๐ฌ๐ง
Celtic
2026-04-22 12:35:59
(1 month ago)
Blocked by Fail2Ban with Jail (plesk-modsecurity)
Brute-Force
SSH
๐บ๐ธ
TPI-Abuse
2026-04-22 11:59:07
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 84.239.45.141 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 84.239.45.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 07:59:01.471675 2026] [security2:error] [pid 23675:tid 23675] [client 84.239.45.141:56047] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.cadimpressions.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.cadimpressions.com"] [uri "/robots.txt"] [unique_id "aei4Bc73HPSNP7ZFfJ44MgAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-22 10:52:13
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 84.239.45.141 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 84.239.45.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 06:52:09.965389 2026] [security2:error] [pid 2434474:tid 2434474] [client 84.239.45.141:22304] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.justmakingitbetter.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.justmakingitbetter.com"] [uri "/robots.txt"] [unique_id "aeioWSCtcpmXgiL5Bud3IQAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-22 09:44:20
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 84.239.45.141 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 84.239.45.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 05:44:12.071075 2026] [security2:error] [pid 3219027:tid 3219027] [client 84.239.45.141:17838] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.rentkase.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.rentkase.com"] [uri "/robots.txt"] [unique_id "aeiYbAd3SVsnu7QvGKdHbQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2026-04-22 09:31:09
(1 month ago)
FortiWeb WAF: 65 attacks detected. Threat Score: 6600. Types: Known Bots Detection(33), Client Manag ...
show more
FortiWeb WAF: 65 attacks detected. Threat Score: 6600. Types: Known Bots Detection(33), Client Management(32). Origin: United States.
show less
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-04-22 09:04:42
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 84.239.45.141 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 84.239.45.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 05:04:35.908702 2026] [security2:error] [pid 23889:tid 23889] [client 84.239.45.141:41038] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.karenjoyce.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.karenjoyce.com"] [uri "/robots.txt"] [unique_id "aeiPIydxRWV4iDKYXjyr-QAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ช๐ธ
masterguru
2026-04-22 08:53:26
(1 month ago)
COMODO WAF: Rogue web site crawler. Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblo ...
show more
COMODO WAF: Rogue web site crawler. Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( (210831-123)
show less
Hacking
๐ฉ๐ช
psauxit
2026-04-22 08:32:34
(1 month ago)
Fail2Ban - NGINX heavily bad-bot, possible vulnerability scanning and excessive crawling/scraping
Bad Web Bot
Web App Attack
Hacking
Web Spam
๐ฌ๐ง
poundawebsiteltd
2026-04-22 08:23:35
(1 month ago)
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:443 84.239.45.141 - - [22/Apr/2026:0 ...
show more
Web App Attack (ModSecurity Block). Evidence: [REDACTED_DOMAIN]:443 84.239.45.141 - - [22/Apr/2026:09:23:32 +0100] GET /robots.txt HTTP/1.1 403 2640 - [REDACTED_DOMAIN]
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-22 07:17:31
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 84.239.45.141 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 84.239.45.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 03:17:20.693664 2026] [security2:error] [pid 2144932:tid 2144932] [client 84.239.45.141:8783] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.moonfest.net|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.moonfest.net"] [uri "/robots.txt"] [unique_id "aeh2AEt4xFoe-WzEu3srYwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-22 06:02:15
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 84.239.45.141 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 84.239.45.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 02:02:07.248161 2026] [security2:error] [pid 1218162:tid 1218162] [client 84.239.45.141:1379] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.flightclaimservices.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.flightclaimservices.com"] [uri "/robots.txt"] [unique_id "aehkX63rrWLPX5Std6zC4AAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-22 05:35:52
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 84.239.45.141 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 84.239.45.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 01:35:45.739871 2026] [security2:error] [pid 30660:tid 30660] [client 84.239.45.141:32654] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.cityofhaleyville.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.cityofhaleyville.com"] [uri "/robots.txt"] [unique_id "aeheMTwBqk38848t7XLHOAAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
Apache
2026-04-22 05:26:49
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 84.239.45.141 (US/United States/-): 5 in the la ...
show more
(mod_security) mod_security (id:210831) triggered by 84.239.45.141 (US/United States/-): 5 in the last 300 secs
show less
Brute-Force
Email Spam
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-22 05:07:18
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 84.239.45.141 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 84.239.45.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 01:07:15.326036 2026] [security2:error] [pid 1132478:tid 1132478] [client 84.239.45.141:49087] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.asttechgroup.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.asttechgroup.com"] [uri "/robots.txt"] [unique_id "aehXg-i1BfpiOpTbgPQudAAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-04-22 04:51:22
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 84.239.45.141 (-): 1 in the last 300 secs; Port ...
show more
(mod_security) mod_security (id:210831) triggered by 84.239.45.141 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Apr 22 00:51:15.049691 2026] [security2:error] [pid 3956:tid 3956] [client 84.239.45.141:42454] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.taekwondoit.com|F|4"] [data "panscient.com"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.taekwondoit.com"] [uri "/about-us/robots.txt"] [unique_id "aehTwy741b79c_2cuw15uAAAAAg"]
show less
Brute-Force
Bad Web Bot
Web App Attack