π³π±
e.fierstra
2026-06-08 08:03:41
(5 hours ago)
ModSecurity hits exceeded
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-07 20:09:09
(17 hours ago)
(mod_security) mod_security (id:210831) triggered by 37.19.197.130 (unn-37-19-197-130.datapacket.com ...
show more
(mod_security) mod_security (id:210831) triggered by 37.19.197.130 (unn-37-19-197-130.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 16:09:05.841130 2026] [security2:error] [pid 12444:tid 12444] [client 37.19.197.130:4329] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.legionellaexperts.org|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.legionellaexperts.org"] [uri "/robots.txt"] [unique_id "aiXP4VQcU5noFQqE5tV1wAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-07 14:59:32
(22 hours ago)
(mod_security) mod_security (id:210831) triggered by 37.19.197.130 (unn-37-19-197-130.datapacket.com ...
show more
(mod_security) mod_security (id:210831) triggered by 37.19.197.130 (unn-37-19-197-130.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 07 10:59:28.179572 2026] [security2:error] [pid 19933:tid 19933] [client 37.19.197.130:18010] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.wisdomwfm.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.wisdomwfm.com"] [uri "/robots.txt"] [unique_id "aiWHUCzBhbGgUhxVp7MYVgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¬π§
Celtic
2026-06-07 09:48:06
(1 day ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
πΊπΈ
TPI-Abuse
2026-06-06 20:37:51
(1 day ago)
(mod_security) mod_security (id:210831) triggered by 37.19.197.130 (unn-37-19-197-130.datapacket.com ...
show more
(mod_security) mod_security (id:210831) triggered by 37.19.197.130 (unn-37-19-197-130.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jun 06 16:37:45.995904 2026] [security2:error] [pid 6105:tid 6105] [client 37.19.197.130:6675] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.leadslibrary.net|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.leadslibrary.net"] [uri "/robots.txt"] [unique_id "aiSFGQOFkYDf7pC68yxn-gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-06 09:46:37
(2 days ago)
Banned by Fail2Ban on server
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-05 19:36:55
(2 days ago)
(mod_security) mod_security (id:210831) triggered by 37.19.197.130 (unn-37-19-197-130.datapacket.com ...
show more
(mod_security) mod_security (id:210831) triggered by 37.19.197.130 (unn-37-19-197-130.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 15:36:51.866531 2026] [security2:error] [pid 26120:tid 26120] [client 37.19.197.130:11391] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.whodatnation.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.whodatnation.com"] [uri "/robots.txt"] [unique_id "aiMlUzOQw2v8kAIwyxraDgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
Vegascosmetics
2026-06-05 15:00:28
(2 days ago)
Kingcopy(AI-IDS) Report: IP automatically blocked after obfuscated encoding. Vegas Security System
DDoS Attack
Hacking
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-06-05 05:34:35
(3 days ago)
(mod_security) mod_security (id:210831) triggered by 37.19.197.130 (unn-37-19-197-130.datapacket.com ...
show more
(mod_security) mod_security (id:210831) triggered by 37.19.197.130 (unn-37-19-197-130.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 05 01:34:29.509125 2026] [security2:error] [pid 16392:tid 16392] [client 37.19.197.130:51929] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.newmooncafe.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.newmooncafe.com"] [uri "/robots.txt"] [unique_id "aiJf5YdUKifEq5NjOob45gAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π©πͺ
LRob.fr
2026-06-05 05:00:05
(3 days ago)
WAF repeated trigger detected by Fail2Ban in plesk-modsecurity jail
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-03 18:34:19
(4 days ago)
(mod_security) mod_security (id:210831) triggered by 37.19.197.130 (unn-37-19-197-130.datapacket.com ...
show more
(mod_security) mod_security (id:210831) triggered by 37.19.197.130 (unn-37-19-197-130.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 14:34:12.084186 2026] [security2:error] [pid 10269:tid 10269] [client 37.19.197.130:55643] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.tulsatvmemories.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.tulsatvmemories.com"] [uri "/robots.txt"] [unique_id "aiBzpFMtgw_JTev_SHPBBgAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-03 06:09:40
(5 days ago)
(mod_security) mod_security (id:210831) triggered by 37.19.197.130 (unn-37-19-197-130.datapacket.com ...
show more
(mod_security) mod_security (id:210831) triggered by 37.19.197.130 (unn-37-19-197-130.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 02:09:35.359110 2026] [security2:error] [pid 5327:tid 5327] [client 37.19.197.130:62202] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.disenowebprofesional.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.disenowebprofesional.com"] [uri "/robots.txt"] [unique_id "ah_FH3LRhPgMJLKX1LU5-QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-03 03:35:06
(5 days ago)
(mod_security) mod_security (id:210831) triggered by 37.19.197.130 (unn-37-19-197-130.datapacket.com ...
show more
(mod_security) mod_security (id:210831) triggered by 37.19.197.130 (unn-37-19-197-130.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 23:35:00.476156 2026] [security2:error] [pid 21626:tid 21626] [client 37.19.197.130:10827] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.goldenvalley1.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.goldenvalley1.com"] [uri "/robots.txt"] [unique_id "ah-g5DU-mEFpIqIRLn1cIQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
π¦πΊ
paulshipley.com.au
2026-06-03 00:58:24
(5 days ago)
[Wed Jun 03 10:58:23.959056 2026] [security2:error] [pid 310704] [client 37.19.197.130:19655] [clien ...
show more
[Wed Jun 03 10:58:23.959056 2026] [security2:error] [pid 310704] [client 37.19.197.130:19655] [client 37.19.197.130] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "mareeshefford.com"] [uri "/robots.txt"] [unique_id "ah98L2ZqRqIfGphSTjYsVAAAAAw"]
...
show less
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-02 16:49:19
(5 days ago)
(mod_security) mod_security (id:210831) triggered by 37.19.197.130 (unn-37-19-197-130.datapacket.com ...
show more
(mod_security) mod_security (id:210831) triggered by 37.19.197.130 (unn-37-19-197-130.datapacket.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 02 12:49:14.758084 2026] [security2:error] [pid 2391:tid 2391] [client 37.19.197.130:62608] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.bigskyprints.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.bigskyprints.com"] [uri "/robots.txt"] [unique_id "ah8JigNqKdN7H2KxDBpKFwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack