๐บ๐ธ
TPI-Abuse
2026-10-02 10:59:12
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:a:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:a:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 06:59:08.952432 2026] [security2:error] [pid 11985:tid 11985] [client 2a03:2880:f806:a:::32848] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vitalitywebb.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vitalitywebb.com"] [uri "/backstore/Catnapper/images/Teddy Bear/Thumbs.db"] [unique_id "ar-OfKeimPcS11rOT8ogVQAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
abuseipdb.amaze321
2026-10-01 06:35:41
(1 day ago)
Automated reconnaissance: repeated requests for sensitive/non-existent paths.
Web App Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-29 23:05:23
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:a:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:a:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 19:05:15.646648 2026] [security2:error] [pid 7691:tid 7782] [client 2a03:2880:f806:a:::65408] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.digital4z.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.digital4z.com"] [uri "/wp-content/plugins/app-your-wordpress-uppsite/admin/js/WS_FTP.LOG"] [unique_id "arxEK4c6lrIlLyzUdtMRvQAAAMY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 15:23:26
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:a:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:a:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 11:23:23.205598 2026] [security2:error] [pid 22860:tid 22860] [client 2a03:2880:f806:a:::63594] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||haroturkiye.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "haroturkiye.com"] [uri "/haroturkiye.com"] [unique_id "arvX63hAvywTiHGF2TaY9AAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-29 13:34:24
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:a:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:a:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 09:34:17.870776 2026] [security2:error] [pid 11444:tid 11444] [client 2a03:2880:f806:a:::55260] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||baselinesc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "baselinesc.com"] [uri "/baselinesc.com"] [unique_id "aru-WRBUEPNTQWZRyxezGQAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
jbcrn
2026-09-28 21:43:01
(3 days ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Reque ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Requested honeypot path: /. User-Agent: facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 20:06:31
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:a:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:a:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 16:06:24.601471 2026] [security2:error] [pid 10755:tid 10755] [client 2a03:2880:f806:a:::29230] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mininoarg.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mininoarg.com"] [uri "/mininoarg.com"] [unique_id "arrIwAnyeniRijEWYcSSUQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 13:51:40
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:a:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:a:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 28 09:51:37.121328 2026] [security2:error] [pid 17943:tid 17943] [client 2a03:2880:f806:a:::50570] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sammour.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sammour.com"] [uri "/sammour.com"] [unique_id "arpw6YV35UtwaYo9Iyj7mgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-28 02:33:37
(4 days ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:a:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:a:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 22:33:30.898665 2026] [security2:error] [pid 32114:tid 32114] [client 2a03:2880:f806:a:::44998] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||lusineweb.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "lusineweb.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "arnR-kD2uFomYFvxAuPt3gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-09-25 11:07:55
(1 week ago)
147 querystring crawling (29m59s)
Brute-Force
Bad Web Bot
๐บ๐ธ
MatCat
2026-09-25 11:05:08
(1 week ago)
Banned by fail2ban: gitea
Brute-Force
Web App Attack
๐ฉ๐ช
jbcrn
2026-09-25 04:43:50
(1 week ago)
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Reque ...
show more
Blocked by iocaine (nam-shub-of-enki) tarpit. Classified as: Facebook, ruleset: ai.robots.txt. Requested honeypot path: /. User-Agent: facebookexternalhit/1.1 (+http://www.facebook.com/externalhit_uatext.php)
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-25 01:21:23
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:a:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:a:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 21:21:16.868480 2026] [security2:error] [pid 27757:tid 27757] [client 2a03:2880:f806:a:::52170] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||shinynew.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "shinynew.com"] [uri "/shinynew.com"] [unique_id "arXMjOpVEEEsfh_9t2ZB0QAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-24 22:56:30
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:a:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:a:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 24 18:56:22.682229 2026] [security2:error] [pid 13320:tid 13320] [client 2a03:2880:f806:a:::61420] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.computerservicesofflorida.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.computerservicesofflorida.com"] [uri "/computerservicesofflorida.com"] [unique_id "arWqlsCXDtK-PjFRmXrpvQAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
Skyrider
2026-09-22 19:47:07
(1 week ago)
Nginx: HTTP 4xx probe/scan attempts. Automated fail2ban report.
Bad Web Bot
Web App Attack