πͺπΈ
el-brujo
2026-09-27 22:57:00
(15 hours ago)
28/Sep/2026:00:56:59.447281 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client ...
show more
28/Sep/2026:00:56:59.447281 +0200Apache-Error: [file "apache2_util.c"] [line 271] [level 3] [client 60.27.225.113] ModSecurity: Warning. Match of "rx ^urlgrabber/[0-9\\\\\\\\.]+ yum/[0-9\\\\\\\\.]+$" against "REQUEST_HEADERS:User-Agent" required. [file "/etc/httpd/modsecurity.d/activated_rules/REQUEST-913-SCANNER-DETECTION.conf"] [line "53"] [id "913100"] [msg "Found User-Agent associated with security scanner"] [data "Matched Data: user-agent: found within REQUEST_HEADERS:User-Agent: user-agent:mozilla/5.0 (windows nt 6.1; wow64) applewebkit/537.36 (khtml, like gecko) chrome/50.0.2661.102 safari/537.36"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.5"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-reputation-scanner"] [tag "paranoia-level/1"] [tag "OWASP_CRS"] [tag "capec/1000/118/224/541/310"] [tag "PCI/6.5.10"] [hostname "hwagm.elhacker.net"] [uri "/changetip-hd/"] [unique_id "armfO0mXAvWan6GCM80fPAAAkFQ"]
...
show less
Hacking
Web App Attack
πΊπΈ
kosada.com
2026-08-11 19:44:41
(1 month ago)
Web bot: denial-of-service flood
DDoS Attack
Bad Web Bot
πΊπΈ
TPI-Abuse
2026-07-03 08:04:07
(2 months ago)
(mod_security) mod_security (id:210831) triggered by 60.27.225.113 (no-data): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:210831) triggered by 60.27.225.113 (no-data): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 03 04:04:02.893965 2026] [security2:error] [pid 1200:tid 1200] [client 60.27.225.113:28073] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||airdeluxemusic.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "airdeluxemusic.com"] [uri "/"] [unique_id "akds8jQdVBgPJ6XJIX5J4AAAAAM"], referer: http://airdeluxemusic.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-02 22:27:26
(2 months ago)
(mod_security) mod_security (id:210831) triggered by 60.27.225.113 (no-data): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:210831) triggered by 60.27.225.113 (no-data): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 02 18:27:19.038691 2026] [security2:error] [pid 27114:tid 27114] [client 60.27.225.113:28575] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.godplusus.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.godplusus.com"] [uri "/"] [unique_id "akblx4I-9FWvG98M-3OU_gAAAAM"], referer: http://www.godplusus.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-07-01 01:02:19
(2 months ago)
(mod_security) mod_security (id:210831) triggered by 60.27.225.113 (no-data): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:210831) triggered by 60.27.225.113 (no-data): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Jun 30 21:02:14.560259 2026] [security2:error] [pid 14414:tid 14424] [client 60.27.225.113:27827] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||aafm.us|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "aafm.us"] [uri "/index.html"] [unique_id "akRnFraPrVO3lCdie3N-_wAAAEc"], referer: https://aafm.us/index.html
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-06-29 03:27:44
(2 months ago)
(mod_security) mod_security (id:210831) triggered by 60.27.225.113 (no-data): 1 in the last 300 secs ...
show more
(mod_security) mod_security (id:210831) triggered by 60.27.225.113 (no-data): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Jun 28 23:27:39.946361 2026] [security2:error] [pid 19994:tid 19994] [client 60.27.225.113:28238] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||royaleliteclub.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "royaleliteclub.com"] [uri "/"] [unique_id "akHmK-xYPc-aeraG7xsCYwAAAA4"], referer: http://royaleliteclub.com/
show less
Brute-Force
Bad Web Bot
Web App Attack