🇫🇷
SpaceHost-Server
2026-09-08 22:14:03
(1 day ago)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 09:32:24
(2 days ago)
(mod_security) mod_security (id:217210) triggered by 102.129.141.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217210) triggered by 102.129.141.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 08 05:32:16.016584 2026] [security2:error] [pid 30970:tid 30970] [client 102.129.141.194:3535] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||simplybrandedllc.com|F|4"] [data "GET http://simplybrandedllc.com HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "simplybrandedllc.com"] [uri "/"] [unique_id "ap_WILxp6OXFtIxrruBhXwAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
TPI-Abuse
2026-09-08 03:27:35
(2 days ago)
(mod_security) mod_security (id:217210) triggered by 102.129.141.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217210) triggered by 102.129.141.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 23:27:31.517031 2026] [security2:error] [pid 30662:tid 30662] [client 102.129.141.194:17964] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||dynarol.com|F|4"] [data "ET http://dynarol.com/robots.txt HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "dynarol.com"] [uri "/robots.txt"] [unique_id "ap-Ao71khHYluw2gfhYJMwAAABA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇩🇪
John Chrys.
2026-09-08 01:20:18
(2 days ago)
102.129.141.194 - - [08/Sep/2026:04:20:01 +0300] "POST /xmlrpc.php HTTP/1.1" 403 380 "-" "Mozilla/5. ...
show more
102.129.141.194 - - [08/Sep/2026:04:20:01 +0300] "POST /xmlrpc.php HTTP/1.1" 403 380 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
102.129.141.194 - - [08/Sep/2026:04:20:10 +0300] "POST /xmlrpc.php HTTP/1.1" 403 380 "-" "Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_7) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
102.129.141.194 - - [08/Sep/2026:04:20:10 +0300] "POST /xmlrpc.php HTTP/1.1" 403 380 "-" "Mozilla/5.0 (iPhone; CPU iPhone OS 17_0 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/17.0 Mobile/15E148 Safari/604.1"
102.129.141.194 - - [08/Sep/2026:04:20:11 +0300] "POST /xmlrpc.php HTTP/1.1" 403 380 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36"
102.129.141.194 - - [08/Sep/2026:04:20:11 +0300] "POST /xmlrpc.php HTTP/1.1" 403 380 "-" "Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML,
...
show less
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 23:28:24
(2 days ago)
(mod_security) mod_security (id:217210) triggered by 102.129.141.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217210) triggered by 102.129.141.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 19:28:20.158857 2026] [security2:error] [pid 13059:tid 13059] [client 102.129.141.194:28450] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||gre-home.com|F|4"] [data "GET http://gre-home.com HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "gre-home.com"] [uri "/"] [unique_id "ap9IlAGsfzCg-d4anFWVKQAAABQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇫🇷
SpaceHost-Server
2026-09-07 22:14:02
(2 days ago)
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 19:35:30
(3 days ago)
(mod_security) mod_security (id:217210) triggered by 102.129.141.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217210) triggered by 102.129.141.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 15:35:25.586966 2026] [security2:error] [pid 3011:tid 3011] [client 102.129.141.194:19676] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||tduniverse.net|F|4"] [data "GET http://tduniverse.net HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "tduniverse.net"] [uri "/"] [unique_id "ap8R_adaYe1jzILCh359FAAAAA0"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇨🇦
DRI
2026-09-07 14:58:00
(3 days ago)
Web attack/Malicious activity detected
Web App Attack
🇮🇹
VHosting
2026-09-07 13:40:03
(3 days ago)
Detected WordPress attack from different servers
Brute-Force
Web App Attack
🇺🇸
TPI-Abuse
2026-09-07 13:37:13
(3 days ago)
(mod_security) mod_security (id:217210) triggered by 102.129.141.194 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217210) triggered by 102.129.141.194 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Sep 07 09:37:06.895674 2026] [security2:error] [pid 23004:tid 23004] [client 102.129.141.194:62304] ModSecurity: Access denied with code 403 (phase 2). Match of "rx ^(?i:(?:[a-z]{3,10}\\\\s+(?:\\\\w{3,7}?://[\\\\w\\\\-\\\\./]*(?::\\\\d+)?)?/[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?|connect (?:\\\\d{1,3}\\\\.){3}\\\\d{1,3}\\\\.?(?::\\\\d+)?|options \\\\*)\\\\s+[\\\\w\\\\./]+|get /[^?#]*(?:\\\\?[^#\\\\s]*)?(?:#[\\\\S]*)?)$" against "REQUEST_LINE" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "114"] [id "217210"] [rev "1"] [msg "COMODO WAF: Invalid HTTP Request Line||anus.net|F|4"] [data "GET http://anus.net HTTP/1.1"] [severity "WARNING"] [tag "CWAF"] [tag "Protocol"] [hostname "anus.net"] [uri "/"] [unique_id "ap6-AuQKUiJAYFESQz0QpQAAAAM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
🇺🇸
EchoGuard
2026-05-06 02:21:43
(4 months ago)
FortiGate SSL VPN login failures
VPN IP
Brute-Force
🇺🇸
fbarela
2026-05-05 19:00:16
(4 months ago)
FortiGate SSL VPN login failures.
Brute-Force
Hacking