๐ช๐ธ
alferez
2026-08-24 21:47:39
(1 day ago)
Searching .(env|sql|zip|tar|rar) files
Hacking
Exploited Host
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-24 00:19:58
(2 days ago)
Excessive 404/403 errors
Brute-Force
๐ณ๐ฑ
Site.eu
2026-08-22 12:38:48
(4 days ago)
Excessive 404/403 errors
Brute-Force
๐บ๐ธ
TPI-Abuse
2026-08-19 15:55:36
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::540:4569:be55:d0e1 (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::540:4569:be55:d0e1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 19 11:55:30.152169 2026] [security2:error] [pid 25870:tid 25870] [client 2a11:3b80::540:4569:be55:d0e1:65135] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||backstore.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "backstore.com"] [uri "/stressless-chair/Ekornes.htm/logs/combined.log"] [unique_id "aoXR8malsUr5MFve2H_GdAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ต๐ฑ
Budyn
2026-08-19 08:11:54
(1 week ago)
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit ...
show more
Automated threat detected by Budyn Honeypot Sinkhole. Attack type: CRITICAL: ModSecurity WAF Exploit Block. Malicious scanner triggered a security trap targeting emulated vulnerabilities. Evidence: HOST: goblinpot.store | URI: /logs/access.log | UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0 | BODY: [Empty / GET Request]
show less
Hacking
Web App Attack
๐ซ๐ท
ELYAZ
2026-08-18 10:57:06
(1 week ago)
(y3) Failed access -byebye- from 2a11:3b80::540:4569:be55:d0e1 (Unknown): (CF_ENABLE)
Hacking
๐ณ๐ฑ
BlueWire Hosting
2026-08-17 22:21:03
(1 week ago)
Aggressive scanning resulting into 404
Bad Web Bot
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-17 15:42:47
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-17 14:59:35
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::540:4569:be55:d0e1 (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::540:4569:be55:d0e1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 10:59:26.766720 2026] [security2:error] [pid 29540:tid 29540] [client 2a11:3b80::540:4569:be55:d0e1:53208] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||cityofportales.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "cityofportales.com"] [uri "/log/access.log"] [unique_id "aoMhzo439vdWUeWS2PKPzAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 13:22:18
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::540:4569:be55:d0e1 (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::540:4569:be55:d0e1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 09:22:06.874818 2026] [security2:error] [pid 29351:tid 29363] [client 2a11:3b80::540:4569:be55:d0e1:53855] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dermatologybriargate.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dermatologybriargate.com"] [uri "/logs/combined.log"] [unique_id "aoMK_kJ5diA1CdPUpmxYRQAAAMo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-12 20:52:22
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::540:4569:be55:d0e1 (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::540:4569:be55:d0e1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 16:52:13.902059 2026] [security2:error] [pid 1470029:tid 1470029] [client 2a11:3b80::540:4569:be55:d0e1:53763] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rwcartoons.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rwcartoons.com"] [uri "/access.log"] [unique_id "anzc_ZWJ2kXCK7PkGRoN-gAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-12 18:30:23
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::540:4569:be55:d0e1 (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::540:4569:be55:d0e1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 14:30:15.287295 2026] [security2:error] [pid 1536488:tid 1536488] [client 2a11:3b80::540:4569:be55:d0e1:57608] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||philcarta.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "philcarta.com"] [uri "/log/access.log"] [unique_id "any7tyoO7SUI5UH-EA7GmQAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-12 13:00:33
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::540:4569:be55:d0e1 (Unknown): 1 in t ...
show more
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::540:4569:be55:d0e1 (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 09:00:25.535713 2026] [security2:error] [pid 31694:tid 31694] [client 2a11:3b80::540:4569:be55:d0e1:61714] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.abeltours.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.abeltours.com"] [uri "/culinary-tour/logs/access.log"] [unique_id "anxuaaJP8KTG2DKBHRHkYQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack