πΊπΈ
TPI-Abuse
2026-06-03 21:39:48
(4 hours ago)
(mod_security) mod_security (id:210831) triggered by 120.239.28.214 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210831) triggered by 120.239.28.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed Jun 03 17:39:40.974381 2026] [security2:error] [pid 8044:tid 8044] [client 120.239.28.214:8937] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||angelaridgwaydressage.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "angelaridgwaydressage.com"] [uri "/"] [unique_id "aiCfHIiOaWnmyJWUMPWXfgAAABY"], referer: https://angelaridgwaydressage.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-29 20:04:06
(5 days ago)
(mod_security) mod_security (id:210831) triggered by 120.239.28.214 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210831) triggered by 120.239.28.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Fri May 29 16:04:00.086436 2026] [security2:error] [pid 14960:tid 14960] [client 120.239.28.214:8926] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||vividlee.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "vividlee.com"] [uri "/"] [unique_id "ahnxMOYYAeYhEeCgi0wQsAAAABA"], referer: http://vividlee.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-27 22:09:27
(1 week ago)
(mod_security) mod_security (id:210831) triggered by 120.239.28.214 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210831) triggered by 120.239.28.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Wed May 27 18:09:23.519541 2026] [security2:error] [pid 20340:tid 20340] [client 120.239.28.214:9862] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||walkingwithghosts.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "walkingwithghosts.com"] [uri "/"] [unique_id "ahdrk-xSpmOPJT4zV1IyWgAAAAE"], referer: https://walkingwithghosts.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-05-17 19:57:59
(2 weeks ago)
(mod_security) mod_security (id:210831) triggered by 120.239.28.214 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210831) triggered by 120.239.28.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Sun May 17 15:57:51.056725 2026] [security2:error] [pid 21972:tid 21999] [client 120.239.28.214:18232] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||www.newyorkfreepress.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "www.newyorkfreepress.com"] [uri "/"] [unique_id "agodvxmUNFKWNEy3ewN8hgAAARM"], referer: https://www.newyorkfreepress.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
πΊπΈ
TPI-Abuse
2026-04-06 23:45:09
(1 month ago)
(mod_security) mod_security (id:210831) triggered by 120.239.28.214 (-): 1 in the last 300 secs; Por ...
show more
(mod_security) mod_security (id:210831) triggered by 120.239.28.214 (-): 1 in the last 300 secs; Ports: *; Direction: 1; Trigger: LF_MODSEC; Logs: [Mon Apr 06 19:45:00.270641 2026] [security2:error] [pid 713843:tid 713843] [client 120.239.28.214:22858] ModSecurity: Access denied with code 403 (phase 2). Pattern match "(?i:(?:^(?:microsoft url|user-Agent|www\\\\.weblogs\\\\.com|(?:jakart|vi)a|(google|i{0,1}explorer{0,1}\\\\.exe|(ms){0,1}ie( [0-9.]{1,}){0,1} {0,1}(compatible( browser){0,1}){0,1})$)|\\\\bdatacha0s\\\\b|; widows|\\\\\\\\r|a(?: href=|d(?:sarobot|vanced email extractor ..." at REQUEST_HEADERS:User-Agent. [file "/etc/apache2/conf.d/modsec_vendor_configs/comodo_apache/03_Global_Agents.conf"] [line "29"] [id "210831"] [rev "2"] [msg "COMODO WAF: Rogue web site crawler||aquatech-ind.com|F|4"] [data "User-Agent"] [severity "WARNING"] [tag "CWAF"] [tag "Agents"] [hostname "aquatech-ind.com"] [uri "/"] [unique_id "adRFfAwelLANGezglMHlmAAAAAQ"], referer: https://aquatech-ind.com/
show less
Brute-Force
Bad Web Bot
Web App Attack
π¨π³
ThreatBook.io
2025-11-13 00:32:00
(6 months ago)
ThreatBook Intelligence: Gateway more details on http://threatbook.io/ip/120.239.28.214
2025-11-12 0 ...
show more
ThreatBook Intelligence: Gateway more details on http://threatbook.io/ip/120.239.28.214
2025-11-12 07:23:20 /favicon.ico
show less
Web App Attack
π¨π³
ThreatBook.io
2025-09-01 00:09:38
(9 months ago)
ThreatBook Intelligence: Gateway more details on http://threatbook.io/ip/120.239.28.214
2025-08-31 1 ...
show more
ThreatBook Intelligence: Gateway more details on http://threatbook.io/ip/120.239.28.214
2025-08-31 13:29:52 /
show less
Web App Attack
π¨π³
ThreatBook.io
2025-05-24 02:13:45
(1 year ago)
ThreatBook Intelligence: Gateway more details on http://threatbook.io/ip/120.239.28.214
2025-05-23 0 ...
show more
ThreatBook Intelligence: Gateway more details on http://threatbook.io/ip/120.239.28.214
2025-05-23 04:57:49 /sitemap.xml
show less
Web App Attack