๐บ๐ธ
TPI-Abuse
2026-09-30 01:33:16
(1 day ago)
(mod_security) mod_security (id:217210) triggered by 3.90.118.141 (ec2-3-90-118-141.compute-1.amazon ...
show more
(mod_security) mod_security (id:217210) triggered by 3.90.118.141 (ec2-3-90-118-141.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 29 21:33:12.924142 2026] [security2:error] [pid 31187:tid 31187] [client 3.90.118.141:62425] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||gapanda.com|F|4"] [data "GET ?C=D;O=A HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "gapanda.com"] [uri "/"] [unique_id "arxm2FfgBJMzyujMPC5phgAAAA0"], referer: http://gapanda.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-27 05:26:35
(4 days ago)
(mod_security) mod_security (id:217210) triggered by 3.90.118.141 (ec2-3-90-118-141.compute-1.amazon ...
show more
(mod_security) mod_security (id:217210) triggered by 3.90.118.141 (ec2-3-90-118-141.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 27 01:26:30.401254 2026] [security2:error] [pid 21899:tid 21899] [client 3.90.118.141:59035] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||nexthop.com|F|4"] [data "GET ?C=N;O=D HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "nexthop.com"] [uri "/"] [unique_id "aripBpeN-24ZiC6ne-It4gAAABc"], referer: http://nexthop.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-01 23:22:06
(4 weeks ago)
(mod_security) mod_security (id:217210) triggered by 3.90.118.141 (ec2-3-90-118-141.compute-1.amazon ...
show more
(mod_security) mod_security (id:217210) triggered by 3.90.118.141 (ec2-3-90-118-141.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 01 19:22:01.945962 2026] [security2:error] [pid 27811:tid 27811] [client 3.90.118.141:3811] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||toptek.com|F|4"] [data "GET ?C=S;O=A HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "toptek.com"] [uri "/"] [unique_id "apdeGSmGPMH7V3z7QuMqqAAAAAg"], referer: https://toptek.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-14 16:56:11
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 3.90.118.141 (ec2-3-90-118-141.compute-1.amazon ...
show more
(mod_security) mod_security (id:210730) triggered by 3.90.118.141 (ec2-3-90-118-141.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Aug 14 12:56:04.191989 2026] [security2:error] [pid 27022:tid 27022] [client 3.90.118.141:17519] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||elsmithpest.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "elsmithpest.com"] [uri "/[email protected] "] [unique_id "an9IpDoq2upkWqqzBTFqdAAAAAM"], referer: http://elsmithpest.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-12 13:00:08
(1 month ago)
(mod_security) mod_security (id:217210) triggered by 3.90.118.141 (ec2-3-90-118-141.compute-1.amazon ...
show more
(mod_security) mod_security (id:217210) triggered by 3.90.118.141 (ec2-3-90-118-141.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Aug 12 09:00:01.629979 2026] [security2:error] [pid 9758:tid 9758] [client 3.90.118.141:25748] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||sheamar.com|F|4"] [data "GET ?C=S;O=A HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "sheamar.com"] [uri "/"] [unique_id "anxuURExVN5a9yhsi2xHwAAAAAY"], referer: http://sheamar.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-08-12 02:21:55
(1 month ago)
[WedAug1204:21:52.8487972026][security2:error][pid2966214:tid2966236][client3.90.118.141:0]ModSecuri ...
show more
[WedAug1204:21:52.8487972026][security2:error][pid2966214:tid2966236][client3.90.118.141:0]ModSecurity:Accessdeniedwithcode403\(phase1\).Patternmatch\"\(\?i\)\(curl\|wget\|python\|nikto\|sqlmap\|acunetix\|fimap\|dirbuster\|cmsmap\)\"atREQUEST_HEADERS:User-Agent.[file\"/etc/apache2/conf.d/modsec_custom_rules.conf\"][line\"217\"][id\"990210\"][msg\"Suspicioususer-agentblocked\"][hostname\"www.sisuconsulting.net\"][uri\"/\"][unique_id\"anvYwMvq4IgXG6HrWECu8gAAABM\"]
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-08-08 03:05:11
(1 month ago)
Request Overload (427)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-08-07 02:05:07
(1 month ago)
Request Overload (224)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-08-06 01:05:15
(1 month ago)
Request Overload (135)
Brute-Force
Web App Attack
๐บ๐ธ
mnsf
2026-08-05 00:05:14
(1 month ago)
Request Overload (108)
Brute-Force
Web App Attack
Anonymous
2026-05-13 09:28:07
(4 months ago)
FortiWeb WAF: 39 attacks detected. Threat Score: 5200. Types: Client Management(19), HTTP Protocol C ...
show more
FortiWeb WAF: 39 attacks detected. Threat Score: 5200. Types: Client Management(19), HTTP Protocol Constraints(19), Biometrics Based Detection(1). Origin: United States.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 17:01:43
(4 months ago)
(mod_security) mod_security (id:217210) triggered by 3.90.118.141 (ec2-3-90-118-141.compute-1.amazon ...
show more
(mod_security) mod_security (id:217210) triggered by 3.90.118.141 (ec2-3-90-118-141.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 13:01:40.453909 2026] [security2:error] [pid 24683:tid 24683] [client 3.90.118.141:3391] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||randeen.com|F|4"] [data "GET ?C=M;O=A HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "randeen.com"] [uri "/"] [unique_id "agILdIKxk1gODNgriDyAuwAAABs"], referer: http://randeen.com
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-05-11 06:58:48
(4 months ago)
(mod_security) mod_security (id:210730) triggered by 3.90.118.141 (ec2-3-90-118-141.compute-1.amazon ...
show more
(mod_security) mod_security (id:210730) triggered by 3.90.118.141 (ec2-3-90-118-141.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon May 11 02:58:43.558918 2026] [security2:error] [pid 7189:tid 7189] [client 3.90.118.141:42309] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.chicagowca.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.chicagowca.com"] [uri "/[email protected] "] [unique_id "agF-I_6AVr7HoC35r-d4ggAAABA"], referer: https://www.chicagowca.com/contact.html
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
stechusa
2026-03-24 10:37:07
(6 months ago)
[Askari] ELEVATED_THREAT | country=US | ASN=Amazon.com, Inc. | 30 unique facet paths in 5 minutes (t ...
show more
[Askari] ELEVATED_THREAT | country=US | ASN=Amazon.com, Inc. | 30 unique facet paths in 5 minutes (threshold: 30) | 31 unique facet paths in 5 minutes (threshold: 30) | 32 unique facet paths in 5 minutes (threshold: 30) | Signals: path_concentration, rapid_facet_enumeration, high_path_entropy, concurrent_facet_load, http1_only
show less
Web App Attack
Hacking
Web Spam
DDoS Attack
๐บ๐ธ
stechusa
2026-03-24 10:37:07
(6 months ago)
ELEVATED_THREAT | country=US | ASN=Amazon.com, Inc. | 30 unique facet paths in 5 minutes (threshold: ...
show more
ELEVATED_THREAT | country=US | ASN=Amazon.com, Inc. | 30 unique facet paths in 5 minutes (threshold: 30) | 31 unique facet paths in 5 minutes (threshold: 30) | 32 unique facet paths in 5 minutes (threshold: 30)
show less
Web App Attack
Hacking
Web Spam