๐ง๐ท
Peregrine
2026-09-17 16:42:51
(12 hours ago)
Fail2Ban Jail s2: tomcat-honeypot | Evidence: 39.104.67.21 172.71.158.76 - - [04/Sep/2026:22:33:29 - ...
show more
Fail2Ban Jail s2: tomcat-honeypot | Evidence: 39.104.67.21 172.71.158.76 - - [04/Sep/2026:22:33:29 -0300] "GET /static/warn/close.php HTTP/1.1" 404 414
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-17 02:40:58
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 39.104.67.21 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 39.104.67.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 22:40:52.136274 2026] [security2:error] [pid 14188:tid 14274] [client 39.104.67.21:50886] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.asrtrax.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.asrtrax.com"] [uri "/okok.cer"] [unique_id "aqtTNFzWrjP-0_ynNOHjwAAAAcM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
SpaceHost-Server
2026-09-16 22:21:55
(1 day ago)
Brute-Force
Web App Attack
๐ฌ๐ง
Smish
2026-09-16 15:33:27
(1 day ago)
HONEYPOT HIT --> Fail2ban time=1789572805 log=2026-09-16T16:33:25+01:00 ip=39.104.67.21 host=as21066 ...
show more
HONEYPOT HIT --> Fail2ban time=1789572805 log=2026-09-16T16:33:25+01:00 ip=39.104.67.21 host=as210667.net method=GET uri="/wp-admincsscolorsmidnightabout.php" status=404 ua="Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36" ref="-" rid=8e6ffe31ca091fce11db9c4943940eff
show less
Web App Attack
๐ง๐ท
Peregrine
2026-09-16 03:13:04
(2 days ago)
Fail2Ban Jail s2: tomcat-honeypot | Evidence: 39.104.67.21 172.71.158.76 - - [04/Sep/2026:22:33:29 - ...
show more
Fail2Ban Jail s2: tomcat-honeypot | Evidence: 39.104.67.21 172.71.158.76 - - [04/Sep/2026:22:33:29 -0300] "GET /static/warn/close.php HTTP/1.1" 404 414
show less
Bad Web Bot
๐ซ๐ท
SpaceHost-Server
2026-09-15 22:20:13
(2 days ago)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 20:26:06
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 39.104.67.21 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 39.104.67.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 16:26:01.066606 2026] [security2:error] [pid 18848:tid 18848] [client 39.104.67.21:57846] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||anxo.org|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "anxo.org"] [uri "/okok.cer"] [unique_id "aqmp2anc-vx_9ApgwykVHgAAADg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
macrob
2026-09-15 20:07:55
(2 days ago)
2026/09/15 20:07:52 [error] 2447295#2447295: *2276840 access forbidden by rule, client: 39.104.67.21 ...
show more
2026/09/15 20:07:52 [error] 2447295#2447295: *2276840 access forbidden by rule, client: 39.104.67.21, server: antzfund.com, request: "GET /uploads/slide4.php HTTP/1.1", host: "antzfund.com"
2026/09/15 20:07:53 [error] 2447295#2447295: *2276848 access forbidden by rule, client: 39.104.67.21, server: antzfund.com, request: "GET /admin.php HTTP/1.1", host: "antzfund.com"
2026/09/15 20:07:54 [error] 2447295#2447295: *2276841 access forbidden by rule, client: 39.104.67.21, server: antzfund.com, request: "GET /.index_bak.php?type=2 HTTP/1.1", host: "antzfund.com"
...
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 19:20:57
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 39.104.67.21 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 39.104.67.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 15:20:50.514366 2026] [security2:error] [pid 25964:tid 25964] [client 39.104.67.21:50168] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||anthearodgers.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "anthearodgers.com"] [uri "/okok.cer"] [unique_id "aqmakrsJqyn-Q4A3yFm8yQAAAGE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 14:15:22
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 39.104.67.21 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 39.104.67.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 10:15:14.178184 2026] [security2:error] [pid 8644:tid 8644] [client 39.104.67.21:55088] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||andiamorun.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "andiamorun.com"] [uri "/okok.cer"] [unique_id "aqlS8tcrqJXjOLeC45hkJQAAAA8"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 14:01:49
(2 days ago)
Banned by Fail2Ban on server
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 10:53:51
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 39.104.67.21 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 39.104.67.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 06:53:43.853296 2026] [security2:error] [pid 19853:tid 19853] [client 39.104.67.21:51124] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||amgtr.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "amgtr.com"] [uri "/okok.cer"] [unique_id "aqkjt4jth4-oJRuDBSdTugAAAAI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐พ
Rizzy
2026-09-15 01:44:42
(3 days ago)
Multiple WAF Violations
Brute-Force
Web App Attack
๐ง๐ท
Peregrine
2026-09-14 03:14:08
(4 days ago)
Fail2Ban Jail s2: tomcat-honeypot | Evidence: 39.104.67.21 172.71.158.76 - - [04/Sep/2026:22:33:29 - ...
show more
Fail2Ban Jail s2: tomcat-honeypot | Evidence: 39.104.67.21 172.71.158.76 - - [04/Sep/2026:22:33:29 -0300] "GET /static/warn/close.php HTTP/1.1" 404 414
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-13 18:05:55
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 39.104.67.21 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:210730) triggered by 39.104.67.21 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 13 14:05:50.155176 2026] [security2:error] [pid 2988:tid 2988] [client 39.104.67.21:41238] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ajvaage.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ajvaage.com"] [uri "/okok.cer"] [unique_id "aqbl_uKAN0BtSB4-Z-NbPgAAABs"]
show less
Brute-Force
Bad Web Bot
Web App Attack