๐บ๐ธ
ipblock.com
2026-01-08 08:51:00
(8 months ago)
IPBlock protected site ID [3192-af][s=02].
Robotic site crawling, undeclared spider
Bad Web Bot
Web App Attack
๐ณ๐ฑ
Roderic
2026-01-08 04:13:29
(8 months ago)
54.82.246.162 (US/United States/Virginia/Ashburn/ec2-54-82-246-162.compute-1.amazonaws.com/[redacted ...
show more
54.82.246.162 (US/United States/Virginia/Ashburn/ec2-54-82-246-162.compute-1.amazonaws.com/[redacted]), more than 30 Apache 403 hits
show less
Hacking
๐ฉ๐ช
DocNetzwerk
2026-01-08 04:06:51
(8 months ago)
54.82.246.162 (US/United States/ec2-54-82-246-162.compute-1.amazonaws.com), more than 7 Apache 403 h ...
show more
54.82.246.162 (US/United States/ec2-54-82-246-162.compute-1.amazonaws.com), more than 7 Apache 403 hits
show less
Hacking
๐ซ๐ท
Sklurk
2026-01-07 22:21:44
(8 months ago)
Web App Attack
Web App Attack
๐บ๐ธ
mnsf
2026-01-03 23:05:11
(8 months ago)
Too many Status 40X (11)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-03 21:52:35
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 54.82.246.162 (ec2-54-82-246-162.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 54.82.246.162 (ec2-54-82-246-162.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Jan 03 16:52:30.940590 2026] [security2:error] [pid 2370556:tid 2370652] [client 54.82.246.162:36964] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.kerrfamilyassociation.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.kerrfamilyassociation.com"] [uri "/[email protected] "] [unique_id "aVmPntxLBejnPbV-zbGN3AAAAcw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2026-01-01 21:05:19
(8 months ago)
Too many Status 40X (13)
Request Overload (144)
Brute-Force
Web App Attack
๐ฉ๐ช
Echobit
2026-01-01 11:14:37
(8 months ago)
Crawling, BadBot, Fake User-Agent, Ignore robots.txt
Hacking
Bad Web Bot
๐ง๐ช
taivas.nl
2026-01-01 05:32:22
(8 months ago)
Many_bad_calls
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-01-01 03:12:13
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 54.82.246.162 (ec2-54-82-246-162.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 54.82.246.162 (ec2-54-82-246-162.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 31 22:12:09.174070 2025] [security2:error] [pid 1460862:tid 1460862] [client 54.82.246.162:50254] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.dalessalesandservice.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.dalessalesandservice.com"] [uri "/[email protected] "] [unique_id "aVXmCeYYg7Ojwn37DMi7zwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
mnsf
2025-12-31 20:05:09
(8 months ago)
Too many Status 40X (20)
Brute-Force
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-31 17:39:50
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 54.82.246.162 (ec2-54-82-246-162.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 54.82.246.162 (ec2-54-82-246-162.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 31 12:39:47.496275 2025] [security2:error] [pid 20521:tid 20521] [client 54.82.246.162:48830] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.john-bell-associates.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.john-bell-associates.com"] [uri "/reddit.com"] [unique_id "aVVf41E5ljprM8WEbeByOQAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
rsa
2025-12-31 17:21:00
(8 months ago)
excessive crawling
DDoS Attack
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-31 10:28:53
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 54.82.246.162 (ec2-54-82-246-162.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 54.82.246.162 (ec2-54-82-246-162.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 31 05:28:46.980772 2025] [security2:error] [pid 6732:tid 6732] [client 54.82.246.162:53660] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.flashbackmusicmemories.com|F|2"] [data ".40svocaltrio.com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.flashbackmusicmemories.com"] [uri "/www.40svocaltrio.com"] [unique_id "aVT63lFxp4-fLHfD_M0UJwAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2025-12-31 07:30:23
(8 months ago)
(mod_security) mod_security (id:210730) triggered by 54.82.246.162 (ec2-54-82-246-162.compute-1.amaz ...
show more
(mod_security) mod_security (id:210730) triggered by 54.82.246.162 (ec2-54-82-246-162.compute-1.amazonaws.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Dec 31 02:30:17.099592 2025] [security2:error] [pid 22456:tid 22456] [client 54.82.246.162:52958] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.brookspowell.com|F|2"] [data ".com"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.brookspowell.com"] [uri "/mail to: [email protected] "] [unique_id "aVTRCVILPrqT3b4vl0wgKQAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack