Anonymous
2026-07-01 04:33:31
(4 days ago)
Failed login attempt detected by Fail2Ban in plesk-modsecurity jail
Exploited Host
๐ญ๐บ
kranem
2026-06-22 06:00:17
(1 week ago)
Triggered Cloudflare WAF from NL.
Action taken: LINK_MAZE_INJECTED
ASN: 62005 (BlueVPS OU)
Protocol: ...
show more
Triggered Cloudflare WAF from NL.
Action taken: LINK_MAZE_INJECTED
ASN: 62005 (BlueVPS OU)
Protocol: HTTP/1.1 (GET method)
Endpoint: /autodiscover/autodiscover.xml
Timestamp: 2026-06-22T04:54:45Z
User-Agent: Python/3.14 aiohttp/3.13.5
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-22 05:14:55
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a (Unknown): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 22 01:14:50.508953 2026] [security2:error] [pid 8138:tid 8138] [client 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a:64459] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||presucad.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "presucad.com"] [uri "/rpc/rpcproxy.dll"] [unique_id "ajjEyovcgi4_r6BEs9wINQAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐จ๐ฆ
Not Fake
2026-06-16 07:56:49
(2 weeks ago)
$f2bV_matches
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 10:56:20
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a (Unknown): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 06:56:09.092346 2026] [security2:error] [pid 17085:tid 17085] [client 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a:52360] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mrbaystreet.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mrbaystreet.com"] [uri "/rpc/rpcproxy.dll"] [unique_id "aiqUSWYLqk7LujqINLC_bwAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-10 11:50:20
(3 weeks ago)
17 requests with url.path *.dll
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-06-10 10:43:48
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a (Unknown): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 06:43:42.669211 2026] [security2:error] [pid 1229:tid 1229] [client 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a:56234] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||superlamb.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "superlamb.com"] [uri "/rpc/rpcproxy.dll"] [unique_id "aik_3nZ-dGSJh7jUEQWNDQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
filstal.org
2026-06-08 12:34:39
(3 weeks ago)
Bad bot activity detected (automated scraping/probing) UA: Python/3.14 aiohttp/3.13.5
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-08 08:24:54
(3 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a (Unknown): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Jun 08 04:24:45.953154 2026] [security2:error] [pid 19267:tid 19267] [client 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a:58925] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||powerkiteforum.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "powerkiteforum.com"] [uri "/rpc/rpcproxy.dll"] [unique_id "aiZ8TR51rv4HHpaq7fA6pQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
BlueWire Hosting
2026-06-04 14:51:14
(1 month ago)
Bad bot ignoring robot.txt
Bad Web Bot
๐ฆ๐บ
2000cn.com.au
2026-06-04 13:42:02
(1 month ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-sensitive-files
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-04 11:55:17
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a (Unknown): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 04 07:55:10.297266 2026] [security2:error] [pid 28483:tid 28483] [client 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a:53780] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||agchurchkuwait.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "agchurchkuwait.com"] [uri "/rpc/rpcproxy.dll"] [unique_id "aiFnnjGtGvM4RafV-vf9vQAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-03 09:40:53
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a (Unknown): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 05:40:45.281876 2026] [security2:error] [pid 17204:tid 17204] [client 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a:63181] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||fashionmenswear.com|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "fashionmenswear.com"] [uri "/rpc/rpcproxy.dll"] [unique_id "ah_2nUT-aVYK48ISvY2t8AAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ง๐ช
cmbplf
2026-06-01 07:33:23
(1 month ago)
25 requests with url.path *.dll
Brute-Force
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-05-21 03:44:15
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a (Unknown): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 20 23:44:06.502806 2026] [security2:error] [pid 12257:tid 12257] [client 2a10:1fc0:c:0:dc9c:a8ef:a967:4d7a:55512] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||mail.saadeh.ws|F|2"] [data ".dll"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "mail.saadeh.ws"] [uri "/rpc/rpcproxy.dll"] [unique_id "ag5_hs2cbRFybnPa9-0jIgAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack