๐บ๐ธ
TPI-Abuse
2026-10-06 14:50:20
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 54.242.205.58 (ec2-54-242-205-58.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 54.242.205.58 (ec2-54-242-205-58.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 06 10:50:17.172727 2026] [security2:error] [pid 1081:tid 1091] [client 54.242.205.58:38630] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.gafm.org|F|2"] [data ".gafm.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.gafm.org"] [uri "/www.GAFM.com"] [unique_id "asUKqdRVoOUHHvIPf5qUbwAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ซ๐ท
bigorre.org
2026-10-05 17:05:22
(4 days ago)
Excessive crawling : exceed crawl-delay defined in robots.txt
Bad Web Bot
๐ฉ๐ช
conseilgouz
2026-10-05 16:21:39
(4 days ago)
avw-(visforms) : try to access forms...
Hacking
๐ต๐ฑ
mscode.pl
2026-10-05 07:37:54
(5 days ago)
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: CHALLENGE
ASN: 14618 (Amazon.com, I ...
show more
Triggered Cloudflare WAF (firewallCustom) from US.
Action taken: CHALLENGE
ASN: 14618 (Amazon.com, Inc.)
Protocol: HTTP/1.1 (GET method)
Zone: www.mscode.pl
Endpoint: /
UA: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/86.0.4240.75 Safari/537.36
show less
Bad Web Bot
Anonymous
2026-10-04 06:42:40
(6 days ago)
[da.kdns.gr] httpd-suspicious-path: sites=www.diadromi.com; logs=/var/log/httpd/domains/diadromi.com ...
show more
[da.kdns.gr] httpd-suspicious-path: sites=www.diadromi.com; logs=/var/log/httpd/domains/diadromi.com.log; samples=/?paged=2&author=3 | /?author=3
show less
Hacking
Web App Attack
Anonymous
2026-10-03 19:55:04
(6 days ago)
IP banned by Fail2Ban in jail nginx-abusive-ips
Web App Attack
Brute-Force
Bad Web Bot
๐ฉ๐ช
FeG Deutschland
2026-10-03 17:17:26
(6 days ago)
Looking for CMS/PHP/SQL vulnerablilities/excessive crawling - 24
Exploited Host
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 13:58:20
(6 days ago)
(mod_security) mod_security (id:210730) triggered by 54.242.205.58 (ec2-54-242-205-58.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 54.242.205.58 (ec2-54-242-205-58.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 09:58:16.772012 2026] [security2:error] [pid 14547:tid 14547] [client 54.242.205.58:41934] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.myairbalance.org|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.myairbalance.org"] [uri "/nampac.com"] [unique_id "asEJ-JWTopS8isHrzvE8kAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-03 09:47:10
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 54.242.205.58 (ec2-54-242-205-58.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 54.242.205.58 (ec2-54-242-205-58.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 03 05:47:06.701779 2026] [security2:error] [pid 7467:tid 7467] [client 54.242.205.58:56838] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.techspertnet.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.techspertnet.com"] [uri "/[email protected] "] [unique_id "asDPGhmqjnzeQmIUz2VkAwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฉ๐ช
findlab
2026-10-02 19:05:02
(1 week ago)
Backdrop CMS module - malicious activity detected
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 17:01:20
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 54.242.205.58 (ec2-54-242-205-58.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 54.242.205.58 (ec2-54-242-205-58.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 13:01:17.242939 2026] [security2:error] [pid 1275700:tid 1275700] [client 54.242.205.58:34466] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.khaoula.com|F|2"] [data ".monmaghreb.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.khaoula.com"] [uri "/sante.monmaghreb.com"] [unique_id "ar_jXXgmjcxv2psMQuHg5wAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-10-02 07:50:10
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 54.242.205.58 (ec2-54-242-205-58.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 54.242.205.58 (ec2-54-242-205-58.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 02 03:50:04.252799 2026] [security2:error] [pid 12552:tid 12564] [client 54.242.205.58:50048] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.munatseng.org|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.munatseng.org"] [uri "/stories/tsengkwongchi.com"] [unique_id "ar9iLAo8ostI5-e8PHQjuAAAAEk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Comberton
2026-10-01 21:27:11
(1 week ago)
Ban via by F2B apache-wordfence jail
Brute-Force
๐บ๐ธ
mnsf
2026-10-01 00:05:42
(1 week ago)
Too many Status 40X (12)
Request Overload (169)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-30 08:04:10
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 54.242.205.58 (ec2-54-242-205-58.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 54.242.205.58 (ec2-54-242-205-58.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 30 04:04:05.204701 2026] [security2:error] [pid 9195:tid 9195] [client 54.242.205.58:49624] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.citystreetsalon.com|F|2"] [data ".fionnardesign.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.citystreetsalon.com"] [uri "/www.fionnardesign.com"] [unique_id "arzCdXjM1hn8IX-NqbgLPgAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack