๐จ๐ณ
ThreatBook.io
2025-09-06 22:56:26
(1 year ago)
ThreatBook Intelligence: Spam,Gateway more details on https://threatbook.io/ip/112.193.255.71
2025-0 ...
show more
ThreatBook Intelligence: Spam,Gateway more details on https://threatbook.io/ip/112.193.255.71
2025-09-06 11:21:48 /ftp.tar.gz
2025-09-06 11:12:55 /total.rar
2025-09-06 11:20:53 /db.7z
2025-09-06 11:10:35 /tomcat.tar.gz
show less
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-09 03:04:19
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Tue Oct 08 23:03:05.490577 2024] [security2:error] [pid 6530:tid 6530] [client 112.193.255.71:31002] [client 112.193.255.71] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.zacharyschwartzman.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.zacharyschwartzman.com"] [uri "/forum.bak"] [unique_id "ZwXyaUZwxQa9hE-q47uyIAAAABY"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-07 05:42:08
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Oct 07 01:40:03.356516 2024] [security2:error] [pid 30509:tid 30509] [client 112.193.255.71:32253] [client 112.193.255.71] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.med-engineering.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.med-engineering.com"] [uri "/orders.bak"] [unique_id "ZwN0M3QfJw8XaUCs4eg4owAAAAo"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-05 08:20:04
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Oct 05 04:19:05.618327 2024] [security2:error] [pid 18509:tid 18509] [client 112.193.255.71:50539] [client 112.193.255.71] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.mosherpit.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.mosherpit.com"] [uri "/log.sql"] [unique_id "ZwD2eZV96-tuyRZzqxcGQgAAACA"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-05 02:25:36
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Oct 04 22:22:44.781614 2024] [security2:error] [pid 7047:tid 7047] [client 112.193.255.71:49712] [client 112.193.255.71] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.wassusa.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.wassusa.com"] [uri "/users.sql"] [unique_id "ZwCi9J9-NIpK2mD03x1vtgAAABU"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-03 14:53:19
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Oct 03 10:50:46.458094 2024] [security2:error] [pid 7341:tid 7341] [client 112.193.255.71:50245] [client 112.193.255.71] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.paulburns.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.paulburns.com"] [uri "/log.sql"] [unique_id "Zv6vRofk9uVONcrAZio7MwAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-10-02 06:17:15
(1 year ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Oct 02 02:16:16.477165 2024] [security2:error] [pid 8536:tid 8536] [client 112.193.255.71:50534] [client 112.193.255.71] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.valuechains4poor.net|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.valuechains4poor.net"] [uri "/auth.bak"] [unique_id "ZvzlMPto29k-BVHtbMng6wAAABI"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-07 16:48:23
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 07 12:46:34.382952 2024] [security2:error] [pid 17129:tid 17129] [client 112.193.255.71:56638] [client 112.193.255.71] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.powerkiteforum.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.powerkiteforum.com"] [uri "/my.sql"] [unique_id "ZtyDau-PBlpaE5KA7aEGogAAAAc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-07 05:36:14
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sat Sep 07 01:34:27.023024 2024] [security2:error] [pid 910:tid 910] [client 112.193.255.71:56449] [client 112.193.255.71] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.wplusw.com|F|2"] [data ".backup"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.wplusw.com"] [uri "/wplusw_com.backup"] [unique_id "Ztvl40wmxo3uar1uBUgmqAAAACM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-06 18:01:49
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 06 14:01:10.822267 2024] [security2:error] [pid 26991:tid 26991] [client 112.193.255.71:55987] [client 112.193.255.71] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.mordesign1.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.mordesign1.com"] [uri "/2017.sql"] [unique_id "ZttDZvDlKlchVmRjV5YkwwAAABM"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-06 12:32:31
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 06 08:31:01.418092 2024] [security2:error] [pid 5536:tid 5542] [client 112.193.255.71:24391] [client 112.193.255.71] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.catslife.net|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.catslife.net"] [uri "/2012.sql"] [unique_id "Ztr2BQZCox1goEb_6NbhNgAAAQQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-06 11:32:35
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri Sep 06 07:31:49.508583 2024] [security2:error] [pid 26002:tid 26002] [client 112.193.255.71:22948] [client 112.193.255.71] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.balivisaservice.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.balivisaservice.com"] [uri "/error_log.bak"] [unique_id "ZtroJeKlOjwNfKNSp82HDAAAABc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-06 00:24:03
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 05 20:21:50.934048 2024] [security2:error] [pid 12404:tid 12404] [client 112.193.255.71:22565] [client 112.193.255.71] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.warchildsworld.com|F|2"] [data ".sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.warchildsworld.com"] [uri "/database.sql"] [unique_id "ZtpLHhWpxIJ0tu7bT4PzIQAAACc"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-05 22:52:31
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 05 18:50:50.333780 2024] [security2:error] [pid 25032:tid 25032] [client 112.193.255.71:23888] [client 112.193.255.71] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "4"] [msg "COMODO WAF: URL file extension is restricted by policy||www.randallbrooks.com|F|2"] [data ".com.sql"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.randallbrooks.com"] [uri "/randallbrooks.com.sql"] [unique_id "Zto1yuQyV8Rp2VfZ4bToNgAAAA4"]
show less
Brute-Force
Bad Web Bot
Web App Attack
๐บ๐ธ
TPI-Abuse
2024-09-05 20:14:20
(2 years ago)
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210730) triggered by 112.193.255.71 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Thu Sep 05 16:13:27.666745 2024] [security2:error] [pid 19023:tid 19023] [client 112.193.255.71:56173] [client 112.193.255.71] ModSecurity: Access denied with code 403 (phase 2). Match of "pmFromFile userdata_wl_extensions" against "TX:extension" required. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/10_HTTP_HTTP.conf"] [line "27"] [id "210730"] [rev "5"] [msg "COMODO WAF: URL file extension is restricted by policy||www.baselineledsolutions.com|F|2"] [data ".bak"] [severity "CRITICAL"] [tag "CWAF"] [tag "HTTP"] [hostname "www.baselineledsolutions.com"] [uri "/joomla.bak"] [unique_id "ZtoQ55MDUl17k2rcxggy7QAAAAQ"]
show less
Brute-Force
Bad Web Bot
Web App Attack