๐บ๐ธ
TPI-Abuse
2026-02-23 13:34:17
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:38:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:38:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 08:34:10.037396 2026] [security2:error] [pid 9512:tid 9512] [client 2a03:2880:f806:38:::24051] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kiinlog.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kiinlog.com"] [uri "/kiinlog.com"] [unique_id "aZxXUhaHgXOiMCnJeaScVQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-22 17:03:47
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:38:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:38:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 12:03:39.228475 2026] [security2:error] [pid 5531:tid 5531] [client 2a03:2880:f806:38:::38831] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||amazinghydraulics.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "amazinghydraulics.com"] [uri "/amazinghydraulics.com"] [unique_id "aZs261rDRvN1xJXaA79jqgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-22 12:36:05
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:38:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:38:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Feb 22 07:36:01.050958 2026] [security2:error] [pid 29862:tid 29862] [client 2a03:2880:f806:38:::42969] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.nancyscafeandcatering.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.nancyscafeandcatering.com"] [uri "/wp-content/themes/eatery/nubileteensex.com"] [unique_id "aZr4MeoER45IDl65f3H-mgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-21 03:36:23
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:38:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:38:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Feb 20 22:36:16.963408 2026] [security2:error] [pid 16175:tid 16175] [client 2a03:2880:f806:38:::58215] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||danged.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "danged.com"] [uri "/danged.com"] [unique_id "aZkoMC0Zff06QG-fHRXEbQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 21:34:05
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:38:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:38:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 19 16:34:02.015326 2026] [security2:error] [pid 16619:tid 16619] [client 2a03:2880:f806:38:::26433] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wallawallafirearmstraining.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wallawallafirearmstraining.com"] [uri "/wallawallafirearmstraining.com"] [unique_id "aZeByYFx3VRpJHnZf0vt8gAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-19 21:18:05
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:38:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:38:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 19 16:17:56.765070 2026] [security2:error] [pid 13036:tid 13036] [client 2a03:2880:f806:38:::59421] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||star-discgolf.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "star-discgolf.com"] [uri "/star-discgolf.com"] [unique_id "aZd-BNm3VKf-g-6M2YGLjQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-18 22:10:28
(7 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:38:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:38:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Feb 18 17:10:23.824195 2026] [security2:error] [pid 8006:tid 8006] [client 2a03:2880:f806:38:::21847] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||raynernet.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "raynernet.com"] [uri "/raynernet.com"] [unique_id "aZY4zycXNvoNwXar3zyPiAAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2025-12-04 00:18:27
(9 months ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
Anonymous
2025-12-03 12:43:49
(9 months ago)
[Wed Dec 03 13:41:04.305236 2025] [authz_core:error] [pid 2471489:tid 2471511] [remote 2a03:2880:f80 ...
show more
[Wed Dec 03 13:41:04.305236 2025] [authz_core:error] [pid 2471489:tid 2471511] [remote 2a03:2880:f806:38:::50092] AH01630: client denied by server configuration: /var/www/10137/exklusive-fincas-mallorca.de/suche.html [Wed Dec 03 13:41:54.941780 2025] [authz_core:error] [pid 2471489:tid 2471505] [remote 2a03:2880:f806:38:::41880] AH01630: client denied by server configuration: /var/www/10137/exklusive-fincas-mallorca.de/suche.html [Wed Dec 03 13:43:48.211411 2025] [authz_core:error] [pid 2471345:tid 2471348] [remote 2a03:2880:f806:38:::42182] AH01630: client denied by server configuration: /var/www/10137/exklusive-fincas-mallorca.de/suche.html
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
Anonymous
2025-12-03 05:19:17
(9 months ago)
[Wed Dec 03 06:09:21.351749 2025] [authz_core:error] [pid 2471345:tid 2471365] [remote 2a03:2880:f80 ...
show more
[Wed Dec 03 06:09:21.351749 2025] [authz_core:error] [pid 2471345:tid 2471365] [remote 2a03:2880:f806:38:::45638] AH01630: client denied by server configuration: /var/www/10137/exklusive-fincas-mallorca.de/suche.html [Wed Dec 03 06:15:39.947070 2025] [authz_core:error] [pid 2471345:tid 2471350] [remote 2a03:2880:f806:38:::49190] AH01630: client denied by server configuration: /var/www/10137/exklusive-fincas-mallorca.de/suche.html [Wed Dec 03 06:19:16.685244 2025] [authz_core:error] [pid 2471489:tid 2471504] [remote 2a03:2880:f806:38:::59704] AH01630: client denied by server configuration: /var/www/10137/exklusive-fincas-mallorca.de/suche.html
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
Anonymous
2025-12-02 17:42:43
(9 months ago)
[Tue Dec 02 18:29:47.731025 2025] [authz_core:error] [pid 2322519:tid 2322559] [remote 2a03:2880:f80 ...
show more
[Tue Dec 02 18:29:47.731025 2025] [authz_core:error] [pid 2322519:tid 2322559] [remote 2a03:2880:f806:38:::52438] AH01630: client denied by server configuration: /var/www/10136/competa-online.de/free/fincas/nispero [Tue Dec 02 18:36:00.724828 2025] [authz_core:error] [pid 2322519:tid 2322524] [remote 2a03:2880:f806:38:::59430] AH01630: client denied by server configuration: /var/www/10136/competa-online.de/free/fincas/competa/miranda [Tue Dec 02 18:42:43.249942 2025] [authz_core:error] [pid 2322520:tid 2322567] [remote 2a03:2880:f806:38:::56852] AH01630: client denied by server configuration: /var/www/10137/exklusive-fincas-mallorca.de/suche.html
show less
Web Spam
Blog Spam
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 21:16:19
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:38:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:38:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 16:16:13.507400 2025] [security2:error] [pid 30601:tid 30601] [client 2a03:2880:f806:38:::56276] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||jnpmarinesolutions.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "jnpmarinesolutions.com"] [uri "/jnpmarinesolutions.com"] [unique_id "aS4FnSRAZ7YK6C6Lr_4tVgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 20:07:50
(9 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:38:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:38:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 15:07:43.217374 2025] [security2:error] [pid 14334:tid 14334] [client 2a03:2880:f806:38:::44914] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||go-901.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "go-901.com"] [uri "/go-901.com"] [unique_id "aS31jyZUeB3IDhgLWnJHeAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐น
VHosting
2025-12-01 11:00:13
(9 months ago)
Detected WordPress attack from 4 different servers
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-01 10:27:10
(9 months ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:38:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:38:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 01 05:27:03.838479 2025] [security2:error] [pid 7041:tid 7041] [client 2a03:2880:f806:38:::46698] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/22263"] [unique_id "aS1tdxw77_oJE5PI5m_9SgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack