๐บ๐ธ
kosada.com
2026-09-17 15:29:39
(2 days ago)
Repeated requests for suspicious nonexistent URLs, for example: /login9.php (HTTP/1.1 port 443, user ...
show more
Repeated requests for suspicious nonexistent URLs, for example: /login9.php (HTTP/1.1 port 443, user agent: "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/128.0.0.0 Safari/537.36")
show less
Web App Attack
๐ฉ๐ช
LRob
2026-09-17 05:36:05
(3 days ago)
Connection flood: far more simultaneous connections than any client needs, dropped by the server | 2 ...
show more
Connection flood: far more simultaneous connections than any client needs, dropped by the server | 2026-09-17 05:36 UTC
show less
DDoS Attack
๐บ๐ธ
TPI-Abuse
2026-09-17 03:44:48
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 47.108.179.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.108.179.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 23:44:43.706212 2026] [security2:error] [pid 31975:tid 31975] [client 47.108.179.24:53038] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||autodiscover.patanthony.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "autodiscover.patanthony.com"] [uri "/okok.cer"] [unique_id "aqtiK_5tpPa21ORzhO8EkwAAAD4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
consul.to
2026-09-17 01:10:40
(3 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 14:50:52
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 47.108.179.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.108.179.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 10:50:39.089695 2026] [security2:error] [pid 29165:tid 29165] [client 47.108.179.24:39940] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||artspacecleveland.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "artspacecleveland.com"] [uri "/okok.cer"] [unique_id "aqqsvltysKMs2lnN7ReSkAAAAIw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-16 13:00:45
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 47.108.179.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.108.179.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 16 09:00:38.395232 2026] [security2:error] [pid 24197:tid 24197] [client 47.108.179.24:56584] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||arsprobabile.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "arsprobabile.com"] [uri "/okok.cer"] [unique_id "aqqS9tAP7tlwvPUyiNWGPQAAACw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-16 12:35:33
(3 days ago)
Banned by Fail2Ban on server
Web App Attack
๐ซ๐ท
dynamix
2026-09-16 09:32:27
(3 days ago)
Multiple WAF Violations
Web App Attack
๐ฌ๐ง
consul.to
2026-09-15 22:40:51
(4 days ago)
Web attack/malicious scanning detected
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 22:34:08
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 47.108.179.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.108.179.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 18:34:02.492701 2026] [security2:error] [pid 8189:tid 8189] [client 47.108.179.24:42010] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||apesetx.com.jbcllcnet.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "apesetx.com.jbcllcnet.com"] [uri "/okok.cer"] [unique_id "aqnH2sMAo5IrKfGq0HeCWgAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 18:00:02
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 47.108.179.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.108.179.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 13:59:54.426514 2026] [security2:error] [pid 10144:tid 10178] [client 47.108.179.24:38084] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||annefraser.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "annefraser.com"] [uri "/okok.cer"] [unique_id "aqmHmrLxS6jRdy0S2GkZfgAAAEI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-15 16:12:56
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 47.108.179.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.108.179.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 12:12:47.976811 2026] [security2:error] [pid 15193:tid 15298] [client 47.108.179.24:51174] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||anglicancommission.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "anglicancommission.com"] [uri "/okok.cer"] [unique_id "aqlufxnnEifDmOZV3vQo2AAAAkM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-09-15 13:52:36
(4 days ago)
Blocked: Reason='N/A'; Requests=
Hacking
Anonymous
2026-09-15 11:48:53
(4 days ago)
IP matched detection query 20 more in short time bad rqs.
Brute-Force
Web App Attack
Hacking
๐บ๐ธ
TPI-Abuse
2026-09-15 10:17:08
(4 days ago)
(mod_security) mod_security (id:210730) triggered by 47.108.179.24 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.108.179.24 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 15 06:17:04.228177 2026] [security2:error] [pid 8758:tid 8758] [client 47.108.179.24:55842] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||americanexportimport.com|F|2"] [data ".cer"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "americanexportimport.com"] [uri "/okok.cer"] [unique_id "aqkbII2fsjC6UDb9pF211gAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack