๐ฆ๐บ
paulshipley.com.au
2026-08-01 20:29:08
(3 hours ago)
[Sun Aug 02 06:29:07.132805 2026] [security2:error] [pid 775617] [client 95.179.189.194:56783] [clie ...
show more
[Sun Aug 02 06:29:07.132805 2026] [security2:error] [pid 775617] [client 95.179.189.194:56783] [client 95.179.189.194] ModSecurity: Access denied with code 403 (phase 2). Operator GE matched 5 at TX:anomaly_score. [file "/etc/modsecurity/crs/rules/REQUEST-949-BLOCKING-EVALUATION.conf"] [line "94"] [id "949110"] [msg "Inbound Anomaly Score Exceeded (Total Score: 5)"] [severity "CRITICAL"] [ver "OWASP_CRS/3.3.4"] [tag "application-multi"] [tag "language-multi"] [tag "platform-multi"] [tag "attack-generic"] [hostname "dlcarterauthor.com"] [uri "/storage/logs/laravel-2026-07-30.log"] [unique_id "am5XE35rTYyWCpKDrXWUUAAAABA"]
...
show less
Web App Attack
๐จ๐ญ
4server
2026-08-01 20:19:05
(3 hours ago)
[SatAug0122:19:00.4560692026][security2:error][pid752505:tid752678][client95.179.189.194:0]ModSecuri ...
show more
[SatAug0122:19:00.4560692026][security2:error][pid752505:tid752678][client95.179.189.194:0]ModSecurity:Accessdeniedwithcode403\(phase2\).Stringmatchwithin\".asa/.asax/.ascx/.backup/.bak/.bat/.cdx/.cer/.cfg/.cmd/.com/.config/.conf/.cs/.csproj/.csr/.dat/.db/.dbf/.dll/.dos/.htr/.htw/.ida/.idc/.idq/.inc/.ini/.key/.licx/.lnk/.log/.mdb/.old/.pass/.pdb/.pol/.printer/.pwd/.rdb/.resources/.resx/.sql/.swp/.sys/.vb/.vbs/.vbproj/.vsdisco/.webinfo/.xsx/\"atTX:extension.[file\"/etc/apache2/conf.d/modsec_rules/00_asl_zz_strict.conf\"][line\"91\"][id\"390716\"][rev\"2\"][msg\"Atomicorp.comWAFRules:URLfileextensionisrestrictedbypolicy\"][data\".log\"][severity\"ERROR\"][hostname\"dc-graphicart.com\"][uri\"/storage/logs/laravel-2026-07-30.log\"][unique_id\"am5UtOFW3r9zWrIQViFuNgAAAEk\"]
show less
Hacking
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 12:39:24
(11 hours ago)
(mod_security) mod_security (id:210730) triggered by 95.179.189.194 (95.179.189.194.vultrusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 95.179.189.194 (95.179.189.194.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 08:39:16.302272 2026] [security2:error] [pid 713492:tid 713492] [client 95.179.189.194:56881] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||oakleighfarm.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "oakleighfarm.com"] [uri "/storage/logs/laravel-2026-07-30.log"] [unique_id "am3o9Hbx1zuumafZayZdKgAAABo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-08-01 12:06:01
(11 hours ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 10:50:53
(12 hours ago)
(mod_security) mod_security (id:210730) triggered by 95.179.189.194 (95.179.189.194.vultrusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 95.179.189.194 (95.179.189.194.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 06:50:45.433767 2026] [security2:error] [pid 2453234:tid 2453234] [client 95.179.189.194:60440] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||texaspropertyinspection.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "texaspropertyinspection.com"] [uri "/storage/logs/laravel-2026-07-30.log"] [unique_id "am3PhdU9stCElBeiS9qtfAAAAB0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-08-01 10:28:52
(13 hours ago)
(mod_security) mod_security (id:210730) triggered by 95.179.189.194 (95.179.189.194.vultrusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 95.179.189.194 (95.179.189.194.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Aug 01 06:28:48.873939 2026] [security2:error] [pid 80912:tid 80912] [client 95.179.189.194:55021] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||redlitephotos.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "redlitephotos.com"] [uri "/storage/logs/laravel-2026-07-30.log"] [unique_id "am3KYPZTLvNgomJ9LnVAJwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 22:56:04
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 95.179.189.194 (95.179.189.194.vultrusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 95.179.189.194 (95.179.189.194.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 18:55:59.064075 2026] [security2:error] [pid 1775485:tid 1775492] [client 95.179.189.194:57979] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||30acre.net|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "30acre.net"] [uri "/storage/logs/laravel-2026-07-30.log"] [unique_id "am0n_-C7Rfscs8eaRjqpigAAAUI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 22:36:59
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 95.179.189.194 (95.179.189.194.vultrusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 95.179.189.194 (95.179.189.194.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 18:36:53.061776 2026] [security2:error] [pid 3977733:tid 3977733] [client 95.179.189.194:54225] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||300blockofwarwick.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "300blockofwarwick.com"] [uri "/storage/logs/laravel-2026-07-30.log"] [unique_id "am0jheS_uPFTXGdyAWlKUAAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-31 21:38:16
(1 day ago)
(mod_security) mod_security (id:210730) triggered by 95.179.189.194 (95.179.189.194.vultrusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 95.179.189.194 (95.179.189.194.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Jul 31 17:38:09.928290 2026] [security2:error] [pid 1119311:tid 1119311] [client 95.179.189.194:52422] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||2janderson.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "2janderson.com"] [uri "/storage/logs/laravel-2026-07-30.log"] [unique_id "am0VwbVU_U-HljPD29TtDwAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 21:34:21
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 95.179.189.194 (95.179.189.194.vultrusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 95.179.189.194 (95.179.189.194.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 17:34:16.423614 2026] [security2:error] [pid 2033136:tid 2033136] [client 95.179.189.194:56414] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||rosawallas.com|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "rosawallas.com"] [uri "/storage/logs/laravel.log"] [unique_id "amvDWBzAMShVxUpXxpyrZAAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-30 16:24:20
(2 days ago)
(mod_security) mod_security (id:210730) triggered by 95.179.189.194 (95.179.189.194.vultrusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 95.179.189.194 (95.179.189.194.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Jul 30 12:24:16.484021 2026] [security2:error] [pid 3913182:tid 3913182] [client 95.179.189.194:56591] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||powdercoatovens.net|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "powdercoatovens.net"] [uri "/storage/logs/laravel.log"] [unique_id "amt6sMmoQvxgbZJsl1TqzQAAABk"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฎ๐ฉ
Burayot
2026-07-30 07:49:45
(2 days ago)
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 95.179.189.194 (95.179.189.194.vultr ...
show more
LF_MODSEC: (mod_security) mod_security (id:949110) triggered by 95.179.189.194 (95.179.189.194.vultrusercontent.com): 1 in the last 3600 secs
show less
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-07-30 05:08:02
(2 days ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [ice01,ice02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐ฌ๐ง
thetomtaylor.co.uk
2026-07-30 04:05:03
(2 days ago)
Fail2Ban - [WEB]Custom exploit pattern detected on customexploits ... [wa01,wa02]
Hacking
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-07-29 23:11:38
(3 days ago)
(mod_security) mod_security (id:210730) triggered by 95.179.189.194 (95.179.189.194.vultrusercontent ...
show more
(mod_security) mod_security (id:210730) triggered by 95.179.189.194 (95.179.189.194.vultrusercontent.com): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jul 29 19:11:33.910163 2026] [security2:error] [pid 1307058:tid 1307058] [client 95.179.189.194:50463] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||pathpa.org|F|2"] [data ".log"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "pathpa.org"] [uri "/storage/logs/laravel-2026-07-28.log"] [unique_id "amqIpYe09dbLimCS4Wj3mQAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack