๐บ๐ธ
interbiznw.com
2026-06-18 00:07:31
(2 days ago)
malicious-web-requests-vulnerability-scanning
Hacking
Brute-Force
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 22:31:02
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 2a0a:c802:3:6::15e (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0a:c802:3:6::15e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 18:30:53.479972 2026] [security2:error] [pid 30580:tid 30580] [client 2a0a:c802:3:6::15e:54088] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||iee-usa.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "iee-usa.com"] [uri "/wp-content/debug.log"] [unique_id "ajMgHfwIdEcBLlLHWZpv1gAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-17 07:27:13
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 2a0a:c802:3:6::15e (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0a:c802:3:6::15e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 17 03:27:06.688591 2026] [security2:error] [pid 21047:tid 21071] [client 2a0a:c802:3:6::15e:33614] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||nimbll.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "nimbll.com"] [uri "/wp-content/debug.log"] [unique_id "ajJMSgnt2lFsHxPFOJQDTQAAAVY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
dynamix
2026-06-17 05:19:24
(3 days ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 21:02:48
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 2a0a:c802:3:6::15e (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0a:c802:3:6::15e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 17:02:42.837097 2026] [security2:error] [pid 14985:tid 14985] [client 2a0a:c802:3:6::15e:57086] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lukeschicago.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lukeschicago.com"] [uri "/wp-content/debug.log"] [unique_id "ajG58k9QkgrGMMzalCROzQAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 18:23:06
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 2a0a:c802:3:6::15e (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0a:c802:3:6::15e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 14:22:58.196852 2026] [security2:error] [pid 12990:tid 12990] [client 2a0a:c802:3:6::15e:44944] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||lemoulinavent.org|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "lemoulinavent.org"] [uri "/wp-content/debug.log"] [unique_id "ajGUgtcSgu1f933tjc15nQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-16 16:32:09
(4 days ago)
(mod_security) mod_security (id:210492) triggered by 2a0a:c802:3:6::15e (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210492) triggered by 2a0a:c802:3:6::15e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 16 12:32:03.723060 2026] [security2:error] [pid 21781:tid 21781] [client 2a0a:c802:3:6::15e:51160] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "wp-config.php" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "laecovillage.org"] [uri "/wp-config.php.bak"] [unique_id "ajF6g2BS2MNdnr6-Dov4pAAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
SLSLLC
2026-06-16 00:47:08
(4 days ago)
2a0a:c802:3:6::15e - - [16/Jun/2026:00:47:07 +0000] "GET /.env HTTP/2.0" 403 1858 "-" "Mozilla/5.0 ( ...
show more
2a0a:c802:3:6::15e - - [16/Jun/2026:00:47:07 +0000] "GET /.env HTTP/2.0" 403 1858 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36"
...
show less
Brute-Force
Web App Attack
๐จ๐ฆ
Anytech
2026-06-15 03:13:54
(5 days ago)
Blocked by Conn-Monitor: Web scanning activity
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-15 00:49:40
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 2a0a:c802:3:6::15e (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0a:c802:3:6::15e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 20:49:31.726452 2026] [security2:error] [pid 19199:tid 19199] [client 2a0a:c802:3:6::15e:43046] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thebrotherhoodlounge.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thebrotherhoodlounge.com"] [uri "/wp-content/debug.log"] [unique_id "ai9MG8rAGRXqxXO7PQNK3wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 21:36:17
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 2a0a:c802:3:6::15e (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0a:c802:3:6::15e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 17:36:08.465549 2026] [security2:error] [pid 25212:tid 25212] [client 2a0a:c802:3:6::15e:35796] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||stinsonbeachsurfandkayak.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "stinsonbeachsurfandkayak.com"] [uri "/wp-content/debug.log"] [unique_id "ai8eyB81JlQbFdJO65_dQwAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 18:05:18
(5 days ago)
(mod_security) mod_security (id:210730) triggered by 2a0a:c802:3:6::15e (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a0a:c802:3:6::15e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 14:05:08.790919 2026] [security2:error] [pid 28458:tid 28458] [client 2a0a:c802:3:6::15e:56606] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rodandreelpiercam.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rodandreelpiercam.com"] [uri "/wp-content/debug.log"] [unique_id "ai7tVFealBaHtz-CulI6BAAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
LRob.fr
2026-06-14 15:15:05
(6 days ago)
Repeated 404 errors, blocked by Fail2ban in custom-404 jail
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-14 14:25:16
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 2a0a:c802:3:6::15e (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a0a:c802:3:6::15e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 10:25:08.602793 2026] [security2:error] [pid 24662:tid 24662] [client 2a0a:c802:3:6::15e:55474] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||thenursingsite.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "thenursingsite.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai65xCBms1yVCW1kJlBtHAAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-14 14:08:35
(6 days ago)
(mod_security) mod_security (id:225170) triggered by 2a0a:c802:3:6::15e (Unknown): 1 in the last 300 ...
show more
(mod_security) mod_security (id:225170) triggered by 2a0a:c802:3:6::15e (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 14 10:08:29.261898 2026] [security2:error] [pid 31616:tid 31616] [client 2a0a:c802:3:6::15e:43764] ModSecurity: Access denied with code 403 (phase 2). Operator EQ matched 0 at REQUEST_COOKIES_NAMES. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/26_Apps_WordPress.conf"] [line "155"] [id "225170"] [rev "3"] [msg "COMODO WAF: Sensitive Information Disclosure Vulnerability in WordPress 4.7 (CVE-2017-5487)||salernospizza.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "WordPress"] [hostname "salernospizza.com"] [uri "/wp-json/wp/v2/users"] [unique_id "ai613UuM0BWzqpqfR5EZLAAAAFg"]
show less
Brute-Force
Bad Web Bot
Web App Attack