๐บ๐ธ
TPI-Abuse
2026-10-01 12:00:50
(43 minutes ago)
(mod_security) mod_security (id:210730) triggered by 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e (Unknown) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 08:00:42.868351 2026] [security2:error] [pid 12791:tid 12791] [client 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||shubil.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "shubil.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "ar5Lat2EZGRjeUrp6QprJAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 11:44:39
(59 minutes ago)
(mod_security) mod_security (id:210730) triggered by 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e (Unknown) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:44:34.219014 2026] [security2:error] [pid 6919:tid 6919] [client 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thectegroup.net|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thectegroup.net"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "ar5HosZZ-OqmMlHHZMvMPQAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Aetherweb Ark
2026-10-01 11:13:11
(1 hour ago)
(mod_security) mod_security (id:949110) triggered by 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e (Unknown) ...
show more
(mod_security) mod_security (id:949110) triggered by 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e (Unknown): N in the last X secs
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 11:04:07
(1 hour ago)
(mod_security) mod_security (id:210730) triggered by 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e (Unknown) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 07:04:02.270530 2026] [security2:error] [pid 4063:tid 4063] [client 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e:50441] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||directcap.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "directcap.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "ar4-InBDdUEANlQdDlJeEAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-10-01 10:29:55
(2 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e (F ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e (FR/France/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e - - [01/Oct/2026:12:29:50 +0200] "GET //vendor/phpunit/phpunit/phpunit.xsd HTTP/1.1" 301 301 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0" "2a05:f480:1c00:9bf:5400:6ff:fec6:f75e" host=vortici.it
show less
Port Scan
๐ง๐ช
Saec
2026-10-01 10:23:25
(2 hours ago)
Jarvis auto-ban: Honeypot //vendor/phpunit/phpunit/phpunit.xsd via saec.me [FR] ASN:The Constant Com ...
show more
Jarvis auto-ban: Honeypot //vendor/phpunit/phpunit/phpunit.xsd via saec.me [FR] ASN:The Constant Company, LLC.
show less
Port Scan
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 10:11:09
(2 hours ago)
(mod_security) mod_security (id:210730) triggered by 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e (Unknown) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 06:11:04.375935 2026] [security2:error] [pid 30154:tid 30154] [client 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ruralcommunitycare.org|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ruralcommunitycare.org"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "ar4xuCSQvUIH-42dDOCJhgAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ญ๐บ
whitehoodie
2026-10-01 09:56:05
(2 hours ago)
AUTOMATED REPORT: Trying to access PHPUnit scripts: //vendor/phpunit/phpunit/phpunit.xsd
Hacking
Bad Web Bot
Web App Attack
๐ฉ๐ช
maxpower
2026-10-01 09:33:17
(3 hours ago)
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e (F ...
show more
(exploit_critical) REGOLA 2 - Critical File Exploit Attempt 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e (FR/France/-): 1 in the last 3600 secs; Ports: *; Direction: inout; Trigger: LF_CUSTOMTRIGGER; Logs: 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e - - [01/Oct/2026:11:33:15 +0200] "GET //vendor/phpunit/phpunit/phpunit.xsd HTTP/2.0" 301 0 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0" "2a05:f480:1c00:9bf:5400:6ff:fec6:f75e" host=focusabruzzo.eu
show less
Port Scan
๐ฉ๐ช
arnisolutions
2026-10-01 09:22:14
(3 hours ago)
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production s ...
show more
Vulnerability scanning (requests for admin panels, shells, backup files etc.) against a production server. Observed on 1 day(s) between 2026-10-01 and 2026-10-01 (UTC). Sample request: GET //vendor/phpunit/phpunit/phpunit.xsd HTTP/2.0
show less
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-10-01 09:08:33
(3 hours ago)
(mod_security) mod_security (id:210730) triggered by 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e (Unknown) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 05:08:28.567390 2026] [security2:error] [pid 26264:tid 26264] [client 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||vertubet.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "vertubet.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "ar4jDLPmEnazwIPNklVObwAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-10-01 08:41:53
(4 hours ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: dont-eat-the-pudding.xyz | URI: //vendor/phpunit/phpunit/phpunit.xsd | UA: Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-01 08:33:47
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e (Unknown) ...
show more
(mod_security) mod_security (id:210730) triggered by 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 01 04:33:41.391234 2026] [security2:error] [pid 6038:tid 6038] [client 2a05:f480:1c00:9bf:5400:6ff:fec6:f75e:0] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||portfoliolighting.net|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "portfoliolighting.net"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "ar4a5ZkqUB-AyzSq3JaNgwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack