Anonymous
2025-05-03 00:00:00
(1 year ago)
Multiple unauthorized attempt to access to non-existent path
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-24 13:20:50
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Apr 24 09:20:45.674854 2025] [security2:error] [pid 2128918:tid 2128918] [client 2a03:2880:f806:b:::60930] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.wallawallafirearmstraining.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.wallawallafirearmstraining.com"] [uri "/wp-json/wp/v2/users/1"] [unique_id "aAo6ra8jj-4Pb8elNdjdnwAAADk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-16 18:03:33
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 16 14:03:27.615031 2025] [security2:error] [pid 19506:tid 19506] [client 2a03:2880:f806:b:::36076] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.gay-holiday-thailand.com|F|2"] [data ".db"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.gay-holiday-thailand.com"] [uri "/images/CarribeanPortal/Thumbs.db"] [unique_id "Z__w72l6D6_BJxOxTCsdigAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-04-16 13:20:53
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 16 09:20:49.200806 2025] [security2:error] [pid 1735257:tid 1735257] [client 2a03:2880:f806:b:::37112] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/198691"] [unique_id "Z_-usTIDxQi1tDJvKUh99gAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-25 10:16:59
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 25 06:16:52.249474 2025] [security2:error] [pid 8349:tid 8349] [client 2a03:2880:f806:b:::39460] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.flavornet.org|F|2"] [data ".pdb"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.flavornet.org"] [uri "/info/jmol/pdb/97-62-1.pdb"] [unique_id "Z-KClOXuIm8SIdH2ReErpQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-14 06:33:12
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Mar 14 02:33:06.627721 2025] [security2:error] [pid 8182:tid 8182] [client 2a03:2880:f806:b:::49954] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||speedgo.mx|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "speedgo.mx"] [uri "/wp-json/wp/v2/users/1"] [unique_id "Z9PNolt_H6naBZQrl2EwMwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-03-11 09:25:57
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 11 05:25:50.565107 2025] [security2:error] [pid 11007:tid 11007] [client 2a03:2880:f806:b:::56284] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.raintechgutters.com|F|2"] [data ".raintechgutters.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.raintechgutters.com"] [uri "/gutter-contractors-near-me-orlando/www.raintechgutters.com"] [unique_id "Z9ABnhAXbnEmf2NnW2H5mgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
LotPhantom
2025-02-26 12:30:25
(1 year ago)
2a03:2880:f806:b:: - - [26/Feb/2025:12:26:09 +0000] "GET /sitemap.xml HTTP/2.0" 404 9 "-" "meta-exte ...
show more
2a03:2880:f806:b:: - - [26/Feb/2025:12:26:09 +0000] "GET /sitemap.xml HTTP/2.0" 404 9 "-" "meta-externalagent/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-02-08 16:11:30
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Feb 08 11:11:24.639479 2025] [security2:error] [pid 20005:tid 20005] [client 2a03:2880:f806:b:::36176] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||williamfitzsimmons.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "williamfitzsimmons.com"] [uri "/news/0410-william-fitzsimmons-spring-tour-update/themodclub.com"] [unique_id "Z6eCLGaiAux2tXNhQXOglwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-01-30 03:59:50
(1 year ago)
[Drupal AbuseIPDB module] Request path is blacklisted. /wp-content/uploads/2022/12/Ando-O-webpage-ma ...
show more
[Drupal AbuseIPDB module] Request path is blacklisted. /wp-content/uploads/2022/12/Ando-O-webpage-main-aspect-ratio-400-400.png
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-31 15:03:56
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 31 10:03:52.812959 2024] [security2:error] [pid 27112:tid 27112] [client 2a03:2880:f806:b:::35098] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.alafiariverrendezvous.org|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.alafiariverrendezvous.org"] [uri "/wp-json/wp/v2/users/1"] [unique_id "Z3QH2EuLwnv3nD32pyeW3wAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-30 17:56:20
(1 year ago)
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 30 12:56:17.138902 2024] [security2:error] [pid 6378:tid 6378] [client 2a03:2880:f806:b:::37838] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||www.vangentholding.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "www.vangentholding.com"] [uri "/wp-json/wp/v2/users/281035"] [unique_id "Z3LewTGIuv7PKKo5CBAlYgAAAAE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-29 10:06:02
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Dec 29 05:05:59.258434 2024] [security2:error] [pid 3130557:tid 3130557] [client 2a03:2880:f806:b:::56792] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||angelonearth.net|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "angelonearth.net"] [uri "/BMWImages/WS_FTP.LOG"] [unique_id "Z3EfB3iXgKrXvQkjK97eZQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-23 12:02:00
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 23 07:01:54.612339 2024] [security2:error] [pid 1150666:tid 1150666] [client 2a03:2880:f806:b:::56838] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.flavornet.org|F|2"] [data ".pdb"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.flavornet.org"] [uri "/info/jmol/pdb/629-97-0.pdb"] [unique_id "Z2lRMle_xTCRwGcQoZfSpAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-12-17 15:01:32
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:b:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Dec 17 10:01:29.031674 2024] [security2:error] [pid 7363:tid 7363] [client 2a03:2880:f806:b:::54934] [client 2a03:2880:f806:b::] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||bahamascruisersguide.com|F|2"] [data ".blogspot.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "bahamascruisersguide.com"] [uri "/page26/snowbirdscompassrose.blogspot.com"] [unique_id "Z2GSScF-FvPV-Dfv007zKgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack