๐บ๐ธ
TPI-Abuse
2026-06-18 10:33:58
(32 minutes ago)
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 18 06:33:53.594923 2026] [security2:error] [pid 32382:tid 32382] [client 2a03:2880:f806:51:::20414] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||cultiplant.com.menagri.com|F|4"] [data "REQUEST_URI=/uploads/products/CULTIPLANT_Sodium_Molybdate_39_5%_TDS.pdf"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "cultiplant.com.menagri.com"] [uri "/uploads/products/CULTIPLANT_Sodium_Molybdate_39_5%_TDS.pdf"] [unique_id "ajPJkeZ1GgGJqW8I5Uh1XgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gui-ying233
2026-06-13 00:11:44
(5 days ago)
meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-12 12:51:16
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 08:51:09.516792 2026] [security2:error] [pid 29969:tid 29969] [client 2a03:2880:f806:51:::57210] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||adonamusic.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "adonamusic.com"] [uri "/adonamusic.com"] [unique_id "aiwAva6UOW6LeB738hVWbwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 14:05:33
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 10:05:28.622930 2026] [security2:error] [pid 28220:tid 28220] [client 2a03:2880:f806:51:::37346] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bjfrancislaw.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bjfrancislaw.com"] [uri "/bjfrancislaw.com"] [unique_id "aigdqEplrhwBOPsMx2zmmQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 15:03:04
(1 week ago)
(mod_security) mod_security (id:949110) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:949110) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 11:02:58.596583 2026] [security2:error] [pid 1450:tid 1450] [client 2a03:2880:f806:51:::24588] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/apache2/conf.d/modsec_vendor_configs/OWASP3/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "30"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "cpectec.com"] [uri "/cpectec.com"] [unique_id "aiWIIkYtLIU28eav23qFWwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 12:01:19
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 08:01:12.004773 2026] [security2:error] [pid 27639:tid 27639] [client 2a03:2880:f806:51:::21894] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||scoretopicturenetwork.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "scoretopicturenetwork.com"] [uri "/scoretopicturenetwork.com"] [unique_id "aiVdiIKlzggtzdm4MnLE2QAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-07 06:35:49
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 02:35:43.406813 2026] [security2:error] [pid 23195:tid 23195] [client 2a03:2880:f806:51:::57308] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||independentmusicconference.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "independentmusicconference.com"] [uri "/independentmusicconference.com"] [unique_id "aiURP-gis2xE5gnTuMpQrwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 14:27:26
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 10:27:22.537479 2026] [security2:error] [pid 13640:tid 13640] [client 2a03:2880:f806:51:::48652] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||vc1.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vc1.com"] [uri "/vc1.com"] [unique_id "aiQuSrwvwMpd7a0Jn8YAQwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 13:29:37
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 09:29:29.337610 2026] [security2:error] [pid 25409:tid 25409] [client 2a03:2880:f806:51:::56764] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||opticasprisma.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "opticasprisma.com"] [uri "/opticasprisma.com"] [unique_id "aiQguRQx7vZNpMowKDJJnQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gui-ying233
2026-06-06 00:23:00
(1 week ago)
meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-05 19:50:42
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 15:50:34.479329 2026] [security2:error] [pid 30066:tid 30066] [client 2a03:2880:f806:51:::23548] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lumentravel.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lumentravel.com"] [uri "/lumentravel.com"] [unique_id "aiMoimJ6yb7gEROdwEl-0AAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-05 13:49:07
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 09:49:03.485603 2026] [security2:error] [pid 20809:tid 20809] [client 2a03:2880:f806:51:::29366] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||automationmp.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "automationmp.com"] [uri "/automationmp.com"] [unique_id "aiLTz9pOAHW-cq3V9Dsz4gAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gui-ying233
2026-06-05 00:21:59
(1 week ago)
meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Bad Web Bot
๐บ๐ธ
gui-ying233
2026-06-04 00:21:18
(2 weeks ago)
meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-03 14:33:02
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 30 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:51:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 10:32:54.578303 2026] [security2:error] [pid 9904:tid 9904] [client 2a03:2880:f806:51:::58402] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||kclawoffice.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "kclawoffice.com"] [uri "/kclawoffice.com"] [unique_id "aiA7FgfjhFw9U0haU05jbgAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack