🇺🇸
TPI-Abuse
2026-09-08 06:59:16
(4 days ago)
(mod_security) mod_security (id:217210) triggered by 82.47.120.84 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217210) triggered by 82.47.120.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 02:59:11.573706 2026] [security2:error] [pid 3086770:tid 3086770] [client 82.47.120.84:17282] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||poulsoncustomhomes.com|F|4"] [data "ET http://poulsoncustomhomes.com/robots.txt HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "poulsoncustomhomes.com"] [uri "/robots.txt"] [unique_id "ap-yP2PQOKScr3lk7_mPMwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 02:10:38
(4 days ago)
(mod_security) mod_security (id:217210) triggered by 82.47.120.84 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217210) triggered by 82.47.120.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 22:10:31.792649 2026] [security2:error] [pid 11471:tid 11471] [client 82.47.120.84:25886] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||ejnes.com|F|4"] [data "GET http://ejnes.com HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "ejnes.com"] [uri "/"] [unique_id "ap9ul9AWmZJGjGJ25xG6zAAAAC0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
John Chrys.
2026-09-07 22:57:28
(4 days ago)
82.47.120.84 - - [08/Sep/2026:01:57:16 +0300] "POST /xmlrpc.php HTTP/1.1" 403 380 "-" "Mozilla/5.0 ( ...
show more
82.47.120.84 - - [08/Sep/2026:01:57:16 +0300] "POST /xmlrpc.php HTTP/1.1" 403 380 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
82.47.120.84 - - [08/Sep/2026:01:57:17 +0300] "POST /xmlrpc.php HTTP/1.1" 403 380 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64; rv:109.0) Gecko/20100101 Firefox/119.0"
82.47.120.84 - - [08/Sep/2026:01:57:18 +0300] "POST /xmlrpc.php HTTP/1.1" 403 380 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Mobile/15E148 Safari/604.1"
82.47.120.84 - - [08/Sep/2026:01:57:19 +0300] "POST /xmlrpc.php HTTP/1.1" 403 380 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Mobile/15E148 Safari/604.1"
82.47.120.84 - - [08/Sep/2026:01:57:20 +0300] "POST /xmlrpc.php HTTP/1.1" 403 380 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/12
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 16:52:07
(5 days ago)
(mod_security) mod_security (id:217210) triggered by 82.47.120.84 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217210) triggered by 82.47.120.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 12:52:01.939249 2026] [security2:error] [pid 3965:tid 3981] [client 82.47.120.84:48112] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||jab-us.com|F|4"] [data "GET http://jab-us.com HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "jab-us.com"] [uri "/"] [unique_id "ap7rsQb4a8TYIOoj7pnslQAAAAk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇮🇹
VHosting
2026-09-07 15:00:05
(5 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 14:37:06
(5 days ago)
(mod_security) mod_security (id:217210) triggered by 82.47.120.84 (-): 1 in the last 300 secs; Ports ...
show more
(mod_security) mod_security (id:217210) triggered by 82.47.120.84 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 10:37:01.274752 2026] [security2:error] [pid 21730:tid 21730] [client 82.47.120.84:44571] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||travel-pix.com|F|4"] [data "ET http://travel-pix.com/robots.txt HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "travel-pix.com"] [uri "/robots.txt"] [unique_id "ap7MDYjcaMEVsuxfATO7SAAAACI"]
show less
Brute-Force
Bad Web Bot
Web App Attack