๐บ๐ธ
TPI-Abuse
2026-02-23 08:17:14
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 03:17:09.769416 2026] [security2:error] [pid 26987:tid 26987] [client 2a03:2880:f806:33:::58103] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cw-enterprises.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cw-enterprises.com"] [uri "/cw-enterprises.com"] [unique_id "aZwNBSS_mCcGQN7kkIx56QAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-23 04:13:04
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 23:13:00.433157 2026] [security2:error] [pid 3727:tid 3727] [client 2a03:2880:f806:33:::20525] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cpking.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cpking.com"] [uri "/cpking.com"] [unique_id "aZvTzG3e_CtWKE9EtiuWPgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-22 05:43:22
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 00:43:17.804349 2026] [security2:error] [pid 21514:tid 21514] [client 2a03:2880:f806:33:::38303] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||csm-dtc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "csm-dtc.com"] [uri "/csm-dtc.com"] [unique_id "aZqXdW6sA07gkLg1ZNTupQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-20 07:42:14
(6 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 02:42:08.328599 2026] [security2:error] [pid 17390:tid 17390] [client 2a03:2880:f806:33:::51255] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||archaiusmusic.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "archaiusmusic.com"] [uri "/archaiusmusic.com"] [unique_id "aZgQUMp2To7nCEJCtkWFmgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 20:33:37
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 19 15:33:33.291408 2026] [security2:error] [pid 30279:tid 30279] [client 2a03:2880:f806:33:::22223] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||darkalleyproductions.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "darkalleyproductions.com"] [uri "/darkalleyproductions.com"] [unique_id "aZdznRMkD0ukrlpbTqKOlwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 09:12:48
(7 months ago)
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 04:12:43.403138 2026] [security2:error] [pid 27769:tid 27769] [client 2a03:2880:f806:33:::56273] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^[\\\\d\\\\.ab]+$" against "ARGS_GET:C" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "143"] [id "225080"] [rev "1"] [msg "COMODO WAF: XSS vulnerability in Plupload before 2.1.9 or MediaElement.js before 2.21.0, as used in WordPress before 4.5.2 (CVE-2016-4566 & CVE-2016-4567)||cerrovictoria.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "cerrovictoria.com"] [uri "/WordPress/wp-includes/js/jquery/ui/"] [unique_id "aZWCi8pgW6uvNO2NdRMYRwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-16 02:43:11
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 15 21:43:04.327107 2026] [security2:error] [pid 1192:tid 1218] [client 2a03:2880:f806:33:::31271] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.stone-doyle.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.stone-doyle.com"] [uri "/stone-doyle.com"] [unique_id "aZKEOByf68FcvXS8ll7fMQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2025-12-04 00:40:46
(9 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐ซ๐ท
conseilgouz
2025-12-04 00:06:34
(9 months ago)
sae-88 : Bloc AI bots=>/sitemap-index.xml(meta-external)
Hacking
Anonymous
2025-12-03 12:57:07
(9 months ago)
[Wed Dec 03 13:49:10.123302 2025] [authz_core:error] [pid 2471345:tid 2471360] [remote 2a03:2880:f80 ...
show more
[Wed Dec 03 13:49:10.123302 2025] [authz_core:error] [pid 2471345:tid 2471360] [remote 2a03:2880:f806:33:::43580] AH01630: client denied by server configuration: /var/www/10137/exklusive-fincas-mallorca.de/suche.html [Wed Dec 03 13:51:38.541151 2025] [authz_core:error] [pid 2471345:tid 2471348] [remote 2a03:2880:f806:33:::38844] AH01630: client denied by server configuration: /var/www/10137/exklusive-fincas-mallorca.de/suche.html [Wed Dec 03 13:57:06.388771 2025] [authz_core:error] [pid 2471489:tid 2471510] [remote 2a03:2880:f806:33:::59114] AH01630: client denied by server configuration: /var/www/10137/exklusive-fincas-mallorca.de/suche.html
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
Anonymous
2025-12-03 00:39:43
(9 months ago)
[Wed Dec 03 01:36:23.812934 2025] [authz_core:error] [pid 2471489:tid 2471495] [remote 2a03:2880:f80 ...
show more
[Wed Dec 03 01:36:23.812934 2025] [authz_core:error] [pid 2471489:tid 2471495] [remote 2a03:2880:f806:33:::54054] AH01630: client denied by server configuration: /var/www/10137/exklusive-fincas-mallorca.de/suche.html [Wed Dec 03 01:37:16.688956 2025] [authz_core:error] [pid 2471489:tid 2471504] [remote 2a03:2880:f806:33:::50376] AH01630: client denied by server configuration: /var/www/10137/exklusive-fincas-mallorca.de/suche.html [Wed Dec 03 01:39:42.228552 2025] [authz_core:error] [pid 2471489:tid 2471494] [remote 2a03:2880:f806:33:::57326] AH01630: client denied by server configuration: /var/www/10136/competa-online.de/pay/pueblos/playas
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 20:17:48
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 15:17:42.223440 2025] [security2:error] [pid 10282:tid 10282] [client 2a03:2880:f806:33:::51226] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||book-arts.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "book-arts.com"] [uri "/book-arts.com"] [unique_id "aS335rIYRl5qm6eUYbzFUAAAACU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2025-11-29 20:11:48
(9 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-11-29 20:10:52
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Nov 29 15:10:48.081879 2025] [security2:error] [pid 6695:tid 6695] [client 2a03:2880:f806:33:::53774] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||opticasprisma.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "opticasprisma.com"] [uri "/opticasprisma.com"] [unique_id "aStTSOhdedKlJtsPsv-izAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-11-28 20:03:57
(9 months ago)
(mod_security) mod_security (id:240950) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:240950) triggered by 2a03:2880:f806:33:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Nov 28 15:03:47.379046 2025] [security2:error] [pid 27675:tid 27675] [client 2a03:2880:f806:33:::55060] ModSecurity: Access denied with code 403 (phase 1). Pattern match "\\\\D" at TX:1. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/30_Apps_OtherApps.conf"] [line "4530"] [id "240950"] [rev "2"] [msg "COMODO WAF: XSS & SQL injection vulnerability in Pragyan CMS 3.0 (CVE-2015-1471)||beckersystems.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "OtherApps"] [hostname "beckersystems.net"] [uri "/beckerwiki/index.php"] [unique_id "aSoAI8YRv8Kr67e5kulZTQAAADo"]
show less
Brute-Force
Bad Web Bot
Web App Attack