πΊπΈ
TPI-Abuse
2025-09-24 08:44:54
(11 months ago)
(mod_security) mod_security (id:217291) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:217291) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Sep 24 04:44:50.629464 2025] [security2:error] [pid 29164:tid 29164] [client 112.193.255.137:41955] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(\\\\n|\\\\r)" at ARGS_NAMES:\\r\\nb9\\r\\nm. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/12_HTTP_Protocol.conf"] [line "145"] [id "217291"] [rev "2"] [msg "HTTP Header Injection Attack via payload (CR/LF detected)||kountz.org|F|2"] [data "Matched Data: \\x0d found within ARGS_NAMES:\\x5cr\\x5cnb9\\x5cr\\x5cnm: \\x0d\\x0ab9\\x0d\\x0am"] [severity "CRITICAL"] [tag "CWAF"] [tag "Protocol"] [hostname "kountz.org"] [uri "/calendar.php"] [unique_id "aNOvgif7V_OBiYuO0DbpbwAAAAA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
Anonymous
2025-07-04 20:06:46
(1 year ago)
Unauthorized connection attempt
Port Scan
Hacking
Exploited Host
π«π·
bigorre.org
2024-12-16 10:21:51
(1 year ago)
Unidentified crawling: not a self-announced bot in user-agent
Bad Web Bot
πΈπ¬
Charles
2024-10-10 17:08:40
(1 year ago)
112.193.255.137 - - [11/Oct/2024:01:08:19 +0800] "GET /admin.rar HTTP/1.1" 404 2110 "-" "Mozilla/5.0 ...
show more
112.193.255.137 - - [11/Oct/2024:01:08:19 +0800] "GET /admin.rar HTTP/1.1" 404 2110 "-" "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/72.0.3626 Safari/537.36"
...
show less
Web Spam
Email Spam
Brute-Force
Bad Web Bot
Web App Attack
SSH
πͺπΈ
10dencehispahard SL
2024-10-04 12:04:39
(1 year ago)
DoS Attack
DDoS Attack
Brute-Force
πΊπΈ
TPI-Abuse
2024-10-03 14:52:12
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 03 10:50:44.734855 2024] [security2:error] [pid 7251:tid 7251] [client 112.193.255.137:40861] [client 112.193.255.137] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.paulburns.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.paulburns.com"] [uri "/2019.sql"] [unique_id "Zv6vRP1zma24G_qE4xbA1wAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-10-03 12:02:01
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 03 08:01:31.957468 2024] [security2:error] [pid 11891:tid 11891] [client 112.193.255.137:39759] [client 112.193.255.137] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.stinsonbeachsurfandkayak.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.stinsonbeachsurfandkayak.com"] [uri "/backups.bak"] [unique_id "Zv6Hm8hvrmMWta7DZFvRfQAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-10-02 06:16:56
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 02 02:16:17.280690 2024] [security2:error] [pid 28147:tid 28147] [client 112.193.255.137:39927] [client 112.193.255.137] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.valuechains4poor.net|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.valuechains4poor.net"] [uri "/root.bak"] [unique_id "ZvzlMUgrPR2Hv4R-JX4BdwAAAEQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-09-28 10:44:55
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 28 06:42:36.632061 2024] [security2:error] [pid 20514:tid 20514] [client 112.193.255.137:15049] [client 112.193.255.137] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.sabrinaspalette.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.sabrinaspalette.com"] [uri "/2010.sql"] [unique_id "ZvfdnJge9vrY39GxFzYGswAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-09-28 04:43:47
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 28 00:41:28.637132 2024] [security2:error] [pid 26993:tid 26993] [client 112.193.255.137:14343] [client 112.193.255.137] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.thorndikestudio.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.thorndikestudio.com"] [uri "/2015.bak"] [unique_id "ZveI-GOThg9wmGAJp57OqAAAAAw"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-09-28 01:47:07
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 27 21:46:03.229124 2024] [security2:error] [pid 27649:tid 27649] [client 112.193.255.137:14803] [client 112.193.255.137] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.gamepart.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.gamepart.com"] [uri "/dat.sql"] [unique_id "Zvdf2xy5cA20vFAqfsmSBAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-09-27 11:29:06
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 27 07:27:12.624284 2024] [security2:error] [pid 3864:tid 3948] [client 112.193.255.137:16292] [client 112.193.255.137] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.idealcentralvac.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.idealcentralvac.com"] [uri "/2016.sql"] [unique_id "ZvaWkNRjWwYaMsM2EVMysQAAAEc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-09-27 08:08:17
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 27 04:05:41.809309 2024] [security2:error] [pid 29284:tid 29284] [client 112.193.255.137:15525] [client 112.193.255.137] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.willowcreekretreathouse.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.willowcreekretreathouse.com"] [uri "/index.sql"] [unique_id "ZvZnVbQfmFz5V86FJQQY3QAAAAU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-09-27 05:26:13
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 27 01:25:22.432615 2024] [security2:error] [pid 26053:tid 26053] [client 112.193.255.137:14887] [client 112.193.255.137] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.customhumanrobots.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.customhumanrobots.com"] [uri "/2021.bak"] [unique_id "ZvZBwoPpSaF4Q8uDrDq39QAAABE"]
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2024-09-17 21:06:16
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Po ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.137 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Sep 17 17:04:23.430524 2024] [security2:error] [pid 8865:tid 8888] [client 112.193.255.137:45110] [client 112.193.255.137] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.mastersofthesecrets.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.mastersofthesecrets.com"] [uri "/store.bak"] [unique_id "Zunu1-_B6mm-Ko-3j2YlbwAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack