๐บ๐ธ
masterguru
2025-08-18 17:34:34
(1 year ago)
BAD BOT - Detected and Blocked.. Matched phrase "meta-externalagent" at REQUEST_HEADERS:User-Agent. ...
show more
BAD BOT - Detected and Blocked.. Matched phrase "meta-externalagent" at REQUEST_HEADERS:User-Agent. (1100000-173)
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-08-09 20:58:04
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 09 16:57:55.572413 2025] [security2:error] [pid 5466:tid 5466] [client 2a03:2880:f806:1c:::35396] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.trinitydent.com|F|2"] [data ".axd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.trinitydent.com"] [uri "/WebResource.axd"] [unique_id "aJe2UztnyNFdQi1fxd1S9gAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-07 21:27:50
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 07 17:27:42.435095 2025] [security2:error] [pid 29542:tid 29542] [client 2a03:2880:f806:1c:::60212] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.dalessalesandservice.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.dalessalesandservice.com"] [uri "/author/admin/[email protected] "] [unique_id "aJUaTvpgDORYXaeeU51LPQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-07 15:10:10
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 07 11:10:01.943908 2025] [security2:error] [pid 25674:tid 25674] [client 2a03:2880:f806:1c:::42392] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||blockadegc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blockadegc.com"] [uri "/blockadegc.com"] [unique_id "aJTByQ4UEqsJEJiRl8sJhAAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-07 08:35:55
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 07 04:35:51.445455 2025] [security2:error] [pid 10286:tid 10286] [client 2a03:2880:f806:1c:::49460] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ipv6.bodybuildbid.com|F|2"] [data ".wnso.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ipv6.bodybuildbid.com"] [uri "/articles/muscle_building/www.WNSO.com"] [unique_id "aJRlZzV_fvzRlEUQIeG3OgAAACg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2025-08-05 03:08:59
(1 year ago)
(PERMBLOCK) 2a03:2880:f806:1c:: (US/United States/Georgia/Alpharetta/-/[redacted]) has had more than ...
show more
(PERMBLOCK) 2a03:2880:f806:1c:: (US/United States/Georgia/Alpharetta/-/[redacted]) has had more than 4 temp blocks
show less
Hacking
๐ณ๐ฑ
Roderic
2025-08-04 17:42:20
(1 year ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-08-03 13:22:01
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 03 09:21:54.805798 2025] [security2:error] [pid 14054:tid 14054] [client 2a03:2880:f806:1c:::59208] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||scoutinsignia.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "scoutinsignia.com"] [uri "/bkground/WS_FTP.LOG"] [unique_id "aI9icja0-hXRB_N-9sb3xgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-29 14:09:12
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 29 10:09:05.743454 2025] [security2:error] [pid 3642:tid 3642] [client 2a03:2880:f806:1c:::34924] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.elcalamo.com|F|2"] [data ".pdb"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.elcalamo.com"] [uri "/pda/nava-paravolveralmar.PDB"] [unique_id "aIjWAQKASH9XydSGPMQ-RwAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-25 03:43:41
(1 year ago)
(mod_security) mod_security (id:240950) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:240950) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 24 23:43:37.318308 2025] [security2:error] [pid 4489:tid 4489] [client 2a03:2880:f806:1c:::49322] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||beckersystems.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "beckersystems.net"] [uri "/beckerwiki/index.php/User:Jianrxrsm"] [unique_id "aIL9aSJH68xwAmRDtmmfwQAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-09 22:06:03
(1 year ago)
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 09 18:05:58.558684 2025] [security2:error] [pid 1738:tid 1738] [client 2a03:2880:f806:1c:::43800] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||pobanz.com|F|4"] [data "REQUEST_URI=/images/christmas17/07/MK7PKnDGQdCwJc2IB1iY%Q_thumb_2df8.jpg"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "pobanz.com"] [uri "/images/christmas17/07/MK7PKnDGQdCwJc2IB1iY%Q_thumb_2df8.jpg"] [unique_id "aG7nxpDdL6UcN08zFE04wwAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-08 14:02:18
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 08 10:02:12.788864 2025] [security2:error] [pid 23853:tid 23853] [client 2a03:2880:f806:1c:::38716] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/8836"] [unique_id "aG0k5DjZ32ynvZX9gGmq2wAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-22 18:03:44
(1 year ago)
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 22 14:03:39.779034 2025] [security2:error] [pid 1737474:tid 1737474] [client 2a03:2880:f806:1c:::48668] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^[\\\\d\\\\.ab]+$" against "ARGS_GET:C" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "143"] [id "225080"] [rev "1"] [msg "COMODO WAF: XSS vulnerability in Plupload before 2.1.9 or MediaElement.js before 2.21.0, as used in WordPress before 4.5.2 (CVE-2016-4566 & CVE-2016-4567)||becclesrestaurants.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "becclesrestaurants.com"] [uri "/wp-includes/js/tinymce/skins/"] [unique_id "aFhFe-eulevrXyqC-2MqXwAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-03 14:33:45
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 03 10:33:41.766172 2025] [security2:error] [pid 752804:tid 752804] [client 2a03:2880:f806:1c:::49138] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cnprcertificationreviews.org|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cnprcertificationreviews.org"] [uri "/twitter.com"] [unique_id "aD8HxfCoLQwlaUZgyJsTnwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-03 04:11:23
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 03 00:11:17.566904 2025] [security2:error] [pid 32913:tid 32913] [client 2a03:2880:f806:1c:::42520] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||gamepart.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "gamepart.com"] [uri "/home/tancedi1/gamepart.com"] [unique_id "aD515a2XpzfY70vV-7WlsgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack