πΊπΈ
TPI-Abuse
2025-11-14 01:39:21
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Nov 13 20:39:14.981051 2025] [security2:error] [pid 13184:tid 13184] [client 2a03:2880:f806:1e:::38282] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||naturessecretresort.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "naturessecretresort.com"] [uri "/naturessecretresort.com"] [unique_id "aRaIQuJdpQb_gom6CwFaLgAAABw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-11-11 22:42:07
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 11 17:42:03.829813 2025] [security2:error] [pid 23593:tid 23593] [client 2a03:2880:f806:1e:::42750] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||intrinsicdiscovery.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "intrinsicdiscovery.com"] [uri "/intrinsicdiscovery.com"] [unique_id "aRO7u2VVyv2s3ME9foS9XQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
conseilgouz
2025-11-11 18:29:27
(9 months ago)
lae-88 : Bloc AI bots=>/sitemap.xml(meta-external)
Hacking
πΊπΈ
TPI-Abuse
2025-11-10 10:05:31
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Nov 10 05:05:23.612477 2025] [security2:error] [pid 20978:tid 20989] [client 2a03:2880:f806:1e:::34600] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||businessbasicsinstitute.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "businessbasicsinstitute.com"] [uri "/businessbasicsinstitute.com"] [unique_id "aRG441vxzaFG_eeC3S1jNQAAAQU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
conseilgouz
2025-11-08 05:29:37
(9 months ago)
ece-88 : Bloc AI bots=>/sitemap.xml(meta-external)
Hacking
πΊπΈ
TPI-Abuse
2025-11-05 03:45:50
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Nov 04 22:45:45.849782 2025] [security2:error] [pid 2976:tid 2976] [client 2a03:2880:f806:1e:::49630] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||book-arts.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "book-arts.com"] [uri "/book-arts.com"] [unique_id "aQrIaZWclv1CmRK0HG8BUwAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-09-03 10:32:01
(11 months ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 03 06:31:56.793622 2025] [security2:error] [pid 21532:tid 21532] [client 2a03:2880:f806:1e:::39288] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/10169"] [unique_id "aLgZHEewrw7VjZHffKIq6gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-08-11 10:44:42
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 11 06:44:38.266462 2025] [security2:error] [pid 26221:tid 26221] [client 2a03:2880:f806:1e:::46050] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||blockadegc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blockadegc.com"] [uri "/blockadegc.com"] [unique_id "aJnJlmOqpWTnme8M9WfV-AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π³π±
Roderic
2025-08-05 03:36:06
(1 year ago)
(PERMBLOCK) 2a03:2880:f806:1e:: (US/United States/Georgia/Alpharetta/-/[redacted]) has had more than ...
show more
(PERMBLOCK) 2a03:2880:f806:1e:: (US/United States/Georgia/Alpharetta/-/[redacted]) has had more than 4 temp blocks
show less
Hacking
π³π±
Roderic
2025-08-04 18:52:05
(1 year ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
πΊπΈ
TPI-Abuse
2025-07-22 16:55:23
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jul 22 12:55:16.680886 2025] [security2:error] [pid 17798:tid 17798] [client 2a03:2880:f806:1e:::35764] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nancyscafeandcatering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nancyscafeandcatering.com"] [uri "/wp-content/themes/eatery/hunterfucktube.com"] [unique_id "aH_CdCW8iZxXgwrxnu7-eQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-07-19 12:09:45
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jul 19 08:09:39.192604 2025] [security2:error] [pid 28759:tid 28759] [client 2a03:2880:f806:1e:::58000] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.agkgt.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.agkgt.org"] [uri "/wp-json/wp/v2/users/3"] [unique_id "aHuLA4r71YT2IvR0TfuzeQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-07-10 11:26:23
(1 year ago)
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 10 07:26:16.099687 2025] [security2:error] [pid 3815:tid 3815] [client 2a03:2880:f806:1e:::54464] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||www.pobanz.com|F|4"] [data "REQUEST_URI=/images/christmas17/10/fQtP1r3IQ%Ka4opW%UaHMg_thumb_2dc2.jpg"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.pobanz.com"] [uri "/images/christmas17/10/fQtP1r3IQ%Ka4opW%UaHMg_thumb_2dc2.jpg"] [unique_id "aG-jWIXlJUsGWyLoKW0rQAAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-07-02 11:05:59
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 02 07:05:55.951005 2025] [security2:error] [pid 5781:tid 5781] [client 2a03:2880:f806:1e:::42748] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/42503"] [unique_id "aGUSk3lMSBs2bfKLTd8XkgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2025-06-29 04:49:49
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:1e:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 29 00:49:45.344469 2025] [security2:error] [pid 4108539:tid 4108539] [client 2a03:2880:f806:1e:::59270] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||didactrend.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "didactrend.com"] [uri "/wp-json/wp/v2/users/3"] [unique_id "aGDF6cnkbDPCdiu6joo-mgAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack