๐ฑ๐น
juozaspo
2026-08-14 15:22:15
(1 week ago)
Automatic Report: Ignores robots.txt, visited bot-trap page linked through a hidden link, auto-banne ...
show more
Automatic Report: Ignores robots.txt, visited bot-trap page linked through a hidden link, auto-banned
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-08-05 03:21:45
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a03:b0c0:1:d0::be3:b001 (Unknown): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:b0c0:1:d0::be3:b001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 04 23:21:39.071239 2026] [security2:error] [pid 28468:tid 28468] [client 2a03:b0c0:1:d0::be3:b001:51802] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||accordionstars.com|F|2"] [data ".accordionfactory.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "accordionstars.com"] [uri "/www.accordionfactory.com"] [unique_id "anKsQ2QnOSt9jRABnKZJUwAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
jasperedv.de
2026-07-30 13:54:23
(3 weeks ago)
Apache Login - Brutforcing
Web App Attack
Brute-Force
๐จ๐ฆ
lakered
2026-07-28 06:38:19
(4 weeks ago)
Detectors: [NGINX] | Reasons: Automated scan targeting an unauthorized host or default server sinkho ...
show more
Detectors: [NGINX] | Reasons: Automated scan targeting an unauthorized host or default server sinkhole | TCP Fingerprint: Unknown (Link:PPPoE, Uptime:37068m)
show less
Port Scan
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-27 13:59:50
(4 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a03:b0c0:1:d0::be3:b001 (Unknown): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:b0c0:1:d0::be3:b001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jul 27 09:59:43.837581 2026] [security2:error] [pid 6226:tid 6226] [client 2a03:b0c0:1:d0::be3:b001:60118] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||caretakerspestcontrol.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "caretakerspestcontrol.com"] [uri "/JMRussell.com"] [unique_id "amdkT0L7rxBWMW_CmS9BAgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
bazter.pro
2026-07-22 03:06:02
(1 month ago)
Auto-Ban [2026-07-22 03:06:02]: CRITICAL: bot trap (soft) | host=minasdeoro.org | route=/api/trap/ca ...
show more
Auto-Ban [2026-07-22 03:06:02]: CRITICAL: bot trap (soft) | host=minasdeoro.org | route=/api/trap/catalog-export | hits=1 | ua=Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko)
show less
Hacking
Web App Attack
๐ต๐ฑ
mscode.pl
2026-07-19 16:28:36
(1 month ago)
Triggered Cloudflare WAF (firewallCustom) from GB.
Action taken: BLOCK
ASN: 14061 (DigitalOcean, LLC ...
show more
Triggered Cloudflare WAF (firewallCustom) from GB.
Action taken: BLOCK
ASN: 14061 (DigitalOcean, LLC)
Protocol: HTTP/1.1 (GET method)
Zone: mscode.pl
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/124.0.0.0 Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-07-19 15:54:31
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 2a03:b0c0:1:d0::be3:b001 (Unknown): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:b0c0:1:d0::be3:b001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 19 11:54:24.694935 2026] [security2:error] [pid 9425:tid 9425] [client 2a03:b0c0:1:d0::be3:b001:36990] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||keystroke.info|F|2"] [data ".php.backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "keystroke.info"] [uri "/LocalSettings.php.backup"] [unique_id "alzzMECThDzaPoF7xsp0ewAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-03 11:55:34
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 2a03:b0c0:1:d0::be3:b001 (Unknown): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:b0c0:1:d0::be3:b001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 07:55:26.201887 2026] [security2:error] [pid 22217:tid 22222] [client 2a03:b0c0:1:d0::be3:b001:52592] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||barstowstationtoo.com|F|2"] [data ".barstow-station.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "barstowstationtoo.com"] [uri "/www.barstow-station.com"] [unique_id "akejLqfwf8PImgD65rLe7wAAAIM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 19:47:42
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 2a03:b0c0:1:d0::be3:b001 (Unknown): 1 in the la ...
show more
(mod_security) mod_security (id:210730) triggered by 2a03:b0c0:1:d0::be3:b001 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 15 15:47:35.912174 2026] [security2:error] [pid 1534:tid 1534] [client 2a03:b0c0:1:d0::be3:b001:55474] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.raintechgutters.com|F|2"] [data ".raintechgutters.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.raintechgutters.com"] [uri "/professional-rain-gutters-orlando/www.raintechgutters.com"] [unique_id "ajBW14VKfxc6EMqXeuhlRAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
jasperedv.de
2026-06-15 18:08:43
(2 months ago)
Apache Login - Brutforcing
Web App Attack
Brute-Force
๐ฉ๐ช
jasperedv.de
2026-06-06 03:15:29
(2 months ago)
Apache Login - Brutforcing
Web App Attack
Brute-Force
๐ฉ๐ช
ksol-hostmaster
2026-05-25 21:53:57
(3 months ago)
2026/05/25 23:53:56 [error] 19886#156965: *637634 access forbidden by rule, client: 2a03:b0c0:1:d0:: ...
show more
2026/05/25 23:53:56 [error] 19886#156965: *637634 access forbidden by rule, client: 2a03:b0c0:1:d0::be3:b001, server: new.hondaforum.hu, request: "GET / HTTP/1.1", host: "new.hondaforum.hu"
...
show less
Web Spam
๐บ๐ธ
LotPhantom
2026-05-22 02:34:33
(3 months ago)
2026/05/22 02:34:33 [error] 3442223#3442223: *50380 connect() failed (111: Connection refused) while ...
show more
2026/05/22 02:34:33 [error] 3442223#3442223: *50380 connect() failed (111: Connection refused) while connecting to upstream, client: 2a03:b0c0:1:d0::be3:b001, server: wynnesmiles.com, request: "GET / HTTP/1.1", upstream: "http://127.0.0.1:4001/", host: "wynnesmiles.com"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-05-15 02:50:44
(3 months ago)
Multiple unauthorized connection attempts
Web App Attack