๐บ๐ธ
TPI-Abuse
2026-06-12 06:16:10
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.242 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 02:16:04.612941 2026] [security2:error] [pid 12567:tid 12725] [client 47.79.206.242:39038] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||ceol.us|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "ceol.us"] [uri "/ceol.com"] [unique_id "aiukJPnmWOfBMVw5B8qDYAAAAgo"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-06-12 05:26:29
(4 hours ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.242 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jun 12 01:26:23.178717 2026] [security2:error] [pid 14415:tid 14415] [client 47.79.206.242:11568] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.register-yacht-belgium.com|F|2"] [data ".register-yacht-belgium.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.register-yacht-belgium.com"] [uri "/no/www.register-yacht-belgium.com"] [unique_id "aiuYf1E3XOKUCr-G5CrMHgAAAAU"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฆ๐บ
FireGuard Server
2026-06-11 22:05:05
(12 hours ago)
Blocked by OPNsense firewall; 4 hits, proto=tcp, ports=443
Port Scan
Hacking
๐บ๐ธ
TPI-Abuse
2026-06-11 19:06:37
(15 hours ago)
(mod_security) mod_security (id:210381) triggered by 47.79.206.242 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210381) triggered by 47.79.206.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jun 11 15:06:31.237922 2026] [security2:error] [pid 29453:tid 29459] [client 47.79.206.242:64064] ModSecurity: Access denied with code 403 (phase 2). Invalid URL Encoding: Non-hexadecimal digits used at REQUEST_URI. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "82"] [id "210381"] [rev "6"] [msg "COMODO WAF: URL Encoding Abuse Attack Attempt||www.mentzlaw.com|F|4"] [data "REQUEST_URI=/louisianaimmigrationlawyer/%url%"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "www.mentzlaw.com"] [uri "/louisianaimmigrationlawyer/%url%"] [unique_id "aisHNzCNFrAKDGoP9DvbWQAAAAI"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-06-11 09:27:47
(1 day ago)
FortiWeb WAF: 77 attacks detected. Threat Score: 7800. Types: GEO IP(39), Client Management(38). Ori ...
show more
FortiWeb WAF: 77 attacks detected. Threat Score: 7800. Types: GEO IP(39), Client Management(38). Origin: Singapore.
show less
Web App Attack
Anonymous
2026-06-11 08:34:02
(1 day ago)
Malicious activity detected
Hacking
Web App Attack
๐ซ๐ท
Sklurk
2026-06-11 03:25:29
(1 day ago)
Web App Attack
Web App Attack
๐ฉ๐ช
4server
2026-06-11 03:12:32
(1 day ago)
[ThuJun1105:12:30.8053462026][security2:error][pid1352025:tid1352148][client47.79.206.242:0]ModSecur ...
show more
[ThuJun1105:12:30.8053462026][security2:error][pid1352025:tid1352148][client47.79.206.242:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Stringmatchwithin\".asa/.asax/.ascx/.backup/.bak/.bat/.cdx/.cer/.cfg/.cmd/.com/.config/.conf/.cs/.csproj/.csr/.dat/.db/.dbf/.dll/.dos/.htr/.htw/.ida/.idc/.idq/.inc/.ini/.key/.licx/.lnk/.log/.mdb/.old/.pass/.pdb/.pol/.printer/.pwd/.rdb/.resources/.resx/.sql/.swp/.sys/.vb/.vbs/.vbproj/.vsdisco/.webinfo/.xsx/\"atTX:extension.[file\"/etc/apache2/conf.d/modsec_rules/00_asl_zz_strict.conf\"][line\"91\"][id\"390716\"][rev\"2\"][msg\"Atomicorp.comWAFRules:URLfileextensionisrestrictedbypolicy\"][data\".dll\"][severity\"ERROR\"][hostname\"modularss.com\"][uri\"/recordati/authup/Authenticator.dll\"][unique_id\"aionni5z6XA8S5e82P8TxgAAAQ4\"]\,referer:https://www.google.com/
show less
Port Scan
Brute-Force
Web App Attack
๐ซ๐ท
Sklurk
2026-06-08 05:36:44
(4 days ago)
Web App Attack
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 15:40:24
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.242 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 11:40:17.181483 2026] [security2:error] [pid 18715:tid 18743] [client 47.79.206.242:3964] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.AAFM.us|F|2"] [data ".cgiaglobal.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.aafm.us"] [uri "/www.cgiaglobal.com"] [unique_id "acvq4UPe3xjon_oBavK4LAAAAEw"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-03-31 14:00:13
(2 months ago)
(mod_security) mod_security (id:210730) triggered by 47.79.206.242 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210730) triggered by 47.79.206.242 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Mar 31 10:00:08.542965 2026] [security2:error] [pid 2085:tid 2085] [client 47.79.206.242:42348] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.beirutbazar.com|F|2"] [data ".beirutbazar.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.beirutbazar.com"] [uri "/item/metal-wood-cast-iron-pot-usd-95/www.beirutbazar.com"] [unique_id "acvTaBtTHWTW3ZMujOsGOwAAAAY"], referer: https://www.google.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
librebit
2026-03-27 07:18:30
(2 months ago)
Brute force
Brute-Force
๐บ๐ธ
ersei.net
2026-03-24 23:00:27
(2 months ago)
Web app exploiting
Web App Attack
๐บ๐ธ
ersei.net
2026-01-26 16:35:28
(4 months ago)
Web app exploiting
Web App Attack
๐ช๐ธ
librebit
2026-01-20 05:54:24
(4 months ago)
Brute force
Brute-Force