Anonymous
2026-06-11 09:30:21
(13 hours ago)
FortiWeb WAF: 63 attacks detected. Threat Score: 6400. Types: GEO IP(32), Client Management(31). Ori ...
show more
FortiWeb WAF: 63 attacks detected. Threat Score: 6400. Types: GEO IP(32), Client Management(31). Origin: Singapore.
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 07:11:48
(16 hours ago)
(mod_security) mod_security (id:210381) triggered by 47.79.201.114 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210381) triggered by 47.79.201.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 03:11:43.782148 2026] [security2:error] [pid 30091:tid 30172] [client 47.79.201.114:7452] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||www.mentzlaw.com|F|4"] [data "REQUEST_URI=/louisianakidneydamagelawyer/%url%"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.mentzlaw.com"] [uri "/louisianakidneydamagelawyer/%url%"] [unique_id "aipfr5fF-juYK72ajTzQewAAAgk"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-11 00:17:58
(23 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.114 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 20:17:52.543128 2026] [security2:error] [pid 2107:tid 2155] [client 47.79.201.114:5712] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||behaviorhealth.org|F|2"] [data ".barnesandnoble.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "behaviorhealth.org"] [uri "/www.BarnesandNoble.com"] [unique_id "ain-sC7yO3g5E1xoUcv_mwAAAI8"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 19:11:27
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.114 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 15:11:22.976929 2026] [security2:error] [pid 5659:tid 5659] [client 47.79.201.114:23034] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.register-yacht-bvi.com|F|2"] [data ".register-yacht-bvi.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.register-yacht-bvi.com"] [uri "/no/www.register-yacht-bvi.com"] [unique_id "aim22qNH63DTcU2t-NuWAAAAAAM"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
4server
2026-06-10 18:07:09
(1 day ago)
[WedJun1020:07:07.1801792026][security2:error][pid741609:tid741662][client47.79.201.114:0]ModSecurit ...
show more
[WedJun1020:07:07.1801792026][security2:error][pid741609:tid741662][client47.79.201.114:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Stringmatchwithin\".asa/.asax/.ascx/.backup/.bak/.bat/.cdx/.cer/.cfg/.cmd/.com/.config/.conf/.cs/.csproj/.csr/.dat/.db/.dbf/.dll/.dos/.htr/.htw/.ida/.idc/.idq/.inc/.ini/.key/.licx/.lnk/.log/.mdb/.old/.pass/.pdb/.pol/.printer/.pwd/.rdb/.resources/.resx/.sql/.swp/.sys/.vb/.vbs/.vbproj/.vsdisco/.webinfo/.xsx/\"atTX:extension.[file\"/etc/apache2/conf.d/modsec_rules/00_asl_zz_strict.conf\"][line\"91\"][id\"390716\"][rev\"2\"][msg\"Atomicorp.comWAFRules:URLfileextensionisrestrictedbypolicy\"][data\".dll\"][severity\"ERROR\"][hostname\"modularss.com\"][uri\"/recordati/reagentario/service/V1/ReagentarioIO.dll\"][unique_id\"aimny_3psNl4HuTQecJ5JQAAAFE\"]\,referer:https://www.google.com/
show less
Port Scan
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-10 16:09:44
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.114 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 10 12:09:37.341671 2026] [security2:error] [pid 17485:tid 17485] [client 47.79.201.114:29058] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kairoslogammakmur.com|F|2"] [data ".kairoslogammakmur.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kairoslogammakmur.com"] [uri "/www.kairoslogammakmur.com"] [unique_id "aimMQXcGFdvS9887JjeFegAAABs"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
gui-ying233
2026-04-29 01:26:29
(1 month ago)
Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Sa ...
show more
Mozilla/5.0 (Linux; Android 10; K) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/133.0.0.0 Mobile Safari/537.36
show less
Bad Web Bot
๐บ๐ธ
ersei.net
2026-01-15 17:55:56
(4 months ago)
Nonstop scanning with no cooldown or respect for 429.
Bad Web Bot
๐ฎ๐น
VHosting
2026-01-08 11:36:19
(5 months ago)
Detected attack and reported by a human
DDoS Attack
Brute-Force
Bad Web Bot
Exploited Host
Web App Attack
SSH
๐บ๐ธ
kosada.com
2026-01-05 11:15:37
(5 months ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
๐บ๐ธ
kosada.com
2025-12-26 20:28:30
(5 months ago)
Web bot: DDoS
DDoS Attack
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2025-12-16 02:03:27
(5 months ago)
(mod_security) mod_security (id:210730) triggered by 47.79.201.114 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.201.114 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Dec 15 21:03:21.712855 2025] [security2:error] [pid 12766:tid 12766] [client 47.79.201.114:1950] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.elcalamo.com|F|2"] [data ".pdb"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.elcalamo.com"] [uri "/pda/villoro-obranegra.PDB"] [unique_id "aUC96RH3vlbd_638ZZoj_gAAABE"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
ersei.net
2025-12-13 23:17:13
(5 months ago)
Nonstop scanning with no cooldown or respect for 429.
Bad Web Bot
๐บ๐ธ
ersei.net
2025-12-08 12:40:39
(6 months ago)
Nonstop scanning with no cooldown or respect for 429.
Bad Web Bot
๐ซ๐ท
Sklurk
2025-12-07 07:01:01
(6 months ago)
Web App Attack
Web App Attack