๐บ๐ธ
TPI-Abuse
2025-09-04 14:17:00
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 04 10:16:53.905494 2025] [security2:error] [pid 12619:tid 12619] [client 2a03:2880:f806:b:::51204] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||batonrougecustomcabinets.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "batonrougecustomcabinets.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aLmfVaDGsIq9zgKI3SI1CAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ฎ
cycastic
2025-08-23 19:13:02
(1 year ago)
Probed /index.html on 08/23/2025 19:10:59 +00:00 (UA: meta-externalagent/1.1 (+https://developers.fa ...
show more
Probed /index.html on 08/23/2025 19:10:59 +00:00 (UA: meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler), Query: )
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-15 06:59:34
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 15 02:59:30.621844 2025] [security2:error] [pid 21530:tid 21530] [client 2a03:2880:f806:b:::35444] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||blockadegc.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "blockadegc.com"] [uri "/blockadegc.com"] [unique_id "aJ7a0u12Tnu3XVfsy10SEgAAAB8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-08-10 13:02:05
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Aug 10 09:02:00.418116 2025] [security2:error] [pid 22554:tid 22554] [client 2a03:2880:f806:b:::35928] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||scoutinsignia.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "scoutinsignia.com"] [uri "/hats/WS_FTP.LOG"] [unique_id "aJiYSGrwnh1oSqbDLrwajQAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2025-08-05 02:39:49
(1 year ago)
(PERMBLOCK) 2a03:2880:f806:b:: (US/United States/Georgia/Alpharetta/-/[redacted]) has had more than ...
show more
(PERMBLOCK) 2a03:2880:f806:b:: (US/United States/Georgia/Alpharetta/-/[redacted]) has had more than 4 temp blocks
show less
Hacking
๐ณ๐ฑ
Roderic
2025-08-04 17:48:08
(1 year ago)
(apache-useragents) Failed apache-useragents trigger with match [redacted])
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-07-17 12:23:33
(1 year ago)
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225080) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 17 08:23:30.025505 2025] [security2:error] [pid 12250:tid 12250] [client 2a03:2880:f806:b:::56214] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^[\\\\d\\\\.ab]+$" against "ARGS_GET:C" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "143"] [id "225080"] [rev "1"] [msg "COMODO WAF: XSS vulnerability in Plupload before 2.1.9 or MediaElement.js before 2.21.0, as used in WordPress before 4.5.2 (CVE-2016-4566 & CVE-2016-4567)||becclesrestaurants.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "becclesrestaurants.com"] [uri "/wp-includes/js/tinymce/plugins/wptextpattern/"] [unique_id "aHjrQu8qAdIF0K35hYQOVQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-14 00:22:54
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 13 20:22:48.703390 2025] [security2:error] [pid 23224:tid 23224] [client 2a03:2880:f806:b:::54342] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/114742"] [unique_id "aHRN2C8jC-F2nsUN4D4CFgAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-11 17:14:50
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 11 13:14:45.996321 2025] [security2:error] [pid 20597:tid 20597] [client 2a03:2880:f806:b:::56344] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||sailyourkayak.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "sailyourkayak.com"] [uri "/blog/tag/sailyourkayak.com"] [unique_id "aHFGhThOz5LF_jAf5c6NQgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-07-10 18:08:37
(1 year ago)
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210381) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 10 14:08:32.671863 2025] [security2:error] [pid 30381:tid 30381] [client 2a03:2880:f806:b:::58626] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||www.pobanz.com|F|4"] [data "REQUEST_URI=/images/christmas17/09/dPu+uGP2QDGMYC2wtIB%fw_thumb_2d91.jpg"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.pobanz.com"] [uri "/images/christmas17/09/dPu+uGP2QDGMYC2wtIB%fw_thumb_2d91.jpg"] [unique_id "aHABoH8MezOQk5jPuxPkHwAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-27 13:49:05
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 27 09:48:58.579174 2025] [security2:error] [pid 2839617:tid 2839617] [client 2a03:2880:f806:b:::36196] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.ontimelogistiks.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.ontimelogistiks.com"] [uri "/blog/wp-json/wp/v2/users/1"] [unique_id "aF6hSsY0u24TRt9O4dN-4AAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-15 04:44:47
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 15 00:44:41.188542 2025] [security2:error] [pid 2689576:tid 2689576] [client 2a03:2880:f806:b:::54978] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.technesa.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.technesa.com"] [uri "/tag/technegt/[email protected] "] [unique_id "aE5PuaslML4S1_wCtuu7kwAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-13 01:56:32
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 12 21:56:27.559447 2025] [security2:error] [pid 2804713:tid 2804713] [client 2a03:2880:f806:b:::36386] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||glassclublake.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "glassclublake.com"] [uri "/[email protected] "] [unique_id "aEuFS5ExZP_2KK6zqPqAFAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-09 08:24:16
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 09 04:24:08.382214 2025] [security2:error] [pid 1850704:tid 1850704] [client 2a03:2880:f806:b:::33886] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.theabstractpress.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.theabstractpress.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aEaaKHi9BKLRXydsAL9rxQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-06-07 17:16:16
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 07 13:16:12.052795 2025] [security2:error] [pid 2456835:tid 2456835] [client 2a03:2880:f806:b:::56850] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.robinsnestingplace.net|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.robinsnestingplace.net"] [uri "/wp-json/wp/v2/users/2"] [unique_id "aERz3HxB_Te43PB6-e7cEAAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack