๐ธ๐ฎ
administrator
2026-09-11 22:46:14
(1 week ago)
2026-09-06 00:15:01,269 fail2ban.actions [1054]: NOTICE [apache-badbots] Ban 162.220.11.79
2 ...
show more
2026-09-06 00:15:01,269 fail2ban.actions [1054]: NOTICE [apache-badbots] Ban 162.220.11.79
2026-09-06 00:15:01,269 fail2ban.actions [1054]: NOTICE [apache-badbots] Ban 162.220.11.79
2026-09-06 00:15:01,269 fail2ban.actions [1054]: NOTICE [apache-badbots] Ban 162.220.11.79
...
show less
Bad Web Bot
Web Spam
Email Spam
Blog Spam
Port Scan
Brute-Force
Web App Attack
๐ซ๐ท
EvoX
2026-09-10 17:12:49
(1 week ago)
๐ก๏ธ Honeypot [bsts-tpot-hive]: Incoming HTTP request (dst port 81/tcp, src port 15144) against a pass ...
show more
๐ก๏ธ Honeypot [bsts-tpot-hive]: Incoming HTTP request (dst port 81/tcp, src port 15144) against a passive decoy web service with no legitimate content. Consistent with automated web scanning/exploitation attempts.
show less
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-09 23:22:54
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 162.220.11.79 (vps3396669.trouble-free.net): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 162.220.11.79 (vps3396669.trouble-free.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 09 19:22:49.203072 2026] [security2:error] [pid 3024:tid 3024] [client 162.220.11.79:26708] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||192.64.150.227:80|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "192.64.150.227"] [uri "/.config/rclone/rclone.conf"] [unique_id "aqHqSX3bNDy9S4uGySb3JgAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ณ
Public CSIRT/CC of Mongolia
2026-09-09 16:27:30
(1 week ago)
Honeypot hit: Incoming HTTP traffic on port 81
Web App Attack
Bad Web Bot
๐ซ๐ท
EvoX
2026-09-09 12:00:59
(1 week ago)
๐ก๏ธ Honeypot [bsts-tpot-sensor]: Incoming HTTP request (dst port 81/tcp, src port 60054) against a pa ...
show more
๐ก๏ธ Honeypot [bsts-tpot-sensor]: Incoming HTTP request (dst port 81/tcp, src port 60054) against a passive decoy web service with no legitimate content. Consistent with automated web scanning/exploitation attempts.
show less
Hacking
Bad Web Bot
๐บ๐ธ
TPI-Abuse
2026-09-08 16:34:21
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 162.220.11.79 (vps3396669.trouble-free.net): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 162.220.11.79 (vps3396669.trouble-free.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 12:34:14.405399 2026] [security2:error] [pid 31942:tid 31942] [client 162.220.11.79:45676] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||192.64.150.15:80|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "192.64.150.15"] [uri "/.config/rclone/rclone.conf"] [unique_id "aqA5BqNSkOViZqiQ_Buk-wAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 08:57:06
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 162.220.11.79 (vps3396669.trouble-free.net): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 162.220.11.79 (vps3396669.trouble-free.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 04:56:58.768549 2026] [security2:error] [pid 12895:tid 12895] [client 162.220.11.79:46410] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||192.64.150.189:80|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "192.64.150.189"] [uri "/.config/rclone/rclone.conf"] [unique_id "ap_N2tr2xKeTtMWGmNFlfAAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 07:30:56
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 162.220.11.79 (vps3396669.trouble-free.net): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 162.220.11.79 (vps3396669.trouble-free.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 03:30:49.705572 2026] [security2:error] [pid 12073:tid 12073] [client 162.220.11.79:15300] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||192.64.150.242:80|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "192.64.150.242"] [uri "/.config/rclone/rclone.conf"] [unique_id "ap-5qWcM7ElE3nT6u-SJlwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-08 04:45:30
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 162.220.11.79 (vps3396669.trouble-free.net): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 162.220.11.79 (vps3396669.trouble-free.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 00:45:24.177430 2026] [security2:error] [pid 29915:tid 29915] [client 162.220.11.79:38628] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||192.64.150.142:80|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "192.64.150.142"] [uri "/.config/rclone/rclone.conf"] [unique_id "ap-S5GrbZHu_Pcx5YnaQJgAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 11:13:01
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 162.220.11.79 (vps3396669.trouble-free.net): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 162.220.11.79 (vps3396669.trouble-free.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 07:12:54.132308 2026] [security2:error] [pid 5449:tid 5449] [client 162.220.11.79:6254] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||192.64.150.63:80|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "192.64.150.63"] [uri "/.config/rclone/rclone.conf"] [unique_id "ap6cNgFiwMaDhYG5QGUERQAAABg"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-07 07:47:48
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 162.220.11.79 (vps3396669.trouble-free.net): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 162.220.11.79 (vps3396669.trouble-free.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 03:47:40.527609 2026] [security2:error] [pid 7936:tid 7936] [client 162.220.11.79:64410] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||192.64.150.58:80|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "192.64.150.58"] [uri "/.config/rclone/rclone.conf"] [unique_id "ap5sHKL6_38kFhl--5B8dwAAAAs"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-06 07:04:07
(1 week ago)
(mod_security) mod_security (id:210730) triggered by 162.220.11.79 (vps3396669.trouble-free.net): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 162.220.11.79 (vps3396669.trouble-free.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun Sep 06 03:04:03.435481 2026] [security2:error] [pid 23160:tid 23160] [client 162.220.11.79:15732] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||192.64.150.197:80|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "192.64.150.197"] [uri "/.config/rclone/rclone.conf"] [unique_id "ap0QY-9kpOpfWe86u_h8BQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 18:56:40
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 162.220.11.79 (vps3396669.trouble-free.net): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 162.220.11.79 (vps3396669.trouble-free.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 14:56:36.132587 2026] [security2:error] [pid 12123:tid 12123] [client 162.220.11.79:21912] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||192.64.150.87:80|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "192.64.150.87"] [uri "/.config/rclone/rclone.conf"] [unique_id "apsUZAj1DsogBIZb1cKIAwAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2026-09-04 18:37:53
(2 weeks ago)
(mod_security) mod_security (id:210730) triggered by 162.220.11.79 (vps3396669.trouble-free.net): 1 ...
show more
(mod_security) mod_security (id:210730) triggered by 162.220.11.79 (vps3396669.trouble-free.net): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 04 14:37:47.225821 2026] [security2:error] [pid 8296:tid 8307] [client 162.220.11.79:59492] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||192.64.150.201:80|F|2"] [data ".conf"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "192.64.150.201"] [uri "/.config/rclone/rclone.conf"] [unique_id "apsP-6hTWN4V_haVdZmN_QAAAEU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐ฒ๐ณ
Public CSIRT/CC of Mongolia
2026-09-01 06:16:36
(2 weeks ago)
Honeypot hit: Incoming HTTP traffic on port 81
Web App Attack
Bad Web Bot