๐บ๐ธ
TPI-Abuse
2026-04-22 23:47:13
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 19:47:06.000816 2026] [security2:error] [pid 2912238:tid 2912238] [client 2a03:2880:f806:b:::38516] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.civilwarzone.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.civilwarzone.com"] [uri "/~site/Scripts_ExternalRedirect/ExternalRedirect.dll"] [unique_id "aeld-eI-iXrve9KWxM9o8AAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-21 17:28:24
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 21 13:28:16.394666 2026] [security2:error] [pid 1646744:tid 1646744] [client 2a03:2880:f806:b:::34046] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||baselinesc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "baselinesc.com"] [uri "/baselinesc.com"] [unique_id "aeezsFI2NlPP4HEkOpP1CwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-20 12:13:26
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 20 08:13:22.512423 2026] [security2:error] [pid 4039575:tid 4039575] [client 2a03:2880:f806:b:::52506] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||3-6trucking.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "3-6trucking.com"] [uri "/3-6trucking.com"] [unique_id "aeYYYpXtFIOTw0qsLTEYrwAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-20 06:38:39
(5 months ago)
(mod_security) mod_security (id:213060) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:213060) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 20 02:38:31.670161 2026] [security2:error] [pid 564192:tid 564192] [client 2a03:2880:f806:b:::23296] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i)((?:\\\\bx(?:link:href|html|mlns)|!ENTITY\\\\b.{0,399}?\\\\b(?:SYSTEM|PUBLIC)|\\\\bdata:text\\\\/html))" at ARGS:_bd_prev_page. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/07_XSS_XSS.conf"] [line "170"] [id "213060"] [rev "7"] [msg "COMODO WAF: XSS Filter - Category 3: Attribute Vector||essentialee.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "XSS"] [hostname "essentialee.com"] [uri "/"] [unique_id "aeXJ55tZ7Gplua6vDj2LoAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-19 11:10:30
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 19 07:10:26.675758 2026] [security2:error] [pid 11673:tid 11673] [client 2a03:2880:f806:b:::52096] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rockwaychiropractic.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rockwaychiropractic.com"] [uri "/rockwaychiropractic.com"] [unique_id "aeS4IomDGgTAtI_WYMQUogAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-19 05:35:17
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 19 01:35:10.494376 2026] [security2:error] [pid 1632074:tid 1632074] [client 2a03:2880:f806:b:::46232] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||napaautopartskeokuk.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "napaautopartskeokuk.com"] [uri "/napaautopartskeokuk.com"] [unique_id "aeRpjh0L3ThK82L_08FwhgAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-18 15:49:48
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Apr 18 11:49:40.680437 2026] [security2:error] [pid 2125751:tid 2125751] [client 2a03:2880:f806:b:::53422] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||opticasprisma.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "opticasprisma.com"] [uri "/opticasprisma.com"] [unique_id "aeOoFPaw3L8p4oNw6t545AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
london2038.com
2026-04-18 03:23:29
(5 months ago)
Too many failed requests
2a03:2880:f806:b:: - - [18/Apr/2026:02:06:12 +0200] "GET /User:Damian3594 H ...
show more
Too many failed requests
2a03:2880:f806:b:: - - [18/Apr/2026:02:06:12 +0200] "GET /User:Damian3594 HTTP/2.0" 404 10120 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:b:: - - [18/Apr/2026:02:08:32 +0200] "GET /User:DanialMurphy93 HTTP/2.0" 404 10192 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:b:: - - [18/Apr/2026:02:10:48 +0200] "GET /User:DanaeTafoya132 HTTP/2.0" 404 10192 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:b:: - - [18/Apr/2026:02:12:36 +0200] "GET /User:DanieleMccue HTTP/2.0" 404 10156 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:b:: - - [18/Apr/2026:02:12:48 +0200] "GET /User:DanaeRyder HTTP/2.0" 404 10120 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:b:: - - [18/Apr/2026
...
show less
Web Spam
Bad Web Bot
๐ฉ๐ช
london2038.com
2026-04-17 14:28:16
(5 months ago)
Too many failed requests
2a03:2880:f806:b:: - - [17/Apr/2026:13:46:44 +0200] "GET /User:PilarBrierly ...
show more
Too many failed requests
2a03:2880:f806:b:: - - [17/Apr/2026:13:46:44 +0200] "GET /User:PilarBrierly57 HTTP/2.0" 404 10192 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:b:: - - [17/Apr/2026:13:54:18 +0200] "GET /User:PollyJarman6917 HTTP/2.0" 404 10210 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:b:: - - [17/Apr/2026:14:17:59 +0200] "GET /User:Porter3164 HTTP/2.0" 404 10120 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:b:: - - [17/Apr/2026:14:42:21 +0200] "GET /User:ClaireGreenlee HTTP/2.0" 404 10192 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:b:: - - [17/Apr/2026:14:42:24 +0200] "GET /User:Claire36N5595198 HTTP/2.0" 404 10228 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:b:: - - [17
...
show less
Web Spam
Bad Web Bot
๐ฉ๐ช
london2038.com
2026-04-16 22:22:32
(5 months ago)
Too many failed requests
2a03:2880:f806:b:: - - [16/Apr/2026:19:39:02 +0200] "GET /User:ArnetteV69 H ...
show more
Too many failed requests
2a03:2880:f806:b:: - - [16/Apr/2026:19:39:02 +0200] "GET /User:ArnetteV69 HTTP/2.0" 404 10120 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:b:: - - [16/Apr/2026:21:50:58 +0200] "GET /User:NatalieLuce71 HTTP/2.0" 404 10174 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:b:: - - [16/Apr/2026:22:22:35 +0200] "GET /User:NicholZ319 HTTP/2.0" 404 10120 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:b:: - - [16/Apr/2026:22:31:06 +0200] "GET /User:NealSimos949991 HTTP/2.0" 404 10210 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:b:: - - [16/Apr/2026:22:41:29 +0200] "GET /User:NatalieODonovan HTTP/2.0" 404 10210 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
2a03:2880:f806:b:: - - [16/Apr/2
...
show less
Web Spam
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-16 14:22:17
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 16 10:22:13.670895 2026] [security2:error] [pid 1080319:tid 1080319] [client 2a03:2880:f806:b:::38318] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.alafiariverrendezvous.org|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.alafiariverrendezvous.org"] [uri "/[email protected] "] [unique_id "aeDwlbWskPCjM69YTN81ZQAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gui-ying233
2026-04-14 00:08:14
(5 months ago)
meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Bad Web Bot
๐บ๐ธ
gui-ying233
2026-04-13 00:23:59
(5 months ago)
meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Bad Web Bot
๐บ๐ธ
gui-ying233
2026-04-12 00:18:25
(5 months ago)
meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Bad Web Bot
๐บ๐ธ
myagent.site
2026-04-11 12:14:21
(5 months ago)
Blocking for trying to access an exploit file: /SiteMap.aspx
Hacking