๐ฌ๐ง
Mendip_Defender
2026-06-19 11:34:38
(2 months ago)
2a03:2880:f806:c:: - - [19/Jun/2026:12:34:31 +0100] "GET /amenities/village-churches/ HTTP/1.1" 200 ...
show more
2a03:2880:f806:c:: - - [19/Jun/2026:12:34:31 +0100] "GET /amenities/village-churches/ HTTP/1.1" 200 15954 "-" "meta-externalads/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Bad Web Bot
Anonymous
2026-06-18 10:17:11
(2 months ago)
[ns3.backorder.gr] httpd-noisy-crawler-swarm: sites=gosolar.gr; logs=/var/log/httpd/domains/gosolar. ...
show more
[ns3.backorder.gr] httpd-noisy-crawler-swarm: sites=gosolar.gr; logs=/var/log/httpd/domains/gosolar.gr.log; samples=crawler=meta-webindexer | window=5m | distinct_ips=61
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 20:57:50
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:c:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 16:57:43.066135 2026] [security2:error] [pid 18230:tid 18230] [client 2a03:2880:f806:c:::30438] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||stickittomebuttons.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stickittomebuttons.com"] [uri "/stickittomebuttons.com"] [unique_id "ainPx6iqFRCtXtAQ9N-qEgAAADI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-09 23:17:21
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:c:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 09 19:17:18.664943 2026] [security2:error] [pid 6924:tid 6924] [client 2a03:2880:f806:c:::60514] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nesetsv.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nesetsv.com"] [uri "/nesetsv.com"] [unique_id "aiie_mTfiCZSp3PcAsf4ywAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 21:44:13
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:c:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 17:44:09.027748 2026] [security2:error] [pid 25371:tid 25371] [client 2a03:2880:f806:c:::24654] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||leirstein.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "leirstein.com"] [uri "/leirstein.com"] [unique_id "aic3qQdS5CCl6uBc-ebLUgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-06 19:42:53
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:c:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 15:42:45.086755 2026] [security2:error] [pid 24183:tid 24183] [client 2a03:2880:f806:c:::32950] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||roselockecasting.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "roselockecasting.com"] [uri "/roselockecasting.com"] [unique_id "aiR4NfNEF8WXzGKpJKtHJgAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gui-ying233
2026-06-05 00:23:37
(3 months ago)
meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-04 19:15:13
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:c:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 15:14:55.756865 2026] [security2:error] [pid 2846:tid 2846] [client 2a03:2880:f806:c:::24864] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||wallawallafirearmstraining.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "wallawallafirearmstraining.com"] [uri "/wallawallafirearmstraining.com"] [unique_id "aiHOr2Beq_2VwY474gGTrgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-04 10:00:43
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:c:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 06:00:35.908354 2026] [security2:error] [pid 20217:tid 20217] [client 2a03:2880:f806:c:::27250] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||vc1.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vc1.com"] [uri "/vc1.com"] [unique_id "aiFMw7XTfXoWB-ECqIfWrgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gui-ying233
2026-06-04 00:22:03
(3 months ago)
meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Bad Web Bot
๐บ๐ธ
gui-ying233
2026-06-03 00:10:04
(3 months ago)
meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-02 17:33:52
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:c:: (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:2880:f806:c:: (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 13:33:47.873533 2026] [security2:error] [pid 4542:tid 4542] [client 2a03:2880:f806:c:::33840] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||swindon-itf.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "swindon-itf.com"] [uri "/swindon-itf.com"] [unique_id "ah8T-5lEjcxO3PP0kiy-HgAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-01 18:28:13
(3 months ago)
[ssd5.kdns.gr] httpd-storefront-action-swarm: sites=e-anastasiadis.gr; logs=/var/log/httpd/domains/e ...
show more
[ssd5.kdns.gr] httpd-storefront-action-swarm: sites=e-anastasiadis.gr; logs=/var/log/httpd/domains/e-anastasiadis.gr.log; samples=site_wide=true | distinct_ips=43 | action_types=2
show less
Hacking
Web App Attack
๐ฌ๐ง
Mendip_Defender
2026-06-01 12:58:36
(3 months ago)
2a03:2880:f806:c:: - - [01/Jun/2026:13:58:33 +0100] "GET /ashwick-parish-council/parish-council-meet ...
show more
2a03:2880:f806:c:: - - [01/Jun/2026:13:58:33 +0100] "GET /ashwick-parish-council/parish-council-meetings/ HTTP/1.1" 200 17136 "-" "meta-externalads/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)"
...
show less
Bad Web Bot
๐บ๐ธ
gui-ying233
2026-06-01 03:25:10
(3 months ago)
meta-webindexer/1.1 (+https://developers.facebook.com/docs/sharing/webmasters/crawler)
Bad Web Bot