๐บ๐ธ
TPI-Abuse
2026-08-31 15:01:14
(12 hours ago)
(mod_security) mod_security (id:210492) triggered by 2a11:3b80::e0e4:662e:ca94:d57f (Unknown): 1 in ...
show more
(mod_security) mod_security (id:210492) triggered by 2a11:3b80::e0e4:662e:ca94:d57f (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 31 11:01:05.145834 2026] [security2:error] [pid 31421:tid 31432] [client 2a11:3b80::e0e4:662e:ca94:d57f:63152] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "paygulf.com"] [uri "/.git/index"] [unique_id "apWXMeQ5IaBB0esHgExHEAAAAMU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-08-25 00:16:04
(1 week ago)
Excessive 404/403 errors
Brute-Force
๐ณ๐ฑ
Site.eu
2026-08-23 11:51:51
(1 week ago)
Excessive 404/403 errors
Brute-Force
Anonymous
2026-08-23 08:14:05
(1 week ago)
2a11:3b80::e0e4:662e:ca94:d57f - - [23/Aug/2026:16:13:59 +0800] "GET /logs/access.log HTTP/1.1" 404 ...
show more
2a11:3b80::e0e4:662e:ca94:d57f - - [23/Aug/2026:16:13:59 +0800] "GET /logs/access.log HTTP/1.1" 404 26371 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
2a11:3b80::e0e4:662e:ca94:d57f - - [23/Aug/2026:16:14:00 +0800] "GET /access.log HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
2a11:3b80::e0e4:662e:ca94:d57f - - [23/Aug/2026:16:14:01 +0800] "GET /storage/logs/laravel.log HTTP/1.1" 404 26371 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
2a11:3b80::e0e4:662e:ca94:d57f - - [23/Aug/2026:16:14:01 +0800] "GET /storage/logs/laravel-2026-08-16.log HTTP/1.1" 404 26371 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
2a11:3b80::e0e4:662e:ca94:d57f - - [23/Aug/2026:16:14:02 +0800] "GET /webhook.txt HTTP/1.1" 403 199 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:128.0) Gecko/20100101 Firefox/128.0"
2a11:3b80::e0e4:662
...
show less
Bad Web Bot
Web App Attack
๐ฉ๐ช
FD-IX
2026-08-22 08:40:41
(1 week ago)
Fail2Ban: ModSecurity detected a web application attack.
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-22 05:38:41
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::e0e4:662e:ca94:d57f (Unknown): 1 in ...
show more
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::e0e4:662e:ca94:d57f (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 22 01:38:31.877739 2026] [security2:error] [pid 11883:tid 11883] [client 2a11:3b80::e0e4:662e:ca94:d57f:58746] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||webuychesterfieldhouses.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "webuychesterfieldhouses.com"] [uri "/logs/combined.log"] [unique_id "aok11yPhzz1_slFpz71EPwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 21:08:35
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::e0e4:662e:ca94:d57f (Unknown): 1 in ...
show more
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::e0e4:662e:ca94:d57f (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 17:08:26.969809 2026] [security2:error] [pid 30654:tid 30654] [client 2a11:3b80::e0e4:662e:ca94:d57f:51222] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||voodooshop.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "voodooshop.com"] [uri "/logs/combined.log"] [unique_id "aoi-Shql2Y6iF4C30HjfHAAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-21 04:14:36
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::e0e4:662e:ca94:d57f (Unknown): 1 in ...
show more
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::e0e4:662e:ca94:d57f (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 21 00:14:29.263886 2026] [security2:error] [pid 4341:tid 4341] [client 2a11:3b80::e0e4:662e:ca94:d57f:53029] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||uniquetreasuresshops.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "uniquetreasuresshops.com"] [uri "/access.log"] [unique_id "aofQpe6aS8_5CvH_ZLrcWgAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-08-20 15:40:42
(1 week ago)
[20/Aug/2026:18:40:41 +0300] 178724044180.286838 2a11:3b80::e0e4:662e:ca94:d57f 58319 2a01:4f8:202:4 ...
show more
[20/Aug/2026:18:40:41 +0300] 178724044180.286838 2a11:3b80::e0e4:662e:ca94:d57f 58319 2a01:4f8:202:41d3::2 80
[20/Aug/2026:18:40:41 +0300] 178724044198.634004 2a11:3b80::e0e4:662e:ca94:d57f 58369 2a01:4f8:202:41d3::2 80
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-20 04:00:39
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::e0e4:662e:ca94:d57f (Unknown): 1 in ...
show more
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::e0e4:662e:ca94:d57f (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Aug 20 00:00:33.880787 2026] [security2:error] [pid 27484:tid 27484] [client 2a11:3b80::e0e4:662e:ca94:d57f:51798] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||theradarshop.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "theradarshop.com"] [uri "/logs/access.log"] [unique_id "aoZ74dqEqaiJJIMirUTKqwAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
WeCloudit-Anti-Abuse
2026-08-19 02:17:35
(1 week ago)
This IP was detected by CrowdSec triggering crowdsecurity/http-probing
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-08-18 23:32:40
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::e0e4:662e:ca94:d57f (Unknown): 1 in ...
show more
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::e0e4:662e:ca94:d57f (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Aug 18 19:32:32.301513 2026] [security2:error] [pid 789:tid 789] [client 2a11:3b80::e0e4:662e:ca94:d57f:63516] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||srsrestoration.net|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "srsrestoration.net"] [uri "/log/access.log"] [unique_id "aoTrkEc639yisrmGkK4hiAAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-17 13:58:35
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::e0e4:662e:ca94:d57f (Unknown): 1 in ...
show more
(mod_security) mod_security (id:210730) triggered by 2a11:3b80::e0e4:662e:ca94:d57f (Unknown): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Aug 17 09:58:30.157624 2026] [security2:error] [pid 12988:tid 12988] [client 2a11:3b80::e0e4:662e:ca94:d57f:63036] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||snapdragonworkshops.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "snapdragonworkshops.com"] [uri "/access.log"] [unique_id "aoMThmTNgXBD4UDAvdOEIQAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack