๐ฉ๐ช
Admins@FBN
2026-03-02 11:52:29
(3 months ago)
FW-PortScan: Traffic Blocked srcport=52119 dstport=80
Port Scan
๐บ๐ธ
TPI-Abuse
2026-03-02 11:40:45
(3 months ago)
(mod_security) mod_security (id:210492) triggered by 31.59.107.20 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210492) triggered by 31.59.107.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Mar 02 06:40:26.772369 2026] [security2:error] [pid 32291:tid 32291] [client 31.59.107.20:26681] ModSecurity: Access denied with code 403 (phase 1). Matched phrase "/.git/" at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/02_Global_Generic.conf"] [line "117"] [id "210492"] [rev "3"] [severity "CRITICAL"] [tag "CWAF"] [tag "Generic"] [hostname "www.costumeshalloweenparty.com.piratecostumesonline.com"] [uri "/.git/HEAD"] [unique_id "aaV3KuCeMIyp3kk17k7_jAAAACQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-26 13:03:50
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 31.59.107.20 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 31.59.107.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 26 08:03:44.580207 2026] [security2:error] [pid 3580:tid 3605] [client 31.59.107.20:33805] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.faimreps.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.faimreps.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aaBEsICuniG4DRVjI_6fDAAAARM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-26 09:31:17
(3 months ago)
(mod_security) mod_security (id:210730) triggered by 31.59.107.20 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 31.59.107.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Feb 26 04:31:13.463222 2026] [security2:error] [pid 11292:tid 11292] [client 31.59.107.20:23133] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||dockrockukiah.com|F|2"] [data ".xsd"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "dockrockukiah.com"] [uri "/vendor/phpunit/phpunit/phpunit.xsd"] [unique_id "aaAS4VyVaCRQA81kWRK41wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
dinaco
2026-02-26 01:58:10
(3 months ago)
31.59.107.20 - - [26/Feb/2026:01:58:09 +0000] "GET /vendor/phpunit/phpunit/phpunit.xsd HTTP/1.1" 444 ...
show more
31.59.107.20 - - [26/Feb/2026:01:58:09 +0000] "GET /vendor/phpunit/phpunit/phpunit.xsd HTTP/1.1" 444 0 "-" "Mozilla/5.0 (X11; Linux x86_64; rv:52.0) Gecko/20100101 Firefox/52.0"
...
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-24 09:21:25
(3 months ago)
(mod_security) mod_security (id:240000) triggered by 31.59.107.20 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 31.59.107.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Feb 24 04:21:21.379182 2026] [security2:error] [pid 24398:tid 24398] [client 31.59.107.20:27189] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "74"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||questiondezyn.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "questiondezyn.com"] [uri "/images/stories/themes.php"] [unique_id "aZ1tkTfnqZIxWoZVuvAFiwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Site.eu
2026-02-24 06:39:49
(3 months ago)
Excessive 404/403 errors
Brute-Force
๐ฌ๐ง
consul.to
2026-02-24 03:51:40
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-02-24 02:36:29
(3 months ago)
(mod_security) mod_security (id:240000) triggered by 31.59.107.20 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:240000) triggered by 31.59.107.20 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Feb 23 21:36:22.225522 2026] [security2:error] [pid 7500:tid 7500] [client 31.59.107.20:49245] ModSecurity: Access denied with code 403 (phase 2). String match ".php" at REQUEST_FILENAME. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/24_Apps_Joomla.conf"] [line "87"] [id "240000"] [rev "1"] [msg "COMODO WAF: Protecting Joomla folder||asbechiro.com|F|2"] [severity "CRITICAL"] [tag "CWAF"] [tag "Joomla"] [hostname "asbechiro.com"] [uri "/images/stories/themes.php"] [unique_id "aZ0Opj-vwJWQuxo5PMG9RwAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-02-22 18:21:21
(3 months ago)
Multiple web server 400 error codes from same source ip
Web App Attack
๐ฌ๐ง
consul.to
2026-02-22 17:07:58
(3 months ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-02-22 14:02:58
(3 months ago)
31.59.107.20 - - [22/Feb/2026:16:02:57 +0200] "GET /wp-content/hello.php HTTP/1.1" 404 276 "-" "Mozi ...
show more
31.59.107.20 - - [22/Feb/2026:16:02:57 +0200] "GET /wp-content/hello.php HTTP/1.1" 404 276 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/70.0.3538.110 Safari/537.36"
...
show less
Web App Attack
๐บ๐ฆ
URAN Publishing Service
2026-02-22 12:38:44
(3 months ago)
31.59.107.20 - - [22/Feb/2026:14:38:43 +0200] "GET /wp-content/hello.php HTTP/1.1" 404 272 "-" "Mozi ...
show more
31.59.107.20 - - [22/Feb/2026:14:38:43 +0200] "GET /wp-content/hello.php HTTP/1.1" 404 272 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:73.0) Gecko/20100101 Firefox/73.0"
31.59.107.20 - - [22/Feb/2026:14:38:43 +0200] "GET /wp-admin/maint/bootstrap.php HTTP/1.1" 404 272 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/83.0.4103.97 Safari/537.36"
...
show less
Web App Attack
๐ซ๐ท
dynamix
2026-02-22 11:28:22
(3 months ago)
Multiple WAF Violations
Web App Attack
๐บ๐ธ
ipblock.com
2026-02-22 00:46:00
(3 months ago)
IPBlock protected site ID [4055-d][s=07].
Exploit request, vulnerability scanner.
Hacking
Bad Web Bot
Web App Attack