/May/2026:15:18:46 -0300] "GET /meta.json HTTP/1.1" 404 414
show less
Bad Web Bot
๐บ๐ธ
gui-ying233
2026-06-06 00:09:34
(3 months ago)
meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-05 21:39:13
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 17:39:08.999867 2026] [security2:error] [pid 7518:tid 7539] [client 2a03:2880:f806:13:::37590] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gelatoconsapevole.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gelatoconsapevole.com"] [uri "/gelatoconsapevole.com"] [unique_id "aiNB_AsNKObEvCnCkCDjAAAAAFI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
Peregrine
2026-06-05 03:18:49
(3 months ago)
Fail2Ban Jail s2: tomcat-honeypot | Evidence: 2a03:2880:f806:13:: 172.71.22.186 - - [19/May/2026:15: ...
show more
Fail2Ban Jail s2: tomcat-honeypot | Evidence: 2a03:2880:f806:13:: 172.71.22.186 - - [19/May/2026:15:18:46 -0300] "GET /meta.json HTTP/1.1" 404 414
show less
Bad Web Bot
๐บ๐ธ
gui-ying233
2026-06-05 00:09:01
(3 months ago)
meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Bad Web Bot
๐บ๐ธ
gui-ying233
2026-06-04 00:07:16
(3 months ago)
meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-03 14:25:29
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:13:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 10:25:22.595536 2026] [security2:error] [pid 30698:tid 30698] [client 2a03:2880:f806:13:::35544] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||amazinghydraulics.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "amazinghydraulics.com"] [uri "/amazinghydraulics.com"] [unique_id "aiA5UnVxwxaqEB8XzCzHzQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ท
Peregrine
2026-06-03 03:26:22
(3 months ago)
Fail2Ban Jail s2: tomcat-honeypot | Evidence: 2a03:2880:f806:13:: 172.71.22.186 - - [19/May/2026:15: ...
show more
Fail2Ban Jail s2: tomcat-honeypot | Evidence: 2a03:2880:f806:13:: 172.71.22.186 - - [19/May/2026:15:18:46 -0300] "GET /meta.json HTTP/1.1" 404 414
show less
Bad Web Bot
๐บ๐ธ
gui-ying233
2026-06-03 00:06:13
(3 months ago)
meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Bad Web Bot