🇺🇸
TPI-Abuse
2026-08-28 21:58:05
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 2a09:bac5:4e23:c8::14:2f7 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 2a09:bac5:4e23:c8::14:2f7 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:57:57.027303 2026] [security2:error] [pid 3275:tid 3275] [client 2a09:bac5:4e23:c8::14:2f7:44606] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||oximoron.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "oximoron.com"] [uri "/z9x8c7v6b5-debug-trigger-oximoron.com"] [unique_id "apIEZaACK98MYO5JjkGV2AAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-08-28 21:33:43
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 2a09:bac5:4e23:c8::14:2f7 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 2a09:bac5:4e23:c8::14:2f7 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 28 17:33:37.984838 2026] [security2:error] [pid 15531:tid 15531] [client 2a09:bac5:4e23:c8::14:2f7:56370] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||phoneresponse.com|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "phoneresponse.com"] [uri "/rclone.conf"] [unique_id "apH-sVJXAt6XYLF-mMyPegAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇳🇱
Site.eu
2026-07-12 14:19:12
(1 month ago)
Excessive 404/403 errors
Brute-Force
🇺🇸
TPI-Abuse
2026-07-12 13:58:10
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:4e23:c8::14:2f7 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:4e23:c8::14:2f7 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 09:58:06.278367 2026] [security2:error] [pid 4177071:tid 4177071] [client 2a09:bac5:4e23:c8::14:2f7:53016] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "frootloops.net"] [uri "/.git/config"] [unique_id "alOdbu5NpBSnc8yyBS8jmgAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-12 11:49:57
(1 month ago)
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:4e23:c8::14:2f7 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210492) triggered by 2a09:bac5:4e23:c8::14:2f7 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 07:49:53.383517 2026] [security2:error] [pid 9793:tid 9793] [client 2a09:bac5:4e23:c8::14:2f7:52148] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.env" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "billystuff.net"] [uri "/.env"] [unique_id "alN_YY5sOGyoB7JGY5NEzwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-07-12 11:33:36
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 2a09:bac5:4e23:c8::14:2f7 (Unknown): 1 in the l ...
show more
(mod_security) mod_security (id:210730) triggered by 2a09:bac5:4e23:c8::14:2f7 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jul 12 07:33:31.771187 2026] [security2:error] [pid 28612:tid 28612] [client 2a09:bac5:4e23:c8::14:2f7:31996] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||franknash.nashes.net|F|2"] [data ".axd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "franknash.nashes.net"] [uri "/elmah.axd"] [unique_id "alN7ixiI07W3q5iIN36LVwAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇮
oh.mg
2026-07-12 11:29:21
(1 month ago)
2a09:bac5:4e23:c8::14:2f7 - - [12/Jul/2026:13:25:28 +0200] "GET /service-worker.js HTTP/1.1" 403 543 ...
show more
2a09:bac5:4e23:c8::14:2f7 - - [12/Jul/2026:13:25:28 +0200] "GET /service-worker.js HTTP/1.1" 403 543 "-" "Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html)"
2a09:bac5:4e23:c8::14:2f7 - - [12/Jul/2026:13:25:36 +0200] "GET /runtime-config.js HTTP/1.1" 403 2462 "-" "Mozilla/5.0 (compatible; Google-Extended/1.0; +http://www.google.com/bot.html)"
2a09:bac5:4e23:c8::14:2f7 - - [12/Jul/2026:13:29:17 +0200] "GET /.git-credentials HTTP/1.1" 403 504 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; GPTBot/1.2; +https://openai.com/gptbot"
2a09:bac5:4e23:c8::14:2f7 - - [12/Jul/2026:13:29:19 +0200] "GET /rclone.conf HTTP/1.1" 403 504 "-" "Mozilla/5.0 AppleWebKit/537.36 (KHTML, like Gecko); compatible; OAI-SearchBot/1.0; +https://openai.com/searchbot"
2a09:bac5:4e23:c8::14:2f7 - - [12/Jul/2026:13:29:20 +0200] "GET /.env HTTP/1.1" 403 504 "-" "Mozilla/5.0 (compatible; Bytespider; [email protected] )"
...
show less
Bad Web Bot
Web App Attack
🇩🇪
AetherFox
2026-07-12 08:55:36
(1 month ago)
AetherFox VoidGuard detected: [Sun Jul 12 08:55:30.588947 2026] [authz_core:error] [pid 654757:tid 6 ...
show more
AetherFox VoidGuard detected: [Sun Jul 12 08:55:30.588947 2026] [authz_core:error] [pid 654757:tid 654792] [client 2a09:bac5:4e23:c8::14:2f7:42920] AH01630: client denied by server configuration: proxy:https://[MASKED]/
[Sun Jul 12 08:55:34.126768 2026] [authz_core:error] [pid 654757:tid 654764] [client 2a09:bac5:4e23:c8::14:2f7:42920] AH01630: client denied by server configuration: proxy:https://[MASKED]/.env.production
[Sun Jul 12 08:55:34.989673 2026] [authz_core:error] [pid 654757:tid 654794] [client 2a09:bac5:4e23:c8::14:2f7:42926] AH01630: client denied by server configuration: proxy:https://[MASKED]/.git/HEAD
[Sun Jul 12 08:55:35.039835 2026] [authz_core:error] [pid 654757:tid 654770] [client 2a09:bac5:4e23:c8::14:2f7:42920] AH01630: client denied by server configuration: proxy:https://[MASKED]/.github/workflows/deploy.yml
[Sun Jul 12 08:55:35.913275 2026] [authz_core:error] [pid 654757:tid 654780] [client 2a09:bac5:4e23:c8::14:2f7:42926] AH01630:
...
show less
Bad Web Bot
Web App Attack