๐ฆ๐บ
MAGIC
2026-06-05 01:07:01
(2 days ago)
VM1 Bad user agents ignoring web crawling rules. Draing bandwidth
DDoS Attack
Bad Web Bot
๐ณ๐ฑ
homeshowdomain.nl
2026-05-02 22:15:38
(1 month ago)
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on ...
show more
Auto-ban: single probe for restricted files (.env / backups / admin endpoints). Likely mass-scan on 2026-05-01.
show less
Web App Attack
SSH
Hacking
๐บ๐ธ
TPI-Abuse
2026-04-29 22:12:29
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 31.134.11.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 31.134.11.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 18:12:23.549886 2026] [security2:error] [pid 24385:tid 24385] [client 31.134.11.124:46935] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||thecalls.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "thecalls.net"] [uri "/s3cmd.ini"] [unique_id "afKCR2NS-FTHOugYbFM1ggAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-29 09:49:15
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 31.134.11.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 31.134.11.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 29 05:49:09.146197 2026] [security2:error] [pid 11176:tid 11176] [client 31.134.11.124:38817] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.bundrenfarmstn.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.bundrenfarmstn.com"] [uri "/s3cmd.ini"] [unique_id "afHUFb0wVmgzSkJJX-X_ngAAAAY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-28 18:18:14
(1 month ago)
Blocked by ModSec and CSF
Port Scan
๐บ๐ธ
TPI-Abuse
2026-04-28 10:55:39
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 31.134.11.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 31.134.11.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Apr 28 06:55:32.007753 2026] [security2:error] [pid 10032:tid 10032] [client 31.134.11.124:35251] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||salernospizza.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "salernospizza.com"] [uri "/s3cmd.ini"] [unique_id "afCSJGROZF7F7IQWbI8NgAAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-28 02:46:35
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 31.134.11.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 31.134.11.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 27 22:46:28.287605 2026] [security2:error] [pid 7572:tid 7572] [client 31.134.11.124:46087] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||specialtywebsiteservice.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "specialtywebsiteservice.com"] [uri "/s3cmd.ini"] [unique_id "afAfhP25cdagN_ja40ZjBwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-27 03:33:59
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 31.134.11.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 31.134.11.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 23:33:53.041492 2026] [security2:error] [pid 31199:tid 31220] [client 31.134.11.124:32329] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.indigowampum.com|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.indigowampum.com"] [uri "/s3cmd.ini"] [unique_id "ae7ZIZT2q1D-6U69se_Q3gAAAJM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-27 02:59:58
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 31.134.11.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 31.134.11.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 22:59:54.403382 2026] [security2:error] [pid 24482:tid 24482] [client 31.134.11.124:13533] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.cuneyt.kircali.net|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.cuneyt.kircali.net"] [uri "/s3cmd.ini"] [unique_id "ae7RKtFm22NssY6yemK4qAAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-26 22:39:01
(1 month ago)
(mod_security) mod_security (id:210730) triggered by 31.134.11.124 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 31.134.11.124 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Apr 26 18:38:54.180039 2026] [security2:error] [pid 8747:tid 8752] [client 31.134.11.124:35345] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.culturallyyours.lamco.us|F|2"] [data ".ini"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.culturallyyours.lamco.us"] [uri "/s3cmd.ini"] [unique_id "ae6T_ii1XluFq6WHI7cYMgAAAMA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-01 06:13:44
(4 months ago)
Attempted brute force login to web vpn 2 time(s); last attempt for 2026.02.01 is noted in report tim ...
show more
Attempted brute force login to web vpn 2 time(s); last attempt for 2026.02.01 is noted in report timestamp
show less
Hacking
Brute-Force
๐ณ๐ฑ
exxos
2025-03-11 09:35:55
(1 year ago)
Scripted attacks
Hacking
๐ฆ๐ช
exxos
2025-03-06 23:22:20
(1 year ago)
Scripted attacks
Hacking